Towards Effective Adversarial Textured 3D Meshes on Physical Face Recognition
Xiao Yang, Chang Liu, Longlong Xu, Yikai Wang, Yinpeng Dong, Ning Chen, Hang Su, Jun Zhu
摘要
Face recognition is a prevailing authentication solution in numerous biometric applications. Physical adversarial attacks, as an important surrogate, can identify the weaknesses of face recognition systems and evaluate their robustness before deployed. However, most existing physical attacks are either detectable readily or ineffective against commercial recognition systems. The goal of this work is to develop a more reliable technique that can carry out an endto-end evaluation of adversarial robustness for commercial systems. It requires that this technique can simultaneously deceive black-box recognition models and evade defensive mechanisms. To fulfill this, we design adversarial textured 3D meshes (AT3D) with an elaborate topology on a human face, which can be 3D-printed and pasted on the attacker's face to evade the defenses. However, the mesh-based optimization regime calculates gradients in high-dimensional mesh space, and can be trapped into local optima with unsatisfactory transferability. To deviate from the mesh-based space, we propose to perturb the low-dimensional coefficient space based on 3D Morphable Model, which significantly improves black-box transferability meanwhile enjoying faster search efficiency and better visual quality. Extensive experiments in digital and physical scenarios show that our method effectively explores the security vulnerabilities of multiple popular commercial services, including three recognition APIs, four anti-spoofing APIs, two prevailing mobile phones and two automated access control systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Rethinking Impersonation and Dodging Attacks on Face Recognition SystemsFengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng 等ACM MM 2024 · 被引用 9 次
- HOIAnimator: Generating Text-Prompt Human-Object Animations Using Novel Perceptive Diffusion ModelsWenfeng Song, Xinyu Zhang, Shuai Li, Yang Gao 等CVPR 2024 · 被引用 6 次
- Embodied Active Defense: Leveraging Recurrent Feedback to Counter Adversarial PatchesLingxuan Wu, Xiao Yang, Yinpeng Dong, Liuwei Xie 等ICLR 2024 · 被引用 6 次
- Non-Adaptive Adversarial Face GenerationSunpill Kim, Seunghun Paik, Chanwoo Hwang, Minsu Kim 等NeurIPS 2025 · 被引用 5 次
- FacialFlowNet: Advancing Facial Optical Flow Estimation with a Diverse Dataset and a Decomposed ModelJianzhi Lu, Ruian He, Shili Zhou, Weimin Tan 等ACM MM 2024 · 被引用 4 次
它引用的顶会 Paper7
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su 等ICCV 2021 · 被引用 109 次
- Isometric 3D Adversarial Examples in the Physical WorldYibo Miao, Yinpeng Dong, Jun Zhu, Xiao-Shan GaoNeurIPS 2022 · 被引用 45 次
- Searching Central Difference Convolutional Networks for Face Anti-SpoofingZitong Yu, Chenxu Zhao, Zezheng Wang, Yunxiao Qin 等CVPR 2020
- Deep Spatial Gradient and Temporal Depth Learning for Face Anti-SpoofingZezheng Wang, Zitong Yu, Chenxu Zhao, Xiangyu Zhu 等CVPR 2020
相关 Paper
- Improving Transferability of Adversarial Patches on Face Recognition With Generative ModelsZihao Xiao, Xianfeng Gao, Chilin Fu, Yinpeng Dong 等CVPR 2021
- Physical-World Optical Adversarial Attacks on 3D Face RecognitionYanjie Li, Yiquan Li, Xuelong Dai, Songtao Guo 等CVPR 2023
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang 等ACM MM 2020 · 被引用 40 次
- Towards Transferable Targeted 3D Adversarial Attack in the Physical WorldYao Huang, Yinpeng Dong, Shouwei Ruan, Xiao Yang 等CVPR 2024
- FaceSec: A Fine-Grained Robustness Evaluation Framework for Face Recognition SystemsLiang Tong, Zhengzhang Chen, Jingchao Ni, Wei Cheng 等CVPR 2021
