Improving Robustness of Facial Landmark Detection by Defending against Adversarial Attacks
Congcong Zhu, Xiaoqiang Li, Jide Li, Songmin Dai
Abstract
Many recent developments in facial landmark detection have been driven by stacking model parameters or augmenting annotations. However, three subsequent challenges remain, including 1) an increase in computational overhead, 2) the risk of overfitting caused by increasing model parameters, and 3) the burden of labor-intensive annotation by humans. We argue that exploring the weaknesses of the detector so as to remedy them is a promising method of robust facial landmark detection. To achieve this, we propose a sample-adaptive adversarial training (SAAT) approach to interactively optimize an attacker and a detector, which improves facial landmark detection as a defense against sample-adaptive black-box attacks. By leveraging adversarial attacks, the proposed SAAT exploits adversarial perturbations beyond the handcrafted transformations to improve the detector. Specifically, an attacker generates adversarial perturbations to reflect the weakness of the detector. Then, the detector must improve its robustness to adversarial perturbations to defend against adversarial attacks. Moreover, a sample-adaptive weight is designed to balance the risks and benefits of augmenting adversarial examples to train the detector. We also introduce a masked face alignment dataset, Masked-300W, to evaluate our method. Experiments show that our SAAT performed comparably to existing state-of-the-art methods. The dataset and model are publicly available at https: //github.com/zhuccly/SAAT .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6aecb922-4de7-4706-a9e8-77f96ea0c0c1Cited by top-tier papers2
- Occlusion-robust Face Alignment using A Viewpoint-invariant Hierarchical Network ArchitectureCongcong Zhu, Xintong Wan, Shaorong Xie, Xiaoqiang Li et al.CVPR 2022 · 16 citations
- Towards Robust 3D Pose Transfer with Adversarial LearningHaoyu Chen, Hao Tang, Ehsan Adeli, Guoying ZhaoCVPR 2024
Builds on6
- Aggregation via Separation: Boosting Facial Landmark Detector With Semi-Supervised Style TranslationShengju Qian, Keqiang Sun, Wayne Wu, Chen Qian et al.ICCV 2019 · 79 citations
- Towards Omni-Supervised Face Alignment for Large Scale Unlabeled VideosCongcong Zhu, Hao Liu, Zhenhua Yu, Xuehong SunAAAI 2020 · 11 citations
- Spatial-Temporal Knowledge Integration: Robust Self-Supervised Facial Landmark TrackingCongcong Zhu, Xiaoqiang Li, Jide Li, Guangtai Ding et al.ACM MM 2020 · 10 citations
- Attention-Driven Cropping for Very High Resolution Facial Landmark DetectionPrashanth Chandran, Derek Bradley, Markus Gross, Thabo BeelerCVPR 2020
- LUVLi Face Alignment: Estimating Landmarks' Location, Uncertainty, and Visibility LikelihoodAbhinav Kumar, Tim K. Marks, Wenxuan Mou, Ye Wang et al.CVPR 2020
Related papers
- Laplace Landmark LocalizationJoseph P. Robinson, Yuncheng Li, Ning Zhang, Yun Fu et al.ICCV 2019 · 49 citations
- I Can Hear You: Selective Robust Training for Deepfake Audio DetectionZirui Zhang, Wei Hao, Aroon Sankoh, William Lin et al.ICLR 2025
- Teacher Supervises Students How to Learn From Partially Labeled Images for Facial Landmark DetectionXuanyi Dong, Yi YangICCV 2019 · 75 citations
- Towards Effective Adversarial Textured 3D Meshes on Physical Face RecognitionXiao Yang, Chang Liu, Longlong Xu, Yikai Wang et al.CVPR 2023
- Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch DetectionJiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa et al.CVPR 2022 · 99 citations
