Amora: Black-box Adversarial Morphing Attack
Run Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang, Xiaofei Xie, Lei Ma, Yang Liu
Abstract
Nowadays, digital facial content manipulation has become ubiquitous and realistic with the success of generative adversarial networks (GANs), making face recognition (FR) systems suffer from unprecedented security concerns. In this paper, we investigate and introduce a new type of adversarial attack to evade FR systems by manipulating facial content, called adversarial morphing attack (a.k.a. Amora). In contrast to adversarial noise attack that perturbs pixel intensity values by adding human-imperceptible noise, our proposed adversarial morphing attack works at the semantic level that perturbs pixels spatially in a coherent manner. To tackle the black-box attack problem, we devise a simple yet effective joint dictionary learning pipeline to obtain a proprietary optical flow field for each attack. Our extensive evaluation on two popular FR systems demonstrates the effectiveness of our adversarial morphing attack at various levels of morphing intensity with smiling facial expression manipulations. Both open-set and closed-set experimental results indicate that a novel black-box adversarial attack based on local deformation is possible, and is vastly different from additive noise attacks. The findings of this work potentially pave a new research direction towards a more thorough understanding and investigation of image-based adversarial attacks and defenses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bb596fea-fca9-4660-8cc2-323db5121209Cited by top-tier papers8
- DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat RhythmsHua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie et al.ACM MM 2020 · 224 citations
- EfficientDeRain: Learning Pixel-wise Dilation Filtering for High-Efficiency Single-Image DerainingQing Guo, Jingyang Sun, Felix Juefei-Xu, Lei Ma et al.AAAI 2021 · 120 citations
- Watch out! Motion is Blurring the Vision of Your Deep Neural NetworksQing Guo, Felix Juefei-Xu, Xiaofei Xie, Lei Ma et al.NeurIPS 2020 · 76 citations
- 3D-VField: Adversarial Augmentation of Point Clouds for Domain Generalization in 3D Object DetectionAlexander Lehner, Stefano Gasperini, Alvaro Marcos-Ramiro, Michael Schmidt et al.CVPR 2022 · 61 citations
- Cats Are Not Fish: Deep Learning Testing Calls for Out-Of-Distribution AwarenessDavid Berend, Xiaofei Xie, Lei Ma, Lingjun Zhou et al.ASE 2020 · 56 citations
Builds on7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Image2StyleGAN: How to Embed Images Into the StyleGAN Latent Space?Rameen Abdal, Yipeng Qin, Peter WonkaICCV 2019 · 1,195 citations
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat RhythmsHua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie et al.ACM MM 2020 · 224 citations
Related papers
- Towards Effective Adversarial Textured 3D Meshes on Physical Face RecognitionXiao Yang, Chang Liu, Longlong Xu, Yikai Wang et al.CVPR 2023
- Face Reconstruction from Facial Templates by Learning Latent Space of a Generator NetworkHatef Otroshi-Shahreza, Sébastien MarcelNeurIPS 2023 · 48 citations
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding et al.NeurIPS 2022 · 84 citations
- Discrete Point-Wise Attack is Not Enough: Generalized Manifold Adversarial Attack for Face RecognitionQian Li, Yuxiao Hu, Ye Liu, Dongxiao Zhang et al.CVPR 2023
- Exploring Frequency Adversarial Attacks for Face Forgery DetectionShuai Jia, Chao Ma, Taiping Yao, Bangjie Yin et al.CVPR 2022 · 78 citations
