Skip to main content
QUICK REVIEW

[论文解读] Adversarial Mask: Real-World Adversarial Attack Against Face Recognition Models

Alon Zolfi, Shai Avidan|arXiv (Cornell University)|Nov 21, 2021
Adversarial Robustness in Machine Learning参考文献 40被引用 7
一句话总结

本文提出对抗性遮罩(Adversarial Mask),一种以图案形式应用于医用口罩的物理通用对抗扰动,可规避最先进的面部识别(FR)系统。通过在织物上打印对抗性图案,该方法在测试参与者中的FR准确率降至仅3.34%,显著优于普通口罩,并在不同模型和数据集间展现出极高的迁移性。

ABSTRACT

Deep learning-based facial recognition (FR) models have demonstrated state-of-the-art performance in the past few years, even when wearing protective medical face masks became commonplace during the COVID-19 pandemic. Given the outstanding performance of these models, the machine learning research community has shown increasing interest in challenging their robustness. Initially, researchers presented adversarial attacks in the digital domain, and later the attacks were transferred to the physical domain. However, in many cases, attacks in the physical domain are conspicuous, requiring, for example, the placement of a sticker on the face, and thus may raise suspicion in real-world environments (e.g., airports). In this paper, we propose Adversarial Mask, a physical adversarial universal perturbation (UAP) against state-of-the-art FR models that is applied on face masks in the form of a carefully crafted pattern. In our experiments, we examined the transferability of our adversarial mask to a wide range of FR model architectures and datasets. In addition, we validated our adversarial mask effectiveness in real-world experiments by printing the adversarial pattern on a fabric medical face mask, causing the FR system to identify only 3.34% of the participants wearing the mask (compared to a minimum of 83.34% with other evaluated masks).

研究动机与目标

  • 开发一种可在真实环境中实现且不引起怀疑的物理对抗攻击,以规避面部识别系统。
  • 通过将对抗性图案集成到标准口罩中,解决如贴纸或可见补丁等显眼物理攻击的局限性。
  • 确保对抗性图案在不同面部识别模型架构和数据集间的高度迁移性。
  • 通过在受控实验中使用打印的织物口罩,在真实世界条件下验证该攻击的有效性。
  • 证明对抗性图案在应用于常用医用口罩时仍保持有效性。

提出的方法

  • 设计一种通用对抗扰动(UAP),使其可优化为应用于口罩上的图案,以误导面部识别模型。
  • 使用可微分渲染过程训练对抗性图案,以模拟真实世界的打印和佩戴条件。
  • 优化扰动以最大化在广泛面部识别模型和数据集上的误分类效果。
  • 通过高保真打印将训练好的对抗性图案应用于物理织物口罩,以确保视觉真实感和物理可行性。
  • 采用物理攻击评估流程,包括真实参与者佩戴口罩,并在多个FR系统上测试识别性能。
  • 利用迁移性原理,确保对抗性图案在不同模型架构和数据集间具有泛化能力。

实验结果

研究问题

  • RQ1能否将通用对抗扰动有效嵌入口罩中,以在物理世界中规避面部识别系统?
  • RQ2该对抗性遮罩在不同面部识别模型架构和数据集间的迁移性如何?
  • RQ3与普通口罩相比,对抗性遮罩在真实世界环境中将面部识别准确率降低了多少?
  • RQ4当对抗性图案被打印在织物口罩上时,其视觉隐蔽性如何?
  • RQ5在真实世界的光照和视角条件下,对抗性遮罩是否仍能保持高规避性能?

主要发现

  • 对抗性遮罩在测试参与者中的面部识别准确率降至3.34%,而普通口罩的最低准确率为83.34%。
  • 对抗性图案在多个最先进的面部识别模型和数据集间展现出强大的迁移性。
  • 该攻击在应用于物理织物口罩后仍保持有效,证实其在真实世界部署中的可行性。
  • 对抗性图案视觉上细微,未引起怀疑,适合在真实世界中隐蔽规避而不被察觉。
  • 该方法显著优于依赖贴纸或补丁等显眼元素的现有物理攻击。
  • 结果证实,口罩可被武器化为针对面部识别系统的隐蔽对抗工具。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。