系统梳理针对人脸识别的物理对抗攻击方法与防御策略。
A Survey on Physical Adversarial Attacks against Face Recognition Systems
- 按物理载体将攻击方法分为三类,分析其演进路径。
- 总结现有防御手段,揭示当前研究空白。
- 适合关注安全攻防与实际应用的从业者阅读。
随着人脸识别技术在金融、军事、公共安全及日常生活中广泛应用,其安全性问题日益突出。针对真实场景下人脸识别系统的物理对抗攻击因其现实可行性和严重威胁性,受到广泛关注。然而,目前尚缺乏聚焦此类攻击的系统性综述,制约了对领域挑战与未来方向的深入探索。本文通过全面收集和分析针对人脸识别系统的物理对抗攻击方法,首先探讨了物理攻击面临的关键挑战;随后基于所用物理介质,将现有攻击方法分为三类,并梳理各领域的研究演进过程;进一步回顾了当前防御策略,讨论了潜在的研究方向。旨在为物理对抗攻击提供全面且深入的理解,激发该领域的相关研究。
原文摘要 · Abstract (English)
As Face Recognition (FR) technology becomes increasingly prevalent in finance, the military, public safety, and everyday life, security concerns have grown substantially. Physical adversarial attacks targeting FR systems in real-world settings have attracted considerable research interest due to their practicality and the severe threats they pose. However, a systematic overview focused on physical adversarial attacks against FR systems is still lacking, hindering an in-depth exploration of the challenges and future directions in this field. In this paper, we bridge this gap by comprehensively collecting and analyzing physical adversarial attack methods targeting FR systems. Specifically, we first investigate the key challenges of physical attacks on FR systems. We then categorize existing physical attacks into three categories based on the physical medium used and summarize how the research in each category has evolved to address these challenges. Furthermore, we review current defense strategies and discuss potential future research directions. Our goal is to provide a fresh, comprehensive, and deep understanding of physical adversarial attacks against FR systems, thereby inspiring relevant research in this area.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。