Black-box attacks on face recognition via affine-invariant training

被引:0
|
作者
Sun, Bowen [1 ]
Su, Hang [2 ]
Zheng, Shibao [1 ]
机构
[1] Shanghai Jiao Tong Univ, Dept Elect Engn, Shanghai 200240, Peoples R China
[2] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
来源
NEURAL COMPUTING & APPLICATIONS | 2024年 / 36卷 / 15期
基金
中国国家自然科学基金;
关键词
Face recognition; Black-box attack; Affine-invariant training; AI-block; EIGENFACES;
D O I
10.1007/s00521-024-09543-y
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural network (DNN)-based face recognition has shown impressive performance in verification; however, recent studies reveal a vulnerability in deep face recognition algorithms, making them susceptible to adversarial attacks. Specifically, these attacks can be executed in a black-box manner with limited knowledge about the target network. While this characteristic is practically significant due to hidden model details in reality, it presents challenges such as high query budgets and low success rates. To improve the performance of attacks, we establish the whole framework through affine-invariant training, serving as a substitute for inefficient sampling. We also propose AI-block-a novel module that enhances transferability by introducing generalized priors. Generalization is achieved by creating priors with stable features when sampled over affine transformations. These priors guide attacks, improving efficiency and performance in black-box scenarios. The conversion via AI-block enables the transfer gradients of a surrogate model to be used as effective priors for estimating the gradients of a black-box model. Our method leverages this enhanced transferability to boost both transfer-based and query-based attacks. Extensive experiments conducted on 5 commonly utilized databases and 7 widely employed face recognition models demonstrate a significant improvement of up to 11.9 percentage points in success rates while maintaining comparable or even reduced query times.
引用
收藏
页码:8549 / 8564
页数:16
相关论文
共 50 条
  • [1] Black-box attacks on face recognition via affine-invariant training
    Bowen Sun
    Hang Su
    Shibao Zheng
    Neural Computing and Applications, 2024, 36 : 8549 - 8564
  • [2] Efficient Decision-based Black-box Adversarial Attacks on Face Recognition
    Dong, Yinpeng
    Su, Hang
    Wu, Baoyuan
    Li, Zhifeng
    Liu, Wei
    Zhang, Tong
    Zhu, Jun
    2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 7706 - 7714
  • [3] Controllable Inversion of Black-Box Face Recognition Models via Diffusion
    Kansy, Manuel
    Rael, Anton
    Mignone, Graziana
    Naruniec, Jacek
    Schroers, Christopher
    Gross, Markus
    Weber, Romann M.
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION WORKSHOPS, ICCVW, 2023, : 3159 - 3169
  • [4] Black-box Adversarial Attacks on Video Recognition Models
    Jiang, Linxi
    Ma, Xingjun
    Chen, Shaoxiang
    Bailey, James
    Jiang, Yu-Gang
    PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA (MM'19), 2019, : 864 - 872
  • [5] Affine-invariant character recognition by progressive removing
    Iwamura, Masakazu
    Horimatsu, Akira
    Niwa, Ryo
    Kise, Koichi
    Uchida, Seiichi
    Omachi, Shinichiro
    ELECTRICAL ENGINEERING IN JAPAN, 2012, 180 (02) : 55 - 63
  • [6] Boosting Targeted Black-Box Attacks via Ensemble Substitute Training and Linear Augmentation
    Gao, Xianfeng
    Tan, Yu-an
    Jiang, Hongwei
    Zhang, Quanxin
    Kuang, Xiaohui
    APPLIED SCIENCES-BASEL, 2019, 9 (11):
  • [7] Heuristic Black-Box Adversarial Attacks on Video Recognition Models
    Wei, Zhipeng
    Chen, Jingjing
    Wei, Xingxing
    Jiang, Linxi
    Chua, Tat-Seng
    Zhou, Fengfeng
    Jiang, Yu-Gang
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 12338 - 12345
  • [8] Efficient Black-Box Adversarial Attacks with Training Surrogate Models Towards Speaker Recognition Systems
    Wang, Fangwei
    Song, Ruixin
    Li, Qingru
    Wang, Changguang
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT V, 2024, 14491 : 257 - 276
  • [9] A novel algorithm using affine-invariant features for pose-variant face recognition
    Zhao, Youen
    Li, Li
    Liu, Zhaoguang
    COMPUTERS & ELECTRICAL ENGINEERING, 2015, 46 : 217 - 230
  • [10] Affine-invariant Recognition of Handwritten Characters via Accelerated KL Divergence Minimization
    Wakahara, Toru
    Yamashita, Yukihiko
    11TH INTERNATIONAL CONFERENCE ON DOCUMENT ANALYSIS AND RECOGNITION (ICDAR 2011), 2011, : 1095 - 1099