Skip to main content
QUICK REVIEW

[논문 리뷰] Invisible Mask: Practical Attacks on Face Recognition with Infrared

Zhe Zhou, Di Tang|arXiv (Cornell University)|2018. 03. 13.
Adversarial Robustness in Machine Learning참고 문헌 26인용 수 70
한 줄 요약

이 논문은 모자에 탑재된 보이지 않는 적외선 LED를 이용한 적대적 공격으로 얼굴에 대한 보이지 않는 섭 perturbation을 만들어 FaceNet 같은 얼굴 인식 시스템을 우회하고 신원을 도용할 수 있게 한다.

ABSTRACT

Accurate face recognition techniques make a series of critical applications possible: policemen could employ it to retrieve criminals' faces from surveillance video streams; cross boarder travelers could pass a face authentication inspection line without the involvement of officers. Nonetheless, when public security heavily relies on such intelligent systems, the designers should deliberately consider the emerging attacks aiming at misleading those systems employing face recognition. We propose a kind of brand new attack against face recognition systems, which is realized by illuminating the subject using infrared according to the adversarial examples worked out by our algorithm, thus face recognition systems can be bypassed or misled while simultaneously the infrared perturbations cannot be observed by raw eyes. Through launching this kind of attack, an attacker not only can dodge surveillance cameras. More importantly, he can impersonate his target victim and pass the face authentication system, if only the victim's photo is acquired by the attacker. Again, the attack is totally unobservable by nearby people, because not only the light is invisible, but also the device we made to launch the attack is small enough. According to our study on a large dataset, attackers have a very high success rate with a over 70\% success rate for finding such an adversarial example that can be implemented by infrared. To the best of our knowledge, our work is the first one to shed light on the severity of threat resulted from infrared adversarial examples against face recognition.

연구 동기 및 목표

  • 적외선 대적 perturbation이 얼굴 인식 시스템에 미치는 실제 위험을 동기부여하고 정량화한다.
  • 현실적인 하드웨어 제약 하에서 IR LED 기반 적대적 예제를 생성하는 알고리즘을 개발한다.
  • 현실 세계 설정에서 적대적 섭 perturbations를 구현하기 위한 작고 은밀한 기기를 설계하고 보정한다.
  • 실제 FR 시스템(FaceNet)과 대규모 얼굴 데이터셋(LFW)에서 공격의 효과를 평가한다.

제안 방법

  • IR LED 광점을 위치, 크기, 밝기 및 색상 특성으로 제어 가능한 섭 perturbation으로 모델링한다.
  • IR LED 제약 하에서 공격자의 임베딩과 피해자의 임베딩 간의 거리를 최소화하도록 최적화를 수식화한다.
  • 모델링된 광점을 공격자의 이미지에 합산하여 IR 가시 범주에서 보랏빛으로 변환된 적대적 예제를 합성한다.
  • 피크에 3개의 IR LED를 탑재한 모자형 물리적 기기와 생성된 적대적 예제와의 정렬을 보정하는 교정 도구를 설계한다.
  • LED를 끈 상태와 켠 상태의 이미지를 비교하여 점 광 중심과 밝기를 조정하여 임베딩 거리 최소화를 위한 교정 워크플로우를 구현한다.
  • 손실 J(f(I_syn), f(I_vtm))를 광점 매개변수 및 전반적인 증폭에 대해 최소화하기 위해 Adam 옵티마이저를 적용한다.

실험 결과

연구 질문

  • RQ1IR 기반 섭 perturbation을 현실적인 하드웨어 제약 하에서 FR 시스템의 대상자를 안정적으로 우회하거나 신원을 도용하도록 설계할 수 있는가?
  • RQ2주류 FR 모델(FaceNet)에 대한 IR 기반 보이지 않는 마스크의 효과는 얼마나 되며 우회 및 impersonation의 성공률은 어느 정도인가?
  • RQ3실용적 인 IR LED 적대 예제 구현에서 보정 및 수동 미세 조정의 역할은 무엇인가?
  • RQ4현실 세계에서 이러한 IR 기반 공격을 배포하기 위한 위협 모델, 기기 설계, 안전성 등의 실용적 고려사항은 무엇인가?

주요 결과

  • 물리적 테스트에서 우회 공격이 100% 성공률을 기록했다.
  • 대규모 LFW 데이터에 대한 연구에서 실행 가능한 적대 예제 발견에 대한 impersonation 성공 확률이 70%를 넘는다.
  • cap 기반 기기에 3개의 850 nm IR LED가 있어 랜드마크 전처리를 방해하고 우회 및 impersonation을 가능하게 한다.
  • 최적화 기반 파이프라인은 하드웨어로 구현 가능한 거의 인지할 수 없을 정도의 perturbations에 근접한 IR LED 배치를 생성할 수 있다.
  • 교정 및 미세 조정은 공격 성공률을 크게 높이며, 때로는 수동 조정이 순수 최적화보다 더 나은 결과를 낳기도 한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.