仅用1万次查询,就能生成可物理实施的面部识别攻击贴图。
Real-World Transferable Adversarial Attack on Face-Recognition Systems
- 用零阶贪心算法逐步添加高斯斑点,生成对称灰度贴图。
- 在1万次查询内达成数字与真实世界双重高成功率攻击。
- 无需白盒信息,可跨模型欺骗未见过的FaceNet系统。
针对人脸识别(FR)系统的对抗攻击构成重大安全威胁,但多数局限于数字域或需白盒访问。本文提出GaP(Gaussian Patch),一种在严格黑盒设置下生成通用、物理可转移对抗贴图的新方法。该方法采用查询高效的零阶贪心算法,迭代构建额头区域的对称灰度图案,通过持续添加高斯斑点并仅依赖替代FR模型的余弦相似度得分进行优化,以最大程度降低身份识别准确率。实验表明,仅需约10,000次对黑盒ArcFace模型的查询,所生成的GaP在数字和真实世界测试中均实现高攻击成功率。关键的是,该攻击具备强迁移能力,成功欺骗了完全未见过的FaceNet模型。本工作揭示了仅凭有限系统知识即可构造出鲁棒且可迁移攻击的现实威胁。
原文摘要 · Abstract (English)
Adversarial attacks on face recognition (FR) systems pose a significant security threat, yet most are confined to the digital domain or require white-box access. We introduce GaP (Gaussian Patch), a novel method to generate a universal, physically transferable adversarial patch under a strict black-box setting. Our approach uses a query-efficient, zero-order greedy algorithm to iteratively construct a symmetric, grayscale pattern for the forehead. The patch is optimized by successively adding Gaussian blobs, guided only by the cosine similarity scores from a surrogate FR model to maximally degrade identity recognition. We demonstrate that with approximately 10,000 queries to a black-box ArcFace model, the resulting GaP achieves a high attack success rate in both digital and real-world physical tests. Critically, the attack shows strong transferability, successfully deceiving an entirely unseen FaceNet model. Our work highlights a practical and severe vulnerability, proving that robust, transferable attacks can be crafted with limited knowledge of the target system.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。