[论文解读] Meaningful Adversarial Stickers for Face Recognition in Physical World.
本文提出了一种名为有意义对抗贴纸(Meaningful Adversarial Stickers)的物理可实现攻击方法,利用日常生活中常见的贴纸并优化其粘贴参数,以规避人脸识别系统。通过采用基于区域的启发式差分算法来调节位置、旋转角度等参数,该方法在仅使用少于500次查询的黑盒设置下,对FaceNet、SphereFace和CosFace的攻击成功率分别达到81.78%和79.26%,并且在物理环境中面对动态姿态变化时仍能保持较高成功率。
Face recognition (FR) systems have been widely applied in safety-critical fields with the introduction of deep learning. However, the existence of adversarial examples brings potential security risks to FR systems. To identify their vulnerability and help improve their robustness, in this paper, we propose Meaningful Adversarial Stickers, a physically feasible and easily implemented attack method by using meaningful real stickers existing in our life, where the attackers manipulate the pasting parameters of stickers on the face, instead of designing perturbation patterns and then printing them like most existing works. We conduct attacks in the black-box setting with limited information which is more challenging and practical. To effectively solve the pasting position, rotation angle, and other parameters of the stickers, we design Region based Heuristic Differential Algorithm, which utilizes the inbreeding strategy based on regional aggregation of effective solutions and the adaptive adjustment strategy of evaluation criteria. Extensive experiments are conducted on two public datasets including LFW and CelebA with respective to three representative FR models like FaceNet, SphereFace, and CosFace, achieving attack success rates of 81.78%, 72.93%, and 79.26% respectively with only hundreds of queries. The results in the physical world confirm the effectiveness of our method in complex physical conditions. When continuously changing the face posture of testers, the method can still perform successful attacks up to 98.46%, 91.30% and 86.96% in the time series.
研究动机与目标
- 开发一种基于真实世界贴纸而非打印扰动的、物理上可行且实用的对抗性攻击方法,用于人脸识别系统。
- 解决在有限查询访问条件下的黑盒攻击挑战,模拟真实世界攻击的约束条件。
- 优化贴纸粘贴参数(如位置、旋转角度和缩放比例),以在物理环境中最大化攻击成功率。
- 确保在物理世界部署过程中面对不同面部姿态和动态条件时具备鲁棒性。
- 通过使用有意义的真实贴纸而非人工噪声图案,提升对抗攻击的实用性和隐蔽性。
提出的方法
- 该方法使用日常生活中真实存在的、具有实际意义的贴纸作为对抗性补丁,避免了对定制打印扰动的依赖。
- 提出一种基于区域的启发式差分算法,用于优化贴纸的放置,通过区域聚合有效解实现内生繁殖。
- 该算法采用自适应评估标准调整策略,以提升收敛速度和解的质量。
- 攻击在仅有限查询访问的黑盒设置下运行,模拟真实威胁模型。
- 该方法联合优化多个参数(包括位置、旋转角度和缩放比例),以在物理约束条件下最大化误分类率。
- 该方法在不同姿态下的真实人脸上进行评估,测试其在时间序列物理场景中的鲁棒性。
实验结果
研究问题
- RQ1使用日常物品制作的物理可实现对抗贴纸,是否能在真实世界的人脸识别系统中实现高攻击成功率?
- RQ2所提出的基于区域的启发式差分算法在黑盒约束条件下优化贴纸放置的效率如何?
- RQ3当面部姿态在物理环境中持续动态变化时,该攻击方法的效能是否依然保持?
- RQ4该方法是否能在极低查询次数下实现高成功率,从而具备真实世界部署的实用性?
- RQ5与传统打印的对抗性补丁相比,使用有意义的真实贴纸在隐蔽性和可行性方面有何提升?
主要发现
- 在仅使用数百次查询的黑盒设置下,该方法在FaceNet上实现了81.78%的攻击成功率,在SphereFace上为72.93%,在CosFace上为79.26%。
- 在面部姿态持续动态变化的物理环境中,该攻击在FaceNet、SphereFace和CosFace上的成功率分别保持在98.46%、91.30%和86.96%。
- 基于区域的启发式差分算法有效优化了贴纸参数,使在有限查询预算下仍能实现高性能。
- 使用真实且具有实际意义的贴纸显著提升了物理可行性和隐蔽性,优于传统打印的对抗性图案。
- 该方法对姿态变化表现出强鲁棒性,证实其在真实世界部署场景中的可行性。
- 结果表明,当结合真实世界物体与智能参数优化时,物理世界中的对抗攻击既实用又极具有效性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。