arXiv:2506.19533cs.CVcs.CR2025-06中稿 · ICIP 2021被引 9

找出人脸识别模型中可被现实触发的隐藏后门

Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks

  • 通过分析模型响应,检测并定位自然存在的物理触发器
  • 在真实攻击场景中,识别准确率达74%(基线56%)
  • 适合安全评估与对抗样本防御研究者使用

后门攻击会在深度神经网络中嵌入隐藏功能,当输入包含特定模式的触发器时,模型会表现出异常行为,而正常测试数据上表现良好。近期研究表明,人脸识别系统可能对自然外观的触发器(如特定太阳镜)产生响应,严重威胁高安全性应用。本文提出新方法,可检测人脸识别网络是否被自然、物理可实现的触发器感染,并在已知受感染网络情况下识别出具体触发器。实验表明,在一个受污染的面部识别网络中,我们的方法以74%的前五名准确率成功识别出绿色太阳镜或红色帽子等触发器,显著优于56%的暴力搜索基线。

原文摘要 · Abstract (English)

Backdoor attacks embed a hidden functionality into deep neural networks, causing the network to display anomalous behavior when activated by a predetermined pattern in the input Trigger, while behaving well otherwise on public test data. Recent works have shown that backdoored face recognition (FR) systems can respond to natural-looking triggers like a particular pair of sunglasses. Such attacks pose a serious threat to the applicability of FR systems in high-security applications. We propose a novel technique to (1) detect whether an FR network is compromised with a natural, physically realizable trigger, and (2) identify such triggers given a compromised network. We demonstrate the effectiveness of our methods with a compromised FR network, where we are able to identify the trigger (e.g., green sunglasses or red hat) with a top-5 accuracy of 74%, whereas a naive brute force baseline achieves 56% accuracy.

后门攻击人脸识别安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。