Amora: Black-box Adversarial Morphing Attack
Run Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang, Xiaofei Xie, Lei Ma, Yang Liu
摘要
Nowadays, digital facial content manipulation has become ubiquitous and realistic with the success of generative adversarial networks (GANs), making face recognition (FR) systems suffer from unprecedented security concerns. In this paper, we investigate and introduce a new type of adversarial attack to evade FR systems by manipulating facial content, called adversarial morphing attack (a.k.a. Amora). In contrast to adversarial noise attack that perturbs pixel intensity values by adding human-imperceptible noise, our proposed adversarial morphing attack works at the semantic level that perturbs pixels spatially in a coherent manner. To tackle the black-box attack problem, we devise a simple yet effective joint dictionary learning pipeline to obtain a proprietary optical flow field for each attack. Our extensive evaluation on two popular FR systems demonstrates the effectiveness of our adversarial morphing attack at various levels of morphing intensity with smiling facial expression manipulations. Both open-set and closed-set experimental results indicate that a novel black-box adversarial attack based on local deformation is possible, and is vastly different from additive noise attacks. The findings of this work potentially pave a new research direction towards a more thorough understanding and investigation of image-based adversarial attacks and defenses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat RhythmsHua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie 等ACM MM 2020 · 被引用 224 次
- EfficientDeRain: Learning Pixel-wise Dilation Filtering for High-Efficiency Single-Image DerainingQing Guo, Jingyang Sun, Felix Juefei-Xu, Lei Ma 等AAAI 2021 · 被引用 120 次
- Watch out! Motion is Blurring the Vision of Your Deep Neural NetworksQing Guo, Felix Juefei-Xu, Xiaofei Xie, Lei Ma 等NeurIPS 2020 · 被引用 76 次
- 3D-VField: Adversarial Augmentation of Point Clouds for Domain Generalization in 3D Object DetectionAlexander Lehner, Stefano Gasperini, Alvaro Marcos-Ramiro, Michael Schmidt 等CVPR 2022 · 被引用 61 次
- Cats Are Not Fish: Deep Learning Testing Calls for Out-Of-Distribution AwarenessDavid Berend, Xiaofei Xie, Lei Ma, Lingjun Zhou 等ASE 2020 · 被引用 56 次
它引用的顶会 Paper7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Image2StyleGAN: How to Embed Images Into the StyleGAN Latent Space?Rameen Abdal, Yipeng Qin, Peter WonkaICCV 2019 · 被引用 1,195 次
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang 等CCS 2017 · 被引用 753 次
- DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat RhythmsHua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie 等ACM MM 2020 · 被引用 224 次
相关 Paper
- Towards Effective Adversarial Textured 3D Meshes on Physical Face RecognitionXiao Yang, Chang Liu, Longlong Xu, Yikai Wang 等CVPR 2023
- Face Reconstruction from Facial Templates by Learning Latent Space of a Generator NetworkHatef Otroshi-Shahreza, Sébastien MarcelNeurIPS 2023 · 被引用 48 次
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding 等NeurIPS 2022 · 被引用 84 次
- Discrete Point-Wise Attack is Not Enough: Generalized Manifold Adversarial Attack for Face RecognitionQian Li, Yuxiao Hu, Ye Liu, Dongxiao Zhang 等CVPR 2023
- Exploring Frequency Adversarial Attacks for Face Forgery DetectionShuai Jia, Chao Ma, Taiping Yao, Bangjie Yin 等CVPR 2022 · 被引用 78 次
