ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via Projector
Yuanwei Liu, Hui Wei, Chengyu Jia, Ruqi Xiao, Weijian Ruan, Xingxing Wei, Joey Tianyi Zhou, Zheng Wang
Abstract
Previous physical adversarial attacks have shown that carefully crafted perturbations can deceive face recognition systems, revealing critical security vulnerabilities. However, these attacks often struggle to impersonate multiple targets and frequently fail to bypass liveness detection. For example, attacks using human-skin masks [28] are challenging to fabricate, inconvenient to swap between users, and often fail liveness detection due to facial occlusions. A projector, however, can generate content-rich light without obstructing the face, making it ideal for non-intrusive attacks. Thus, we propose a novel physical adversarial attack using a projector and explore the superposition of projected and natural light to create adversarial facial images. This approach eliminates the need for physical artifacts on the face, effectively overcoming these limitations. Specifically, our proposed ProjAttacker generates adversarial 3D textures that are projected onto human faces. To ensure physical realizability, we introduce a light reflection function that models complex optical interactions between projected light and human skin, accounting for reflection and diffraction effects. Furthermore, we incorporate camera Image Signal Processing (ISP) simulation to maintain the robustness of adversarial perturbations across real-world diverse imaging conditions. Comprehensive evaluations conducted in both digital and physical scenarios validate the effectiveness of our method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ba453a45-50dc-4c64-94c3-9f386b5791caCited by top-tier papers3
- FeatureFool: Zero-Query Fooling of Video Models via Feature MapDuoxun Tang, Xi Xiao, Guangwu Hu, Kangkang Sun et al.CVPR 2026 · 1 citation
- Casting the Net! Revisiting MasterFace Impersonation AttacksSeunghun Paik, Sunpill Kim, Chanwoo Hwang, Jae Hong SeoCCS 2026
- CamPI: Physical Adversarial Examples through Camera Power Signal InjectionYanze Ren, Mingyuan Lv, Qinhong Jiang, Yan Jiang et al.CVPR 2026
Builds on7
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
- Privacy-Preserving Face Recognition Using Trainable Feature SubtractionYuxi Mi, Zhizhou Zhong, Yuge Huang, Jiazhen Ji et al.CVPR 2024 · 24 citations
- Rethinking Impersonation and Dodging Attacks on Face Recognition SystemsFengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng et al.ACM MM 2024 · 9 citations
- Improving Transferability of Adversarial Patches on Face Recognition With Generative ModelsZihao Xiao, Xianfeng Gao, Chilin Fu, Yinpeng Dong et al.CVPR 2021
Related papers
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image ClassifiersBingyao Huang, Haibin LingIEEE VR 2022 · 16 citations
- Physical-World Optical Adversarial Attacks on 3D Face RecognitionYanjie Li, Yiquan Li, Xuelong Dai, Songtao Guo et al.CVPR 2023
- Towards Effective Adversarial Textured 3D Meshes on Physical Face RecognitionXiao Yang, Chang Liu, Longlong Xu, Yikai Wang et al.CVPR 2023
- Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face RecognitionShuai Yuan, Hongwei Li, Rui Zhang, Hangcheng Cao et al.ICML 2025
- Virtual U: Defeating Face Liveness Detection by Building Virtual Models from Your Public PhotosYi Xu, True Price, Jan-Michael Frahm, Fabian MonroseUSENIX Security 2016 · 94 citations
