Discrete Point-Wise Attack is Not Enough: Generalized Manifold Adversarial Attack for Face Recognition
Qian Li, Yuxiao Hu, Ye Liu, Dongxiao Zhang, Xin Jin, Yuntian Chen
摘要
Classical adversarial attacks for Face Recognition (FR) models typically generate discrete examples for target identity with a single state image. However, such paradigm of point-wise attack exhibits poor generalization against numerous unknown states of identity and can be easily defended. In this paper, by rethinking the inherent relationship between the face of target identity and its variants, we introduce a new pipeline of Generalized Manifold Adversarial Attack (GMAA) 1 to achieve a better attack performance by expanding the attack range. Specifically, this expansion lies on two aspects -GMAA not only expands the target to be attacked from one to many to encourage a good generalization ability for the generated adversarial examples, but it also expands the latter from discrete points to manifold by leveraging the domain knowledge that face expression change can be continuous, which enhances the attack effect as a data augmentation mechanism did. Moreover, we further design a dual supervision with local and global constraints as a minor contribution to improve the visual quality of the generated adversarial examples. We demonstrate the effectiveness of our method based on extensive experiments, and reveal that GMAA promises a semantic continuous adversarial space with a higher generalization ability and visual quality.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Correction-based Defense Against Adversarial Video Attacks via Discretization-Enhanced Video Compressive SensingWei Song, Cong Cong, Haonan Zhong, Jingling XueUSENIX Security 2024 · 被引用 8 次
- GenSR: Symbolic regression based on equation generative spaceQian Li, Yuxiao Hu, Juncheng Liu, Yuntian ChenICLR 2026 · 被引用 7 次
- Detecting Misbehaviors of Large Vision-Language Models by Evidential Uncertainty QuantificationTao Huang, Rui Wang, Xiaofei Liu, Yi Qin 等ICLR 2026 · 被引用 4 次
- Unsegment Anything by Simulating DeformationJiahao Lu, Xingyi Yang, Xinchao WangCVPR 2024 · 被引用 1 次
- PolyJuice Makes It Real: Black-Box, Universal Red Teaming for Synthetic Image DetectorsSepehr Dehdashtian, Mashrur Mahmud Morshed, Jacob H. Seidman, Gaurav Bharaj 等NeurIPS 2025 · 被引用 1 次
它引用的顶会 Paper5
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li 等CVPR 2022 · 被引用 123 次
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su 等ICCV 2021 · 被引用 109 次
- Cascade EF-GAN: Progressive Facial Expression Editing With Local FocusesRongliang Wu, Gongjie Zhang, Shijian Lu, Tao ChenCVPR 2020
- Improving Transferability of Adversarial Patches on Face Recognition With Generative ModelsZihao Xiao, Xianfeng Gao, Chilin Fu, Yinpeng Dong 等CVPR 2021
相关 Paper
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang 等ACM MM 2020 · 被引用 40 次
- Robustness and Generalization via Generative Adversarial TrainingOmid Poursaeed, Tianxing Jiang, Harry Yang, Serge J. Belongie 等ICCV 2021 · 被引用 35 次
- Dual Manifold Adversarial Robustness: Defense against Lp and non-Lp Adversarial AttacksWei-An Lin, Chun Pong Lau, Alexander Levine, Rama Chellappa 等NeurIPS 2020 · 被引用 70 次
- Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network OnceJiangfan Han, Xiaoyi Dong, Ruimao Zhang, Dongdong Chen 等ICCV 2019 · 被引用 31 次
- CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating DeepfakesHao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang 等AAAI 2022 · 被引用 131 次
