arXiv:2412.11735cs.CVcs.AI2024-12AAAI被引 11

用自然语言控制生成高迁移性的逼真伪造人脸攻击

Transferable Adversarial Face Attack with Text Controlled Attribute

  • 通过文本引导实现属性精准控制的对抗攻击
  • 在两个高分辨率数据集上实现高迁移性攻击
  • 适用于真实人脸识别系统测试,实用性强

传统对抗攻击通常在范数约束下生成,而无约束对抗样本具有语义明确的扰动。现有无约束伪造攻击对属性控制能力弱且迁移性差。本文提出文本可控属性攻击(TCA²),利用类别级个人softmax向量精确引导伪造攻击,并结合数据与模型增强策略,提升对未知目标模型的迁移能力。最后采用Style-GAN生成具有目标属性的逼真伪造人脸。在两个高分辨率人脸识别数据集上的实验表明,TCA²可生成自然语义引导、高迁移性的伪造人脸。进一步在真实系统Face++和阿里云上验证,证明该方法具备实际应用潜力。

原文摘要 · Abstract (English)

Traditional adversarial attacks typically produce adversarial examples under norm-constrained conditions, whereas unrestricted adversarial examples are free-form with semantically meaningful perturbations. Current unrestricted adversarial impersonation attacks exhibit limited control over adversarial face attributes and often suffer from low transferability. In this paper, we propose a novel Text Controlled Attribute Attack (TCA$^2$) to generate photorealistic adversarial impersonation faces guided by natural language. Specifically, the category-level personal softmax vector is employed to precisely guide the impersonation attacks. Additionally, we propose both data and model augmentation strategies to achieve transferable attacks on unknown target models. Finally, a generative model, \textit{i.e}, Style-GAN, is utilized to synthesize impersonated faces with desired attributes. Extensive experiments on two high-resolution face recognition datasets validate that our TCA$^2$ method can generate natural text-guided adversarial impersonation faces with high transferability. We also evaluate our method on real-world face recognition systems, \textit{i.e}, Face++ and Aliyun, further demonstrating the practical potential of our approach.

对抗攻击人脸伪造文本控制高迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。