arXiv:2412.07996cs.CVcs.CR2024-12中稿 · and Presented at A…

通过拼贴与缩放提升对抗补丁对人脸检测器的攻击效果

Enhancing Remote Adversarial Patch Attacks on Face Detectors with Tiling and Scaling

  • 针对人脸检测特点设计新型补丁布局与损失函数
  • 在多种尺度下均实现更高干扰成功率,优于通用目标检测攻击
  • 适合研究隐私防护或对抗样本防御的人员参考

本文探讨了针对人脸检测器的远程对抗补丁(RAP)攻击的可行性。尽管其原理与通用目标检测器的RAP相似,但人脸检测面临独特挑战:(1)需检测多尺度物体,小目标在卷积特征提取中感受野小,影响范围有限;(2)为二分类任务,类别间特征差异大,难以引导误检。为此,本文提出新的补丁放置策略与损失函数。实验表明,针对人脸检测器设计的补丁,在干扰效果上显著优于用于通用目标检测器的补丁。

原文摘要 · Abstract (English)

This paper discusses the attack feasibility of Remote Adversarial Patch (RAP) targeting face detectors. The RAP that targets face detectors is similar to the RAP that targets general object detectors, but the former has multiple issues in the attack process the latter does not. (1) It is possible to detect objects of various scales. In particular, the area of small objects that are convolved during feature extraction by CNN is small,so the area that affects the inference results is also small. (2) It is a two-class classification, so there is a large gap in characteristics between the classes. This makes it difficult to attack the inference results by directing them to a different class. In this paper, we propose a new patch placement method and loss function for each problem. The patches targeting the proposed face detector showed superior detection obstruct effects compared to the patches targeting the general object detector.

对抗攻击人脸检测补丁攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。