用视觉语言模型识别并消除人脸认证中的后门陷阱
From Detection to Correction: Backdoor-Resilient Face Recognition via Vision-Language Trigger Detection and Noise-Based Neutralization
- 通过多模型投票检测带后门的训练图像
- 100%准确修复中毒样本且不影响正常识别
- 适合需要高安全性的生物识别系统
基于深度神经网络的人脸识别系统依赖大规模敏感数据,易受后门攻击。攻击者通过在少数训练图像中加入小触发器(如贴纸、妆容或图案面具),可在认证时利用相同触发器冒充他人获取非法访问。现有防御方法难以精准识别并修复中毒样本,影响系统可靠性。本文提出TrueBiometric:一种通用且可靠的生物识别防护方案,利用多个先进视觉-语言模型的多数投票机制,准确检测中毒图像,并通过目标性、校准后的噪声实现修复。实验表明,该方法在不降低正常图像识别准确率的前提下,对中毒样本的检测与修正达到100%准确率,显著优于现有最先进方法。
原文摘要 · Abstract (English)
Biometric systems, such as face recognition systems powered by deep neural networks (DNNs), rely on large and highly sensitive datasets. Backdoor attacks can subvert these systems by manipulating the training process. By inserting a small trigger, such as a sticker, make-up, or patterned mask, into a few training images, an adversary can later present the same trigger during authentication to be falsely recognized as another individual, thereby gaining unauthorized access. Existing defense mechanisms against backdoor attacks still face challenges in precisely identifying and mitigating poisoned images without compromising data utility, which undermines the overall reliability of the system. We propose a novel and generalizable approach, TrueBiometric: Trustworthy Biometrics, which accurately detects poisoned images using a majority voting mechanism leveraging multiple state-of-the-art large vision language models. Once identified, poisoned samples are corrected using targeted and calibrated corrective noise. Our extensive empirical results demonstrate that TrueBiometric detects and corrects poisoned images with 100\% accuracy without compromising accuracy on clean images. Compared to existing state-of-the-art approaches, TrueBiometric offers a more practical, accurate, and effective solution for mitigating backdoor attacks in face recognition systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。