arXiv:2409.16056cs.CVcs.AI2024-09

水印与扰动结合可隐藏攻击,使人脸识别失效

Adversarial Watermarking for Face Recognition

  • 将水印与对抗扰动结合,构造隐蔽攻击
  • 在2/255扰动下识别准确率降67.2%,4/255时降95.9%
  • 揭示水印系统潜在漏洞,适合安全研究者关注

水印技术是嵌入标识以维护数字图像所有权和监控非法修改的关键手段。在人脸识别系统中,水印对保障数据完整性和安全性至关重要。然而,攻击者可能干扰水印过程,严重损害识别性能。本文探讨了水印与对抗攻击在人脸识别模型中的相互作用。研究发现,单独使用水印或输入扰动对识别准确率影响甚微,但两者结合可引发对抗性水印攻击,显著降低识别效果。我们提出一种新型威胁模型——对抗性水印攻击:在无水印时保持隐蔽,可被正常识别;一旦应用水印,攻击即被激活,导致识别失败。该攻击利用水印信息绕过人脸识别系统。在CASIA-WebFace数据集上的评估显示,当ℓ∞范数扰动强度为2/255时,人脸匹配准确率下降67.2%;强度为4/255时下降95.9%。

原文摘要 · Abstract (English)

Watermarking is an essential technique for embedding an identifier (i.e., watermark message) within digital images to assert ownership and monitor unauthorized alterations. In face recognition systems, watermarking plays a pivotal role in ensuring data integrity and security. However, an adversary could potentially interfere with the watermarking process, significantly impairing recognition performance. We explore the interaction between watermarking and adversarial attacks on face recognition models. Our findings reveal that while watermarking or input-level perturbation alone may have a negligible effect on recognition accuracy, the combined effect of watermarking and perturbation can result in an adversarial watermarking attack, significantly degrading recognition performance. Specifically, we introduce a novel threat model, the adversarial watermarking attack, which remains stealthy in the absence of watermarking, allowing images to be correctly recognized initially. However, once watermarking is applied, the attack is activated, causing recognition failures. Our study reveals a previously unrecognized vulnerability: adversarial perturbations can exploit the watermark message to evade face recognition systems. Evaluated on the CASIA-WebFace dataset, our proposed adversarial watermarking attack reduces face matching accuracy by 67.2% with an $\ell_\infty$ norm-measured perturbation strength of ${2}/{255}$ and by 95.9% with a strength of ${4}/{255}$.

人脸识别对抗攻击水印安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。