arXiv:2508.00620cs.CVcs.AI2025-08被引 2

攻击人脸检测模型,让其误定位关键点并引入后门。

Backdoor Attacks on Deep Learning Face Detection

  • 通过生成特定图像诱导检测器输出错误关键点位置。
  • 首次实现关键点坐标回归任务的后门攻击,成功率高。
  • 适合研究安全与防御的人工智能从业者参考。

在非受限环境下运行的人脸识别系统需应对光照不均、姿态多变等挑战,依赖人脸检测模块进行边界框回归与关键点坐标估计以实现正确对齐。本文首次揭示了针对人脸检测的物体生成攻击(即人脸生成攻击)的有效性,并提出一种全新的关键点偏移攻击,可对人脸检测器的坐标回归任务植入后门。实验验证了该攻击在多种主流检测器上的隐蔽性与鲁棒性。同时,论文还提出了相应的防御策略,为提升人脸检测系统的安全性提供了新思路。

原文摘要 · Abstract (English)

Face Recognition Systems that operate in unconstrained environments capture images under varying conditions,such as inconsistent lighting, or diverse face poses. These challenges require including a Face Detection module that regresses bounding boxes and landmark coordinates for proper Face Alignment. This paper shows the effectiveness of Object Generation Attacks on Face Detection, dubbed Face Generation Attacks, and demonstrates for the first time a Landmark Shift Attack that backdoors the coordinate regression task performed by face detectors. We then offer mitigations against these vulnerabilities.

人脸识别后门攻击安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。