[論文レビュー] Meaningful Adversarial Stickers for Face Recognition in Physical World.
本稿では、最適化された貼り付けパラメータを備えた日常的なステッカーを用いて、物理的に実現可能な攻撃を実現する意味のある敵対的ステッカーを提案する。位置、回転角、その他のパラメータを最適化するために、領域ベースのヒューリスティック微分アルゴリズムを採用し、ブラックボックス設定下で500回未満のクエリでFaceNet、SphereFace、CosFaceに対して81.78%から79.26%の攻撃成功率を達成した。また、物理環境における動的ポーズ変化に対しても高い成功率を維持した。
Face recognition (FR) systems have been widely applied in safety-critical fields with the introduction of deep learning. However, the existence of adversarial examples brings potential security risks to FR systems. To identify their vulnerability and help improve their robustness, in this paper, we propose Meaningful Adversarial Stickers, a physically feasible and easily implemented attack method by using meaningful real stickers existing in our life, where the attackers manipulate the pasting parameters of stickers on the face, instead of designing perturbation patterns and then printing them like most existing works. We conduct attacks in the black-box setting with limited information which is more challenging and practical. To effectively solve the pasting position, rotation angle, and other parameters of the stickers, we design Region based Heuristic Differential Algorithm, which utilizes the inbreeding strategy based on regional aggregation of effective solutions and the adaptive adjustment strategy of evaluation criteria. Extensive experiments are conducted on two public datasets including LFW and CelebA with respective to three representative FR models like FaceNet, SphereFace, and CosFace, achieving attack success rates of 81.78%, 72.93%, and 79.26% respectively with only hundreds of queries. The results in the physical world confirm the effectiveness of our method in complex physical conditions. When continuously changing the face posture of testers, the method can still perform successful attacks up to 98.46%, 91.30% and 86.96% in the time series.
研究の動機と目的
- 印刷された摂動ではなく、日常のステッカーを用いて物理的に実現可能で実用的な顔認識システム向けの敵対的攻撃手法を開発すること。
- クエリ制限があるブラックボックス攻撃の課題に取り組み、現実世界の攻撃制約を模擬すること。
- 物理環境下で攻撃成功率を最大化するために、位置、回転角、スケールなどのステッカー貼り付けパラメータを最適化すること。
- 物理的展開時の顔のポーズ変化や動的状況に対しても耐性を確保すること。
- 人工的なノイズパターンではなく、意味のある実際のステッカーを用いることで、敵対的攻撃の実用性とステルス性を向上させること。
提案手法
- 本手法は、日常で使われる意味のあるステッカーを敵対的パッチとして使用し、特別な印刷が必要ない。
- ステッカーの配置最適化のため、効果的な解を領域的に集約することで内因的交配を組み込んだ領域ベースのヒューリスティック微分アルゴリズムを提案する。
- 収束性と解の品質を向上させるために、適応的評価基準調整戦略を採用する。
- 現実の脅威モデルを模擬するため、クエリ制限のあるブラックボックス設定で攻撃を実行する。
- 物理的制約下で、位置、回転角、スケールなどの複数のパラメータを同時に最適化し、誤分類を最大化する。
- 時間的系列の物理的シナリオ下で、顔のポーズが変化する状況下でも実顔に対して評価し、耐性を検証する。
実験結果
リサーチクエスチョン
- RQ1日常の物を使って物理的に実現可能な敵対的ステッカーは、現実世界の顔認識システムで高い攻撃成功率を達成できるか?
- RQ2提案された領域ベースのヒューリスティック微分アルゴリズムは、ブラックボックス制約下でステッカー配置を効果的に最適化できるか?
- RQ3物理環境下で顔のポーズが継続的に変化する状況でも、攻撃の効果は維持されるか?
- RQ4最小限のクエリ数で高い成功率を達成できるか。これにより、実世界への展開が現実的になるか?
- RQ5意味のある実際のステッカーを用いることで、従来の印刷された敵対的パッチと比較して、ステルス性と実現可能性はどのように向上するか?
主な発見
- 本手法は、ブラックボックス設定下で数100回のクエリで、FaceNetでは81.78%、SphereFaceでは72.93%、CosFaceでは79.26%の攻撃成功率を達成した。
- 顔のポーズが継続的に変化する動的物理的条件下でも、FaceNetでは98.46%、SphereFaceでは91.30%、CosFaceでは86.96%の成功率を維持した。
- 領域ベースのヒューリスティック微分アルゴリズムは、クエリ予算が限られた状況下でも効果的にステッカーのパラメータを最適化でき、高い性能を発揮した。
- 実際の意味のあるステッカーの使用により、従来の印刷された敵対的パターンと比較して、物理的実現可能性とステルス性が向上した。
- 本手法はポーズの変化に対しても強く、実世界での展開可能性が確認された。
- 結果から、実世界のオブジェクトと知的なパrameter最適化を組み合わせることで、物理的敵対的攻撃は実用的かつ極めて効果的であることが確認された。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。