arXiv:2502.19710cs.CVcs.CR2025-02被引 3

用扩散模型生成语义扰动贴纸,高效欺骗人脸识别系统

SAP-DIFF: Semantic Adversarial Patch Generation for Black-Box Face Recognition Models via Diffusion Models

  • 在隐空间通过语义扰动生成对抗贴纸,不直接改像素
  • 攻击成功率提升45.66%,平均超过40%,查询次数减少40%
  • 适合研究人脸识别安全的人员,尤其关注对抗攻击者

为评估人脸识别(FR)模型的鲁棒性,现有研究多聚焦于通过局部扰动误导模型的对抗贴纸攻击。伪装攻击威胁重大,因对抗扰动能使攻击者冒充合法用户,导致数据泄露、系统损坏和资源滥用。然而,该领域的研究仍有限。现有方法在伪装攻击中表现不佳,主要受限于高攻击门槛、低成功率和大量查询需求。为此,本文提出SAP-DIFF方法,利用扩散模型在隐空间生成语义扰动贴纸,而非直接像素操作。引入注意力破坏机制,生成与原人脸无关的特征;设计方向性损失函数,引导扰动向目标身份特征空间对齐,从而提升攻击效果与效率。在多个主流FR模型与数据集上的实验表明,本方法优于当前最先进方法,平均攻击成功率提升45.66%(全部超过40%),查询次数减少约40%。

原文摘要 · Abstract (English)

Given the need to evaluate the robustness of face recognition (FR) models, many efforts have focused on adversarial patch attacks that mislead FR models by introducing localized perturbations. Impersonation attacks are a significant threat because adversarial perturbations allow attackers to disguise themselves as legitimate users. This can lead to severe consequences, including data breaches, system damage, and misuse of resources. However, research on such attacks in FR remains limited. Existing adversarial patch generation methods exhibit limited efficacy in impersonation attacks due to (1) the need for high attacker capabilities, (2) low attack success rates, and (3) excessive query requirements. To address these challenges, we propose a novel method SAP-DIFF that leverages diffusion models to generate adversarial patches via semantic perturbations in the latent space rather than direct pixel manipulation. We introduce an attention disruption mechanism to generate features unrelated to the original face, facilitating the creation of adversarial samples and a directional loss function to guide perturbations toward the target identity feature space, thereby enhancing attack effectiveness and efficiency. Extensive experiments on popular FR models and datasets demonstrate that our method outperforms state-of-the-art approaches, achieving an average attack success rate improvement of 45.66% (all exceeding 40%), and a reduction in the number of queries by about 40% compared to the SOTA approach

对抗攻击人脸识别扩散模型语义扰动

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。