Physical-World Optical Adversarial Attacks on 3D Face Recognition
Yanjie Li, Yiquan Li, Xuelong Dai, Songtao Guo, Bin Xiao
Abstract
The success rate of current adversarial attacks remains low on real-world 3D face recognition tasks because the 3D-printing attacks need to meet the requirement that the generated points should be adjacent to the surface, which limits the adversarial example' searching space. Additionally, they have not considered unpredictable head movements or the non-homogeneous nature of skin reflectance in the real world. To address the real-world challenges, we propose a novel structured-light attack against structuredlight-based 3D face recognition. We incorporate the 3D reconstruction process and skin's reflectance in the optimization process to get the end-to-end attack and present 3D transform invariant loss and sensitivity maps to improve robustness. Our attack enables adversarial points to be placed in any position and is resilient to random head movements while maintaining the perturbation unnoticeable. Experiments show that our new method can attack point-cloud-based and depth-image-based 3D face recognition systems with a high success rate, using fewer perturbations than previous physical 3D adversarial attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- ADBA: Approximation Decision Boundary Approach for Black-Box Adversarial AttacksFeiyang Wang, Xingquan Zuo, Hai Huang, Gang ChenAAAI 2025 · 14 citations
- When Lighting Deceives: Exposing Vision-Language Models' Illumination Vulnerability Through Illumination Transformation AttackHanqing Liu, Shouwei Ruan, Yao Huang, Shiji Zhao et al.ICCV 2025 · 13 citations
- Rethinking Impersonation and Dodging Attacks on Face Recognition SystemsFengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng et al.ACM MM 2024 · 9 citations
- UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV MappingYanjie Li, Kaisheng Liang, Bin XiaoICLR 2025
- Improving Transferable Targeted Attacks with Feature Tuning MixupKaisheng Liang, Xuelong Dai, Yanjie Li, Dong Wang et al.CVPR 2025
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Walk in the Cloud: Learning Curves for Point Clouds Shape AnalysisTiange Xiang, Chaoyi Zhang, Yang Song, Jianhui Yu et al.ICCV 2021 · 369 citations
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li et al.ICCV 2019 · 265 citations
Related papers
- Towards Effective Adversarial Textured 3D Meshes on Physical Face RecognitionXiao Yang, Chang Liu, Longlong Xu, Yikai Wang et al.CVPR 2023
- AE-Morpher: Improve Physical Robustness of Adversarial Objects against LiDAR-based Detectors via Object ReconstructionShenchen Zhu, Yue Zhao, Kai Chen, Bo Wang et al.USENIX Security 2024 · 13 citations
- DepthFake: Spoofing 3D Face Authentication with a 2D PhotoZhihao Wu, Yushi Cheng, Jiahui Yang, Xiaoyu Ji et al.S&P 2023
- 3D-Adv: Black-Box Adversarial Attacks against Deep Learning Models through 3D SensorsKaichen Yang, Xuan-Yi Lin, Yixin Sun, Tsung-Yi Ho et al.DAC 2021 · 3 citations
- Isometric 3D Adversarial Examples in the Physical WorldYibo Miao, Yinpeng Dong, Jun Zhu, Xiao-Shan GaoNeurIPS 2022 · 45 citations
