Rethinking Impersonation and Dodging Attacks on Face Recognition Systems
Fengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng, Xuequan Lu, Lizhuang Ma, Hefei Ling
摘要
Face Recognition (FR) systems can be easily deceived by adversarial examples that manipulate benign face images through imperceptible perturbations. Adversarial attacks on FR encompass two types: impersonation (targeted) attacks and dodging (untargeted) attacks. Previous methods often achieve a successful impersonation attack on FR, however, it does not necessarily guarantee a successful dodging attack on FR in the black-box setting. In this paper, our key insight is that the generation of adversarial examples should perform both impersonation and dodging attacks simultaneously. To this end, we propose a novel attack method termed as Adversarial Pruning (Adv-Pruning), to fine-tune existing adversarial examples to enhance their dodging capabilities while preserving their impersonation capabilities. Adv-Pruning consists of Priming, Pruning, and Restoration stages. Concretely, we propose Adversarial Priority Quantification to measure the region-wise priority of original adversarial perturbations, identifying and releasing those with minimal impact on absolute model output variances. Then, Biased Gradient Adaptation is presented to adapt the adversarial examples to traverse the decision boundaries of both the attacker and victim by adding perturbations favoring dodging attacks on the vacated regions, preserving the prioritized features of the original perturbations while boosting dodging performance. As a result, we can maintain the impersonation capabilities of original adversarial examples while effectively enhancing dodging capabilities. Comprehensive experiments demonstrate the superiority of our method compared with state-of-the-art adversarial attack methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR StrategyWenshu Fan, Minxing Zhang, Hongwei Li, Wenbo Jiang 等CCS 2025 · 被引用 1 次
- Recoverable Facial Identity Protection via Adaptive Makeup Transfer Adversarial AttacksXiyao Liu, Junxing Ma, Xinda Wang, Qianyu Lin 等AAAI 2025 · 被引用 1 次
- ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via ProjectorYuanwei Liu, Hui Wei, Chengyu Jia, Ruqi Xiao 等CVPR 2025
- Improving the Transferability of Adversarial Attacks on Face Recognition with Diverse Parameters AugmentationFengfan Zhou, Bangjie Yin, Hefei Ling, Qianyu Zhou 等CVPR 2025
它引用的顶会 Paper36
- Racial Faces in the Wild: Reducing Racial Bias by Information Maximization Adaptation NetworkMei Wang, Weihong Deng, Jiani Hu, Xunqiang Tao 等ICCV 2019 · 被引用 379 次
- Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language ModelsErfan Shayegani, Yue Dong, Nael B. Abu-GhazalehICLR 2024 · 被引用 271 次
- Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial ExamplesChumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang 等ICML 2023 · 被引用 200 次
- Mis-Classified Vector Guided Softmax Loss for Face RecognitionXiaobo Wang, Shifeng Zhang, Shuo Wang, Tianyu Fu 等AAAI 2020 · 被引用 188 次
- Set-level Guidance Attack: Boosting Adversarial Transferability of Vision-Language Pre-training ModelsDong Lu, Zhiqiang Wang, Teng Wang, Weili Guan 等ICCV 2023 · 被引用 141 次
相关 Paper
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang 等ACM MM 2020 · 被引用 40 次
- The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face RecognitionYe Wang, Zeyan Liu, Bo Luo, Rongqing Hui 等CCS 2024 · 被引用 2 次
- FaceSec: A Fine-Grained Robustness Evaluation Framework for Face Recognition SystemsLiang Tong, Zhengzhang Chen, Jingchao Ni, Wei Cheng 等CVPR 2021
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding 等NeurIPS 2022 · 被引用 84 次
- NullSwap: Proactive Identity Cloaking Against Deepfake Face SwappingTianyi Wang, Shuaicheng Niu, Harry Cheng, Xiao Zhang 等ICCV 2025 · 被引用 4 次
