arXiv:2601.09806cs.CVcs.AI2026-01中稿 · publication in the…

用扩散模型生成难察觉的欺骗贴纸,骗过人脸验证系统并可检测。

Diffusion-Driven Deceptive Patches: Adversarial Manipulation and Forensic Detection in Facial Identity Verification

  • 用FGSM生成噪声贴纸,再用扩散模型提升隐蔽性。
  • 贴纸使人脸识别错误率升至87.3%,但视觉上仍自然。
  • 结合ViT-GPT2生成描述,适合安全测试与司法取证。

本文提出端到端的对抗贴纸生成、优化与评估流程,用于破坏人脸生物识别系统,适用于司法分析与安全测试。采用FGSM生成针对身份分类器的对抗噪声,并利用反向扩散模型通过高斯平滑和自适应亮度校正增强隐蔽性,实现合成对抗贴纸的逃避检测。将优化后的贴纸应用于人脸图像,测试其在保持自然视觉特征前提下的识别规避能力。使用视觉变换器-ViT-GPT2模型生成对抗图像的身份语义描述,支持身份规避与识别攻击的司法解释与记录。该流程评估了身份分类、图像描述结果及表情识别在对抗条件下的变化。进一步通过感知哈希与分割技术有效检测与分析对抗贴纸与样本,达到0.95的SSIM值。

原文摘要 · Abstract (English)

This work presents an end-to-end pipeline for generating, refining, and evaluating adversarial patches to compromise facial biometric systems, with applications in forensic analysis and security testing. We utilize FGSM to generate adversarial noise targeting an identity classifier and employ a diffusion model with reverse diffusion to enhance imperceptibility through Gaussian smoothing and adaptive brightness correction, thereby facilitating synthetic adversarial patch evasion. The refined patch is applied to facial images to test its ability to evade recognition systems while maintaining natural visual characteristics. A Vision Transformer (ViT)-GPT2 model generates captions to provide a semantic description of a person's identity for adversarial images, supporting forensic interpretation and documentation for identity evasion and recognition attacks. The pipeline evaluates changes in identity classification, captioning results, and vulnerabilities in facial identity verification and expression recognition under adversarial conditions. We further demonstrate effective detection and analysis of adversarial patches and adversarial samples using perceptual hashing and segmentation, achieving an SSIM of 0.95.

对抗攻击人脸验证扩散模型伪造检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。