Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face Recognition

被引:0
|
作者
Jia, Shuai [1 ]
Yin, Bangjie [2 ]
Yao, Taiping [2 ]
Ding, Shouhong [2 ]
Shen, Chunhua [3 ]
Yang, Xiaokang [1 ]
Ma, Chao [1 ]
机构
[1] Shanghai Jiao Tong Univ, AI Inst, MoE Key Lab Artificial Intelligence, Shanghai, Peoples R China
[2] Tencent, Youtu Lab, Shanghai, Peoples R China
[3] Zhejiang Univ, Hangzhou, Peoples R China
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep learning models have shown their vulnerability when dealing with adversarial attacks. Existing attacks almost perform on low-level instances, such as pixels and super-pixels, and rarely exploit semantic clues. For face recognition attacks, existing methods typically generate the l(p)-norm perturbations on pixels, however, resulting in low attack transferability and high vulnerability to denoising defense models. In this work, instead of performing perturbations on the low-level pixels, we propose to generate attacks through perturbing on the high-level semantics to improve attack transferability. Specifically, a unified flexible framework, Adversarial Attributes (Adv-Attribute), is designed to generate inconspicuous and transferable attacks on face recognition, which crafts the adversarial noise and adds it into different attributes based on the guidance of the difference in face recognition features from the target. Moreover, the importance-aware attribute selection and the multi-objective optimization strategy are introduced to further ensure the balance of stealthiness and attacking strength. Extensive experiments on the FFHQ and CelebA-HQ datasets show that the proposed Adv-Attribute method achieves the state-of-the-art attacking success rates while maintaining better visual effects against recent attack methods.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition
    Yin, Bangjie
    Wang, Wenxuan
    Yao, Taiping
    Guo, Junfeng
    Kong, Zelun
    Ding, Shouhong
    Li, Jilin
    Liu, Cong
    [J]. PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 1252 - 1258
  • [2] Toward Transferable Attack via Adversarial Diffusion in Face Recognition
    Hu, Cong
    Li, Yuanbo
    Feng, Zhenhua
    Wu, Xiaojun
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 5506 - 5519
  • [3] Towards Transferable Adversarial Attack Against Deep Face Recognition
    Zhong, Yaoyao
    Deng, Weihong
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 1452 - 1466
  • [4] Sibling-Attack: Rethinking Transferable Adversarial Attacks against Face Recognition
    Li, Zexin
    Yin, Bangjie
    Yao, Taiping
    Guo, Junfeng
    Ding, Shouhong
    Chen, Simin
    Liu, Cong
    [J]. 2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 24626 - 24637
  • [5] Transferable Black-Box Attack Against Face Recognition With Spatial Mutable Adversarial Patch
    Ma, Haotian
    Xu, Ke
    Jiang, Xinghao
    Zhao, Zeyu
    Sun, Tanfeng
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5636 - 5650
  • [6] Transferable Sparse Adversarial Attack on Modulation Recognition With Generative Networks
    Jiang, Zenghui
    Zeng, Weijun
    Zhou, Xingyu
    Chen, Pu
    Yin, Shenqian
    [J]. IEEE COMMUNICATIONS LETTERS, 2024, 28 (05) : 999 - 1003
  • [7] Generative Transferable Adversarial Attack
    Li, Yifeng
    Zhang, Ya
    Zhang, Rui
    Wang, Yanfeng
    [J]. ICVIP 2019: PROCEEDINGS OF 2019 3RD INTERNATIONAL CONFERENCE ON VIDEO AND IMAGE PROCESSING, 2019, : 84 - 89
  • [8] On Adversarial Robustness of Demographic Fairness in Face Attribute Recognition
    Zeng, Huimin
    Yue, Zhenrui
    Shang, Lanyu
    Zhang, Yang
    Wang, Dong
    [J]. PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 527 - 535
  • [9] Speckle-Variant Attack: Toward Transferable Adversarial Attack to SAR Target Recognition
    Peng, Bowen
    Peng, Bo
    Zhou, Jie
    Xia, Jingyuan
    Liu, Li
    [J]. IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2022, 19
  • [10] Adaptive Adversarial Patch Attack on Face Recognition Models
    Yan, Bei
    Zhang, Jie
    Yuan, Zheng
    Shan, Shiguang
    [J]. 2023 IEEE INTERNATIONAL JOINT CONFERENCE ON BIOMETRICS, IJCB, 2023,