Simulated Adversarial Testing of Face Recognition Models
Nataniel Ruiz, Adam Kortylewski, Weichao Qiu, Cihang Xie, Sarah Adel Bargal, Alan L. Yuille, Stan Sclaroff
Abstract
Most machine learning models are validated and tested on fixed datasets. This can give an incomplete picture of the capabilities and weaknesses of the model. Such weaknesses can be revealed at test time in the real world. The risks involved in such failures can be loss of profits, loss of time or even loss of life in certain critical applications. In order to alleviate this issue, simulators can be controlled in a finegrained manner using interpretable parameters to explore the semantic image manifold. In this work, we propose a framework for learning how to test machine learning algorithms using simulators in an adversarial manner in order to find weaknesses in the model before deploying it in critical scenarios. We apply this method in a face recognition setup. We show that certain weaknesses of models trained on real data can be discovered using simulated samples. Using our proposed method, we can find adversarial synthetic faces that fool contemporary face recognition models. This demonstrates the fact that these models have weaknesses that are not measured by commonly used validation datasets. We hypothesize that this type of adversarial examples are not isolated, but usually lie in connected spaces in the latent space of the simulator. We present a method to find these adversarial regions as opposed to the typical adversarial points found in the adversarial example literature.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Can You Rely on Your Model Evaluation? Improving Model Evaluation with Synthetic Test DataBoris van Breugel, Nabeel Seedat, Fergus Imrie, Mihaela van der SchaarNeurIPS 2023 · 51 citations
- 3D-Aware Neural Body Fitting for Occlusion Robust 3D Human Pose EstimationYi Zhang, Pengliang Ji, Angtian Wang, Jieru Mei et al.ICCV 2023 · 44 citations
- From Plane Crashes to Algorithmic Harm: Applicability of Safety Engineering Frameworks for Responsible MLShalaleh Rismani, Renee Shelby, Andrew Smart, Edgar W. Jatho III et al.CHI 2023 · 33 citations
- PoseExaminer: Automated Testing of Out-of-Distribution Robustness in Human Pose and Shape EstimationQihao Liu, Adam Kortylewski, Alan L. YuilleCVPR 2023
Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Moment Matching for Multi-Source Domain AdaptationXingchao Peng, Qinxun Bai, Xide Xia, Zijun Huang et al.ICCV 2019 · 2,239 citations
- Learning an animatable detailed 3D face model from in-the-wild imagesYao Feng, Haiwen Feng, Michael J. Black, Timo BolkartSIGGRAPH 2021 · 662 citations
- Meta-Sim: Learning to Generate Synthetic DatasetsAmlan Kar, Aayush Prakash, Ming-Yu Liu, Eric Cameracci et al.ICCV 2019 · 272 citations
- Unadversarial Examples: Designing Objects for Robust VisionHadi Salman, Andrew Ilyas, Logan Engstrom, Sai Vemprala et al.NeurIPS 2021 · 65 citations
Related papers
- Natural Adversarial ExamplesDan Hendrycks, Kevin Zhao, Steven Basart, Jacob Steinhardt et al.CVPR 2021
- Identifying Model Weakness with Adversarial ExaminerMichelle Shu, Chenxi Liu, Weichao Qiu, Alan L. YuilleAAAI 2020 · 23 citations
- Semantic Adversarial Attacks: Parametric Transformations That Fool Deep ClassifiersAmeya Joshi, Amitangshu Mukherjee, Soumik Sarkar, Chinmay HegdeICCV 2019 · 114 citations
- On the Need for Topology-Aware Generative Models for Manifold-Based DefensesUyeong Jang, Susmit Jha, Somesh JhaICLR 2020 · 15 citations
- Explanation by Progressive ExaggerationSumedha Singla, Brian Pollack, Junxiang Chen, Kayhan BatmanghelichICLR 2020 · 116 citations
