Rethinking Impersonation and Dodging Attacks on Face Recognition Systems
Fengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng, Xuequan Lu, Lizhuang Ma, Hefei Ling
Abstract
Face Recognition (FR) systems can be easily deceived by adversarial examples that manipulate benign face images through imperceptible perturbations. Adversarial attacks on FR encompass two types: impersonation (targeted) attacks and dodging (untargeted) attacks. Previous methods often achieve a successful impersonation attack on FR, however, it does not necessarily guarantee a successful dodging attack on FR in the black-box setting. In this paper, our key insight is that the generation of adversarial examples should perform both impersonation and dodging attacks simultaneously. To this end, we propose a novel attack method termed as Adversarial Pruning (Adv-Pruning), to fine-tune existing adversarial examples to enhance their dodging capabilities while preserving their impersonation capabilities. Adv-Pruning consists of Priming, Pruning, and Restoration stages. Concretely, we propose Adversarial Priority Quantification to measure the region-wise priority of original adversarial perturbations, identifying and releasing those with minimal impact on absolute model output variances. Then, Biased Gradient Adaptation is presented to adapt the adversarial examples to traverse the decision boundaries of both the attacker and victim by adding perturbations favoring dodging attacks on the vacated regions, preserving the prioritized features of the original perturbations while boosting dodging performance. As a result, we can maintain the impersonation capabilities of original adversarial examples while effectively enhancing dodging capabilities. Comprehensive experiments demonstrate the superiority of our method compared with state-of-the-art adversarial attack methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR StrategyWenshu Fan, Minxing Zhang, Hongwei Li, Wenbo Jiang et al.CCS 2025 · 1 citation
- Recoverable Facial Identity Protection via Adaptive Makeup Transfer Adversarial AttacksXiyao Liu, Junxing Ma, Xinda Wang, Qianyu Lin et al.AAAI 2025 · 1 citation
- ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via ProjectorYuanwei Liu, Hui Wei, Chengyu Jia, Ruqi Xiao et al.CVPR 2025
- Improving the Transferability of Adversarial Attacks on Face Recognition with Diverse Parameters AugmentationFengfan Zhou, Bangjie Yin, Hefei Ling, Qianyu Zhou et al.CVPR 2025
Builds on36
- Racial Faces in the Wild: Reducing Racial Bias by Information Maximization Adaptation NetworkMei Wang, Weihong Deng, Jiani Hu, Xunqiang Tao et al.ICCV 2019 · 379 citations
- Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language ModelsErfan Shayegani, Yue Dong, Nael B. Abu-GhazalehICLR 2024 · 271 citations
- Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial ExamplesChumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang et al.ICML 2023 · 200 citations
- Mis-Classified Vector Guided Softmax Loss for Face RecognitionXiaobo Wang, Shifeng Zhang, Shuo Wang, Tianyu Fu et al.AAAI 2020 · 188 citations
- Set-level Guidance Attack: Boosting Adversarial Transferability of Vision-Language Pre-training ModelsDong Lu, Zhiqiang Wang, Teng Wang, Weili Guan et al.ICCV 2023 · 141 citations
Related papers
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang et al.ACM MM 2020 · 40 citations
- The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face RecognitionYe Wang, Zeyan Liu, Bo Luo, Rongqing Hui et al.CCS 2024 · 2 citations
- FaceSec: A Fine-Grained Robustness Evaluation Framework for Face Recognition SystemsLiang Tong, Zhengzhang Chen, Jingchao Ni, Wei Cheng et al.CVPR 2021
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding et al.NeurIPS 2022 · 84 citations
- NullSwap: Proactive Identity Cloaking Against Deepfake Face SwappingTianyi Wang, Shuaicheng Niu, Harry Cheng, Xiao Zhang et al.ICCV 2025 · 4 citations
