arXiv:2602.19539cs.CVcs.CR2026-02

简单化妆就能骗过AI年龄识别,实测成功率最高达83%。

Can a Teenager Fool an AI? Evaluating Low-Cost Cosmetic Attacks on Age Estimation Systems

  • 用合成胡须、灰发等日常美妆模拟攻击,测试模型漏洞。
  • 四类攻击组合使平均年龄误判升高7.7岁,最高欺骗率83%。
  • 专用模型更易被攻破,视觉语言模型相对稳健,适合安全评估。

年龄估计系统正被广泛用于限制在线内容的访问权限,但其对化妆品修饰的鲁棒性尚未系统评估。我们研究了是否可通过简单、家庭可及的美容手段(如胡须、灰发、妆容、模拟皱纹)使AI将未成年人错误识别为成年人。为无伦理风险地大规模测试,我们使用VLM图像编辑器(Gemini 2.5 Flash Image)在329张10至21岁人群的面部图像上模拟这些物理攻击。随后评估了八个来自先前基准的模型:五种专用架构(MiVOLO、Custom-Best、Herosan、MiViaLab、DEX)和三种视觉-语言模型(Gemini 3 Flash、Gemini 2.5 Flash、GPT-5-Nano)。我们引入攻击转换率(ACR),定义为基线预测为未成年人的图像中,在攻击后转为成人的比例,该指标不依赖测试集中未成年人与成年人的比例。结果表明,仅合成胡须一项即在所有八种模型中产生28至69%的ACR;四种攻击组合使平均年龄预测值提升7.7年,最高达到83%的ACR;视觉-语言模型的ACR(59至71%)低于专用模型(63至83%),尽管存在重叠且未进行统计检验。研究揭示了部署式年龄验证流程中的关键脆弱性,并呼吁将对抗鲁棒性评估作为模型选型的强制标准。

原文摘要 · Abstract (English)

Age estimation systems are increasingly deployed as gatekeepers for age-restricted online content, yet their robustness to cosmetic modifications has not been systematically evaluated. We investigate whether simple, household-accessible cosmetic changes, including beards, grey hair, makeup, and simulated wrinkles, can cause AI age estimators to classify minors as adults. To study this threat at scale without ethical concerns, we simulate these physical attacks on 329 facial images of individuals aged 10 to 21 using a VLM image editor (Gemini 2.5 Flash Image). We then evaluate eight models from our prior benchmark: five specialized architectures (MiVOLO, Custom-Best, Herosan, MiViaLab, DEX) and three vision-language models (Gemini 3 Flash, Gemini 2.5 Flash, GPT-5-Nano). We introduce the Attack Conversion Rate (ACR), defined as the fraction of images predicted as minor at baseline that flip to adult after attack, a population-agnostic metric that does not depend on the ratio of minors to adults in the test set. Our results reveal that a synthetic beard alone achieves 28 to 69 percent ACR across all eight models; combining all four attacks shifts predicted age by +7.7 years on average across all 329 subjects and reaches up to 83 percent ACR; and vision-language models exhibit lower ACR (59 to 71 percent) than specialized models (63 to 83 percent) under the full attack, although the ACR ranges overlap and the difference is not statistically tested. These findings highlight a critical vulnerability in deployed age-verification pipelines and call for adversarial robustness evaluation as a mandatory criterion for model selection.

年龄估计对抗攻击视觉语言模型安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。