[论文解读] Multiple-Identity Image Attacks Against Face-based Identity Verification
本文通过分析人脸表征空间的球面几何结构,解释了为何人脸识别系统容易受到多身份图像(MII)投毒攻击。研究发现,匹配对与非匹配对在表征空间中的角度分离度较低,分别约为90°和40–60°。研究证明,可通过表征空间反演与图像空间形变两种方法有效生成MII,这些方法生成的人脸与各组成身份的夹角约为45°,即使在受保护的比较器下,也能成功实施伪装攻击。
Facial verification systems are vulnerable to poisoning attacks that make use of multiple-identity images (MIIs)---face images stored in a database that resemble multiple persons, such that novel images of any of the constituent persons are verified as matching the identity of the MII. Research on this mode of attack has focused on defence by detection, with no explanation as to why the vulnerability exists. New quantitative results are presented that support an explanation in terms of the geometry of the representations spaces used by the verification systems. In the spherical geometry of those spaces, the angular distance distributions of matching and non-matching pairs of face representations are only modestly separated, approximately centred at 90 and 40-60 degrees, respectively. This is sufficient for open-set verification on normal data but provides an opportunity for MII attacks. Our analysis considers ideal MII algorithms, demonstrating that, if realisable, they would deliver faces roughly 45 degrees from their constituent faces, thus classed as matching them. We study the performance of three methods for MII generation---gallery search, image space morphing, and representation space inversion---and show that the latter two realise the ideal well enough to produce effective attacks, while the former could succeed but only with an implausibly large gallery to search. Gallery search and inversion MIIs depend on having access to a facial comparator, for optimisation, but our results show that these attacks can still be effective when attacking disparate comparators, thus securing a deployed comparator is an insufficient defence.
研究动机与目标
- 通过分析人脸表征空间的几何结构,解释人脸识别系统在理论上对多身份图像(MII)攻击的脆弱性。
- 评估在图像空间与表征空间中生成MIIs以有效伪装多个身份的实际可行性。
- 探究通过保护特定人脸识别比较器是否能阻止MII攻击,方法是测试MIIs在不同比较器间的可转移性。
- 量化表征空间中匹配对与非匹配对的夹角距离分布,以评估系统固有的脆弱性。
提出的方法
- 分析球面空间中人脸表征的夹角距离分布,发现匹配对聚集在约90°,非匹配对聚集在约40–60°。
- 提出一种假设的理想MII生成方法,可生成与各组成身份夹角约为45°的MII,此类MII将被分类为匹配。
- 采用图像空间形变技术,直接在像素空间中通过人脸融合方法合成MIIs。
- 应用表征空间反演方法,通过在人脸识别比较器的深层特征空间中进行优化来生成MIIs。
- 通过在一种模型上生成MIIs并在其他模型上评估,测试MIIs在不同人脸识别比较器间的可转移性。
- 使用直方图损失探索改进的训练策略,以降低类内方差并增强对MII攻击的鲁棒性。
实验结果
研究问题
- RQ1尽管在正常数据上表现稳健,为何人脸识别系统在理论上仍对多身份图像(MII)攻击存在脆弱性?
- RQ2实际的MII生成方法(如形变、表征空间反演)在多大程度上能逼近理论上理想的MII——即与各组成身份夹角为45°的MII?
- RQ3在某一人脸识别比较器上生成的MIIs,能在多大程度上成功绕过其他不同比较器,表明其具备可转移性?
- RQ4保护特定人脸识别比较器是否能防止MII攻击?还是说不同模型间表征空间的相似性构成根本性限制?
- RQ5表征空间中的类内方差在多大程度上促进或缓解了MII攻击?
主要发现
- 人脸识别系统易受MII攻击,因为匹配对与非匹配对在表征空间中的夹角距离分布仅被适度分离,分别约为90°和40–60°。
- 理论上理想的MII(与各组成身份夹角约45°)足以欺骗验证系统,因为其落入匹配阈值范围内。
- 表征空间反演与图像空间形变方法生成的MIIs足够接近理想状态,因而具有实际有效性,可成功实施伪装攻击。
- 画廊搜索方法虽可生成MIIs,但需要规模大到不切实际的数据库,因此相比基于优化的方法,实用性较低。
- 由于不同比较器的底层表征空间具有相似性,MIIs可在不同比较器间实现可转移性,表明仅保护单一比较器不足以构成有效防御。
- 即使采用如角度边界损失等改进的训练目标,若未调整匹配阈值以适应理想MII的分布,比较器依然易受MII攻击影响。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。