[论文解读] Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition
Adv-Makeup 通过一种任务驱动的化妆生成与混合模块,生成自然外观的眼影,提出了一种新颖的、难以察觉的、可迁移的对抗性攻击方法,针对人脸识别系统。该方法在数字和物理环境中对黑盒模型(包括商业平台)均实现了高攻击成功率,其在隐蔽性和可迁移性方面优于现有方法。
Deep neural networks, particularly face recognition models, have been shown to be vulnerable to both digital and physical adversarial examples. However, existing adversarial examples against face recognition systems either lack transferability to black-box models, or fail to be implemented in practice. In this paper, we propose a unified adversarial face generation method - Adv-Makeup, which can realize imperceptible and transferable attack under black-box setting. Adv-Makeup develops a task-driven makeup generation method with the blending module to synthesize imperceptible eye shadow over the orbital region on faces. And to achieve transferability, Adv-Makeup implements a fine-grained meta-learning adversarial attack strategy to learn more general attack features from various models. Compared to existing techniques, sufficient visualization results demonstrate that Adv-Makeup is capable to generate much more imperceptible attacks under both digital and physical scenarios. Meanwhile, extensive quantitative experiments show that Adv-Makeup can significantly improve the attack success rate under black-box setting, even attacking commercial systems.
研究动机与目标
- 开发一种在实际应用中兼具隐蔽性和可迁移性的实用对抗性攻击方法。
- 解决现有攻击方法存在的视觉明显或对黑盒模型缺乏可迁移性的问题。
- 通过化妆作为媒介,实现在物理世界中对抗样本的部署,同时保持自然外观。
- 通过元学习策略提升在商业、黑盒人脸识别系统上的攻击成功率。
提出的方法
- 化妆生成模块在人脸的眼眶区域合成逼真的眼影,以确保视觉上的自然性。
- 化妆混合策略对源人脸与生成眼影在风格和内容上进行对齐,提升真实感与隐蔽性。
- 采用细粒度的元学习对抗性攻击策略,以在多种模型间学习通用的攻击特征。
- 该方法端到端训练,以在黑盒设置下同时优化隐蔽性与高攻击成功率。
- 在数字和物理场景中均对方法进行评估,包括真实世界中的纹身贴纸应用。
- 在多个黑盒模型上测试了该攻击,包括 Face++ 和 Microsoft Azure 等商业平台。
实验结果
研究问题
- RQ1能否通过化妆作为媒介,在真实物理部署中实现既隐蔽又可迁移的对抗性攻击?
- RQ2所提出的元学习策略在多种黑盒人脸识别模型之间如何提升可迁移性?
- RQ3化妆混合策略在多大程度上提升了对抗性人脸的自然度与视觉保真度?
- RQ4与现有物理攻击方法(如 Adv-Glasses 和 Adv-Hat)相比,Adv-Makeup 在视觉隐蔽性与攻击成功率方面表现如何?
- RQ5该方法能否在商业、闭源人脸识别平台实现高攻击成功率?
主要发现
- 在所有测试的黑盒目标模型中,Adv-Makeup 达到了最高的攻击成功率,其可迁移性显著优于基线方法。
- 在 LFW 和化妆数据集上,Adv-Makeup 生成的对抗性人脸在视觉自然度方面表现最佳,经定性与定量比较验证。
- 在物理世界攻击中,Adv-Makeup 在姿态变化下仍保持高成功率,展现出对真实环境条件的鲁棒性。
- 即使在严格的置信度阈值约束下,该方法在 Face++ 和 Microsoft Azure 等商业平台上的攻击成功率仍超过 90%。
- 视觉对比显示,Adv-Makeup 生成的眼影与自然妆容最难以区分,仅存在微小且逼真的变化。
- 案例研究证实,Adv-Makeup 在使用物理纹身膏进行真实世界部署中有效,证明了其在数字模拟之外的可行性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。