article

Effective and Robust Physical-World Attacks on Deep Learning Face Recognition Systems

  • IEEE Transactions on Information Forensics and Security
  • Institute of Electrical and Electronics Engineers
Research footprint

At a glance

Citations
53
References
59
Comments
0
Paper overview

Abstract

Deep neural networks (DNNs) have been increasingly used in face recognition (FR) systems. Recent studies, however, show that DNNs are vulnerable to adversarial examples, which potentially mislead DNN-based FR systems in the physical world. Existing attacks either generate perturbations working merely in the digital world, or rely on customized equipment to generate perturbations that are not robust in the ever-changing physical environment. In this paper, we propose FaceAdv, a physical-world attack that crafts adversarial stickers to deceive FR systems. It mainly consists of a sticker generator and a convertor, where the former can craft several stickers with different shapes while the latter aims to digitally attach stickers to human faces and provide feedback to the generator to improve the effectiveness. We conduct extensive experiments to evaluate the effectiveness of FaceAdv on attacking three typical FR systems (i.e., ArcFace, CosFace and FaceNet). The results show that compared with a state-of-the-art attack, FaceAdv can significantly improve the success rates of both dodging and impersonating attacks. We also conduct comprehensive evaluations to demonstrate the robustness of FaceAdv.

Record transparency

Publication details

DOI
10.1109/tifs.2021.3102492
OpenAlex
W3192213611
Document type
article
Language
EN
Source
IEEE Transactions on Information Forensics and Security
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.