Face Reconstruction Transfer Attack as Out-of-Distribution Generalization

被引:0
|
作者
June, Yoon Gyo [1 ]
Park, Jaewoo [2 ]
Dong, Xingbo [3 ]
Park, Hojin [4 ]
Teoh, Andrew Beng Jin [5 ]
Camps, Octavia [1 ]
机构
[1] Northeastern Univ, Boston, MA 02115 USA
[2] AiV Co, Cambridge, England
[3] Anhui Univ, Hefei, Peoples R China
[4] Hanwha Vis, Seongnam, South Korea
[5] Yonsei Univ, Seoul, South Korea
来源
关键词
Face Reconstruction Transfer Attack; Face Identity Reconstruction; Out-of-Distribution Generalization;
D O I
10.1007/978-3-031-73226-3_23
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Understanding the vulnerability of face recognition systems to malicious attacks is of critical importance. Previous works have focused on reconstructing face images that can penetrate a targeted verification system. Even in the white-box scenario, however, naively reconstructed images misrepresent the identity information, hence the attacks are easily neutralized once the face system is updated or changed. In this paper, we aim to reconstruct face images which are capable of transferring face attacks on unseen encoders. We term this problem as Face Reconstruction Transfer Attack (FRTA) and show that it can be formulated as an out-of-distribution (OOD) generalization problem. Inspired by its OOD nature, we propose to solve FRTA by Averaged Latent Search and Unsupervised Validation with pseudo target (ALSUV). To strengthen the reconstruction attack on OOD unseen encoders, ALSUV reconstructs the face by searching the latent of amortized generator Style-GAN2 through multiple latent optimization, latent optimization trajectory averaging, and unsupervised validation with a pseudo target. We demonstrate the efficacy and generalization of our method on widely used face datasets, accompanying it with extensive ablation studies and visually, qualitatively, and quantitatively analyses. Code: https://github.com/jungyg/ALSUV.git
引用
收藏
页码:396 / 413
页数:18
相关论文
共 50 条
  • [1] Assaying Out-Of-Distribution Generalization in Transfer Learning
    Wenzel, Florian
    Dittadi, Andrea
    Gehler, Peter
    Simon-Gabriel, Carl-Johann
    Horn, Max
    Zietlow, Dominik
    Kernert, David
    Russell, Chris
    Brox, Thomas
    Schiele, Bernt
    Scholkopf, Bernhard
    Locatello, Francesco
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [2] Certifiable Out-of-Distribution Generalization
    Ye, Nanyang
    Zhu, Lin
    Wang, Jia
    Zeng, Zhaoyu
    Shao, Jiayao
    Peng, Chensheng
    Pan, Bikang
    Li, Kaican
    Zhu, Jun
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 9, 2023, : 10927 - 10935
  • [3] Out-of-Distribution Generalization in Kernel Regression
    Canatar, Abdulkadir
    Bordelon, Blake
    Pehlevan, Cengiz
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [4] Causal softmax for out-of-distribution generalization
    Luo, Jing
    Zhao, Wanqing
    Peng, Jinye
    DIGITAL SIGNAL PROCESSING, 2025, 156
  • [5] Out-of-distribution generalization for learning quantum dynamics
    Caro, Matthias C.
    Huang, Hsin-Yuan
    Ezzell, Nicholas
    Gibbs, Joe
    Sornborger, Andrew T.
    Cincio, Lukasz
    Coles, Patrick J.
    Holmes, Zoe
    NATURE COMMUNICATIONS, 2023, 14 (01)
  • [6] On the Adversarial Robustness of Out-of-distribution Generalization Models
    Zou, Xin
    Liu, Weiwei
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [7] On the Out-of-distribution Generalization of Probabilistic Image Modelling
    Zhang, Mingtian
    Zhang, Andi
    McDonagh, Steven
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [8] Out-of-distribution Generalization and Its Applications for Multimedia
    Wang, Xin
    Cui, Peng
    Zhu, Wenwu
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 5681 - 5682
  • [9] Out-of-Distribution Generalization With Causal Feature Separation
    Wang, Haotian
    Kuang, Kun
    Lan, Long
    Wang, Zige
    Huang, Wanrong
    Wu, Fei
    Yang, Wenjing
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (04) : 1758 - 1772
  • [10] A Stable Vision Transformer for Out-of-Distribution Generalization
    Yu, Haoran
    Liu, Baodi
    Wang, Yingjie
    Zhang, Kai
    Tao, Dapeng
    Liu, Weifeng
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT VIII, 2024, 14432 : 328 - 339