arXiv:2510.17169cs.CV2025-10中稿 · publication in DIC…

研究黑盒人脸识别中预处理对对抗攻击效果的影响,发现预处理方式会显著降低攻击成功率。

Investigating Adversarial Robustness against Preprocessing used in Blackbox Face Recognition

  • 对比多种预处理方法对对抗攻击的干扰,分析其影响机制
  • 预处理导致攻击成功率最高下降78%,插值方法影响较小
  • 提出不变预处理的输入变换方法,提升攻击迁移性27%

人脸识别模型易受微小扰动的对抗样本攻击,暴露系统漏洞并威胁隐私。端到端识别系统在计算深度特征相似度前需对人脸图像进行预处理。尽管预处理是识别系统的关键环节,但在黑盒攻击中常被忽视。本文研究了多种现成对抗攻击在不同预处理策略下的迁移能力。实验发现,人脸检测模型的选择可使攻击成功率下降高达78%,而下采样时的插值方法影响较小。此外,即使在白盒设置下,预处理也会因噪声向量与检测模型的意外交互而削弱攻击强度。基于此,我们提出一种基于输入变换的预处理无关方法,将攻击迁移性提升最多27%。研究强调了预处理在人脸识别系统中的关键作用,呼吁在对抗训练中考虑其对泛化性的深远影响。

原文摘要 · Abstract (English)

Face Recognition (FR) models have been shown to be vulnerable to adversarial examples that subtly alter benign facial images, exposing blind spots in these systems, as well as protecting user privacy. End-to-end FR systems first obtain preprocessed faces from diverse facial imagery prior to computing the similarity of the deep feature embeddings. Whilst face preprocessing is a critical component of FR systems, and hence adversarial attacks against them, we observe that this preprocessing is often overlooked in blackbox settings. Our study seeks to investigate the transferability of several out-of-the-box state-of-the-art adversarial attacks against FR when applied against different preprocessing techniques used in a blackbox setting. We observe that the choice of face detection model can degrade the attack success rate by up to 78%, whereas choice of interpolation method during downsampling has relatively minimal impacts. Furthermore, we find that the requirement for facial preprocessing even degrades attack strength in a whitebox setting, due to the unintended interaction of produced noise vectors against face detection models. Based on these findings, we propose a preprocessing-invariant method using input transformations that improves the transferability of the studied attacks by up to 27%. Our findings highlight the importance of preprocessing in FR systems, and the need for its consideration towards improving the adversarial generalisation of facial adversarial examples.

对抗攻击人脸识别预处理迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。