Skip to main content
QUICK REVIEW

[論文レビュー] Invisible Mask: Practical Attacks on Face Recognition with Infrared

Zhe Zhou, Di Tang|arXiv (Cornell University)|Mar 13, 2018
Adversarial Robustness in Machine Learning参考文献 26被引用数 70
ひとこと要約

論文は、帽子に搭載された未公開の赤外線LEDを用いた赤外線ベースの敵対的攻撃を紹介し、顔に見えない摂動を作成して、監視を回避し、FaceNet のような顔認識システムへのなりすましを実現します。

ABSTRACT

Accurate face recognition techniques make a series of critical applications possible: policemen could employ it to retrieve criminals' faces from surveillance video streams; cross boarder travelers could pass a face authentication inspection line without the involvement of officers. Nonetheless, when public security heavily relies on such intelligent systems, the designers should deliberately consider the emerging attacks aiming at misleading those systems employing face recognition. We propose a kind of brand new attack against face recognition systems, which is realized by illuminating the subject using infrared according to the adversarial examples worked out by our algorithm, thus face recognition systems can be bypassed or misled while simultaneously the infrared perturbations cannot be observed by raw eyes. Through launching this kind of attack, an attacker not only can dodge surveillance cameras. More importantly, he can impersonate his target victim and pass the face authentication system, if only the victim's photo is acquired by the attacker. Again, the attack is totally unobservable by nearby people, because not only the light is invisible, but also the device we made to launch the attack is small enough. According to our study on a large dataset, attackers have a very high success rate with a over 70\% success rate for finding such an adversarial example that can be implemented by infrared. To the best of our knowledge, our work is the first one to shed light on the severity of threat resulted from infrared adversarial examples against face recognition.

研究の動機と目的

  • 顔認識システムに対する赤外線 adversarial 摂動の実用的リスクを動機づけ、定量化する。
  • 現実的なハードウェア制約の下でIR LEDベースの敵対的な例を生成するアルゴリズムを開発する。
  • 現実世界で敵対的な摂動を実装するための小型で目立たないデバイスを設計・較正する。
  • 実際のFRシステム(FaceNet)および大規模顔データセット(LFW)で攻撃の有効性を評価する。

提案手法

  • IR LEDの光スポットを、位置、サイズ、輝度、色特性を用いて制御可能な摂動としてモデル化する。
  • IR LEDの制約の下で、攻撃者の埋め込みと被験者の埋め込みの距離を最小化する最適化を定式化する。
  • モデル化した光スポットを攻撃者の画像に足し合わせ、紫色のIR可視摂動に変換して敵対的な例を合成する。
  • 帽子の peak に3つのIR LEDを搭載した物理デバイスを設計し、生成された adversarial example に摂動を整合させるための較正ツールを用意する。
  • LEDをオフとオンで比較する較正ワークフローを実装し、摂動の中心と輝度を調整して埋め込み距離を最小化する。
  • spotパラメータと全体の増幅に関して、損失 J(f(I_syn), f(I_vtm)) を最小化するために Adam optimizer を適用する。

実験結果

リサーチクエスチョン

  • RQ1現実的なハードウェア制約の下で、赤外線ベースの摂動を作成してFRシステムのターゲットを確実に回避またはなりすましできるだろうか?
  • RQ2主流のFRモデル(FaceNet)に対するIRベースの不可視マスクの有効性はどれほどで、回避と impersonation の達成率はいくらになるか?
  • RQ3IR LEDs を用いた実用的な敵対的例の実現における較正と manual な微調整の役割は何か?
  • RQ4野外でこのようなIRベースの攻撃を展開する際の実用的な考慮事項(脅威モデル、デバイス設計、安全性)は何か?

主な発見

  • 回避攻撃は報告された物理テストで100%の成功率を達成した。
  • 実行可能な敵対的例を見つけるためのなりすましの成功確率は、LFWデータを用いた大規模研究で70%を超えた。
  • 3つの850 nm IR LEDを搭載した帽子ベースのデバイスは、ランドマーク前処理を撹乱し、回避となりすましの双方を可能にするのに十分である。
  • 最適化ベースのパイプラインは、ハードウェアで実現可能な知覚不能に近い摂動を近似するIR LEDレイアウトを生成できる。
  • 較正と微調整は攻撃の成功を大幅に向上させ、手動での調整が場合によっては生の最適化のみより良い結果をもたらす。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。