Towards Effective Adversarial Textured 3D Meshes on Physical Face Recognition
Xiao Yang, Chang Liu, Longlong Xu, Yikai Wang, Yinpeng Dong, Ning Chen, Hang Su, Jun Zhu
Abstract
Face recognition is a prevailing authentication solution in numerous biometric applications. Physical adversarial attacks, as an important surrogate, can identify the weaknesses of face recognition systems and evaluate their robustness before deployed. However, most existing physical attacks are either detectable readily or ineffective against commercial recognition systems. The goal of this work is to develop a more reliable technique that can carry out an endto-end evaluation of adversarial robustness for commercial systems. It requires that this technique can simultaneously deceive black-box recognition models and evade defensive mechanisms. To fulfill this, we design adversarial textured 3D meshes (AT3D) with an elaborate topology on a human face, which can be 3D-printed and pasted on the attacker's face to evade the defenses. However, the mesh-based optimization regime calculates gradients in high-dimensional mesh space, and can be trapped into local optima with unsatisfactory transferability. To deviate from the mesh-based space, we propose to perturb the low-dimensional coefficient space based on 3D Morphable Model, which significantly improves black-box transferability meanwhile enjoying faster search efficiency and better visual quality. Extensive experiments in digital and physical scenarios show that our method effectively explores the security vulnerabilities of multiple popular commercial services, including three recognition APIs, four anti-spoofing APIs, two prevailing mobile phones and two automated access control systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9e2cd457-5f16-4777-8428-474dfac88f3eCited by top-tier papers10
- Rethinking Impersonation and Dodging Attacks on Face Recognition SystemsFengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng et al.ACM MM 2024 · 9 citations
- HOIAnimator: Generating Text-Prompt Human-Object Animations Using Novel Perceptive Diffusion ModelsWenfeng Song, Xinyu Zhang, Shuai Li, Yang Gao et al.CVPR 2024 · 6 citations
- Embodied Active Defense: Leveraging Recurrent Feedback to Counter Adversarial PatchesLingxuan Wu, Xiao Yang, Yinpeng Dong, Liuwei Xie et al.ICLR 2024 · 6 citations
- Non-Adaptive Adversarial Face GenerationSunpill Kim, Seunghun Paik, Chanwoo Hwang, Minsu Kim et al.NeurIPS 2025 · 5 citations
- FacialFlowNet: Advancing Facial Optical Flow Estimation with a Diverse Dataset and a Decomposed ModelJianzhi Lu, Ruian He, Shili Zhou, Weimin Tan et al.ACM MM 2024 · 4 citations
Builds on7
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su et al.ICCV 2021 · 109 citations
- Isometric 3D Adversarial Examples in the Physical WorldYibo Miao, Yinpeng Dong, Jun Zhu, Xiao-Shan GaoNeurIPS 2022 · 45 citations
- Searching Central Difference Convolutional Networks for Face Anti-SpoofingZitong Yu, Chenxu Zhao, Zezheng Wang, Yunxiao Qin et al.CVPR 2020
- Deep Spatial Gradient and Temporal Depth Learning for Face Anti-SpoofingZezheng Wang, Zitong Yu, Chenxu Zhao, Xiangyu Zhu et al.CVPR 2020
Related papers
- Improving Transferability of Adversarial Patches on Face Recognition With Generative ModelsZihao Xiao, Xianfeng Gao, Chilin Fu, Yinpeng Dong et al.CVPR 2021
- Physical-World Optical Adversarial Attacks on 3D Face RecognitionYanjie Li, Yiquan Li, Xuelong Dai, Songtao Guo et al.CVPR 2023
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang et al.ACM MM 2020 · 40 citations
- Towards Transferable Targeted 3D Adversarial Attack in the Physical WorldYao Huang, Yinpeng Dong, Shouwei Ruan, Xiao Yang et al.CVPR 2024
- FaceSec: A Fine-Grained Robustness Evaluation Framework for Face Recognition SystemsLiang Tong, Zhengzhang Chen, Jingchao Ni, Wei Cheng et al.CVPR 2021
