针对便携投影-相机系统,实现高保真的物理域对抗攻击。
Device-aware Optical Adversarial Attack for a Portable Projector-camera System
- 结合分辨率与色彩感知的设备自适应机制,提升攻击在物理世界的保真度。
- 数字到物理攻击成功率下降仅14%,白盒与黑盒场景均有效。
- 适用于真实部署的面部识别系统,对防伪检测有重要警示意义。
基于深度学习的面部识别(FR)系统在数字和物理领域均易受对抗样本攻击。物理攻击对已部署系统构成更大威胁,因攻击者可直接访问输入通道,伪造输入以冒充目标。本文针对现有投影-相机系统对抗光攻击在实际FR场景中的局限性,通过在数字攻击算法中引入设备感知的适应性调整,如分辨率感知与色彩感知,缓解从数字域到物理域的性能退化。实验验证表明,所提算法在真实与欺骗性攻击下均具高效性,在主流商业系统中实现了高物理相似度评分。平均而言,数字攻击到物理攻击的得分下降仅为14%,且在白盒与黑盒场景下均保持高攻击成功率。
原文摘要 · Abstract (English)
Deep-learning-based face recognition (FR) systems are susceptible to adversarial examples in both digital and physical domains. Physical attacks present a greater threat to deployed systems as adversaries can easily access the input channel, allowing them to provide malicious inputs to impersonate a victim. This paper addresses the limitations of existing projector-camera-based adversarial light attacks in practical FR setups. By incorporating device-aware adaptations into the digital attack algorithm, such as resolution-aware and color-aware adjustments, we mitigate the degradation from digital to physical domains. Experimental validation showcases the efficacy of our proposed algorithm against real and spoof adversaries, achieving high physical similarity scores in FR models and state-of-the-art commercial systems. On average, there is only a 14% reduction in scores from digital to physical attacks, with high attack success rate in both white- and black-box scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。