[論文レビュー] RSTAM: An Effective Black-Box Impersonation Attack on Face Recognition using a Mobile and Compact Printer
RSTAMは、モバイルコンactプリンターで印刷された adversarial マスクを用いて、顔認識システムに対するブラックボックス模倣攻撃を提案する。ランダムな類似変換と事前学習モデルに対するランダムメタ最適化を活用することで、RSTAMは高い転送性を達成し、Face++、Baidu、Tencent などの商用システムに対し、一部のケースで97%を超える信頼度スコアを達成する物理的攻撃を効果的に行える。
Face recognition has achieved considerable progress in recent years thanks to the development of deep neural networks, but it has recently been discovered that deep neural networks are vulnerable to adversarial examples. This means that face recognition models or systems based on deep neural networks are also susceptible to adversarial examples. However, the existing methods of attacking face recognition models or systems with adversarial examples can effectively complete white-box attacks but not black-box impersonation attacks, physical attacks, or convenient attacks, particularly on commercial face recognition systems. In this paper, we propose a new method to attack face recognition models or systems called RSTAM, which enables an effective black-box impersonation attack using an adversarial mask printed by a mobile and compact printer. First, RSTAM enhances the transferability of the adversarial masks through our proposed random similarity transformation strategy. Furthermore, we propose a random meta-optimization strategy for ensembling several pre-trained face models to generate more general adversarial masks. Finally, we conduct experiments on the CelebA-HQ, LFW, Makeup Transfer (MT), and CASIA-FaceV5 datasets. The performance of the attacks is also evaluated on state-of-the-art commercial face recognition systems: Face++, Baidu, Aliyun, Tencent, and Microsoft. Extensive experiments show that RSTAM can effectively perform black-box impersonation attacks on face recognition models or systems.
研究の動機と目的
- 商用顔認識システムに対する効果的で、物理的かつ使いやすいブラックボックス模倣攻撃のギャップを埋める。
- 多様な顔認識モデルおよび現実世界の条件において、adversarial マスクの転送性を向上させる。
- Canon SELPHY CP1300 などの低コストでモバイルな印刷技術を用いて、実用的な物理的攻撃を可能にする。
- 高品質および低品質の顔画像の両方、特に実世界の展開状況を想定した状況において、攻撃効果を評価する。
- 現在の商用顔認識システムが、このような物理的 adversarial 攻撃に対して脆弱であることを示す。
提案手法
- adversarial パerturbation の出発点として、初期のバイナリマスクを設計する。
- 入力の多様性を高め、adversarial マスクの転送性を向上させるために、ランダムな類似変換戦略を導入する。
- 複数の事前学習済み顔認識モデルをアンサンブルするランダムメタ最適化戦略を提案し、より汎用性の高い adversarial マスクを生成する。
- モバイルでコンactなプリンター(Canon SELPHY CP1300)を活用し、実世界への展開に適した物理的マスクを印刷する。
- 高解像度および低品質の顔画像データセット(CelebA-HQ、LFW、MT、CASIA-FaceV5)に対して、デジタルおよび物理的攻撃を実施する。
- Face++、Baidu、Aliyun、Tencent、Microsoft の5つの商用システムにおける攻撃効果を評価する。
実験結果
リサーチクエスチョン
- RQ1低コストのモバイル印刷を用いて、デジタル環境から物理環境への adversarial マスクの効果的転送は可能か?
- RQ2ランダムな類似変換は、ブラックボックス環境における adversarial マスクの転送性をどのように向上させるか?
- RQ3複数の事前学習モデルに対するランダムメタ最適化は、adversarial マスクの一般化性および耐性をどの程度向上させるか?
- RQ4RSTAM は、実世界の物理的制約下でも、商用顔認識システムに対して高信頼度の模倣攻撃を達成できるか?
- RQ5実世界の監視やモバイル撮影状況で一般的に見られる低品質の顔画像において、RSTAM はどの程度効果的か?
主な発見
- LFW 画像を用いた攻撃において、RSTAM^meta_2 法を用いることで、Tencent 顔認識システムで97%を超える信頼度スコアを達成した。
- RSTAM^meta_∞ および RSTAM^meta_2 アンサンブル法は、顔画像が低品質となる長距離位置(位置④)においても高い攻撃成功率を維持した。
- Canon SELPHY CP1300 プリンターを用いた物理的攻撃は、デジタル攻撃と同等またはわずかに優れた信頼度スコアを達成し、物理的実現性の高さを示した。
- ランダム類似変換におけるハイパーパrameter β は、0.15 から 0.25 の範囲で最も効果的であり、感度分析を除くすべての実験で 0.2 を使用した。
- RSTAM は、Face++、Baidu、Aliyun、Tencent、Microsoft の5つの商用システムすべてで一貫した性能を示し、広範な転送性を確認した。
- 本手法は、ソーシャルネットワークから収集した公に利用可能な顔画像のみを用いて、商用システムに対するブラックボックス模倣攻撃を成功裏に実行した。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。