arXiv:2505.03383cs.CV2025-05

提出注意力聚合攻击,提升人脸识别对抗样本的迁移能力。

Attention-aggregated Attack for Boosting the Transferability of Facial Adversarial Examples

  • 模仿目标模型注意力分布,攻击关键人脸特征
  • 在多个人脸识别模型上实现更高攻击成功率
  • 适合研究对抗攻击与人脸识别安全的学者

对抗样本揭示了深度学习模型的脆弱性,引发了信息安全领域的广泛关注。基于迁移的攻击是黑盒攻击中的热点,适用于训练数据、参数和结构未知的实际场景。然而,现有方法未充分考虑细粒度视觉任务(如人脸识别)中类别特定模型的独特性,导致攻击效果不佳。本文首先分析人脸识别模型嵌入学习的关键因素,发现决定性与辅助性面部特征均因模型而异,不同于人类视觉系统的生物机制。据此提出新型攻击方法——注意力聚合攻击(AAA),通过模拟其他人脸识别模型对原始图像的注意力分布,破坏其决策关键特征,从而提升对抗样本的迁移能力。在多种人脸识别模型上的大量实验验证了该方法在攻击成功率和鲁棒性方面的优越性。

原文摘要 · Abstract (English)

Adversarial examples have revealed the vulnerability of deep learning models and raised serious concerns about information security. The transfer-based attack is a hot topic in black-box attacks that are practical to real-world scenarios where the training datasets, parameters, and structure of the target model are unknown to the attacker. However, few methods consider the particularity of class-specific deep models for fine-grained vision tasks, such as face recognition (FR), giving rise to unsatisfactory attacking performance. In this work, we first investigate what in a face exactly contributes to the embedding learning of FR models and find that both decisive and auxiliary facial features are specific to each FR model, which is quite different from the biological mechanism of human visual system. Accordingly we then propose a novel attack method named Attention-aggregated Attack (AAA) to enhance the transferability of adversarial examples against FR, which is inspired by the attention divergence and aims to destroy the facial features that are critical for the decision-making of other FR models by imitating their attentions on the clean face images. Extensive experiments conducted on various FR models validate the superiority and robust effectiveness of the proposed method over existing methods.

对抗攻击人脸识别注意力机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。