arXiv:2603.15396cs.CVcs.AI2026-03

用单次生成的对抗补丁,实现跨摄像头人脸重识别系统的逃避与冒用攻击。

AI Evasion and Impersonation Attacks on Facial Re-Identification with Activation Map Explanations

  • 通过条件编码解码网络,一次前向传播生成对抗补丁。
  • 白盒攻击使mAP从90%降至0.4%,黑盒攻击从72%降至0.4%。
  • 结合激活图聚类分析攻击机制,助力未来防御设计。

人脸识别系统在监控中广泛应用,但其易受对抗性逃避与冒用攻击威胁。本文提出一种新框架,可生成同时支持逃避与冒用攻击的对抗补丁,适用于非重叠摄像头下的深度重识别模型。不同于需逐目标迭代优化的现有方法,本方法采用条件编码-解码网络,基于源图像与目标图像的多尺度特征,在单次前向传播中合成补丁,优化目标包含拉动与推动两项对抗损失。为增强隐蔽性并支持物理部署,进一步融合预训练潜空间扩散模型生成自然风格补丁。在标准行人重识别(Market-1501、DukeMTMC-reID)和人脸识别基准(CelebA-HQ、PubFig)上验证,白盒攻击使mAP由90%降至0.4%,黑盒攻击由72%降至0.4%,展现强跨模型泛化能力;定向冒用攻击在CelebA-HQ上成功率达27%,媲美其他补丁方法。此外,通过激活图聚类分析攻击所依赖的关键特征,提出未来防御路径。结果表明,对抗补丁对检索类系统具实际威胁,亟需构建鲁棒防御策略。

原文摘要 · Abstract (English)

Facial identification systems are increasingly deployed in surveillance and yet their vulnerability to adversarial evasion and impersonation attacks pose a critical risk. This paper introduces a novel framework for generating adversarial patches capable of both evasion and impersonation attacks against deep re-identification models across non-overlapping cameras. Unlike prior approaches that require iterative patch optimisation for each target, our method employs a conditional encoder-decoder network to synthesize adversarial patches in a single forward pass, guided by multi-scale features from source and target images. The patches are optimised with a dual adversarial objective comprising of pull and push terms. To enhance imperceptibility and aid physical deployment, we further integrate naturalistic patch generation using pre-trained latent diffusion models. Experiments on standard pedestrian (Market-1501, DukeMTMCreID) and facial recognition benchmarks (CelebA-HQ, PubFig) datasets demonstrate the effectiveness of the proposed method. Our adversarial evasion attacks reduce mean Average Precision from 90% to 0.4% in white-box settings and from 72% to 0.4% in black-box settings, showing strong cross-model generalization. In targeted impersonation attacks, our framework achieves a success rate of 27% on CelebA-HQ, competing with other patch-based methods. We go further to use clustering of activation maps to interpret which features are most used by adversarial attacks and propose a pathway for future countermeasures. The results highlight the practicality of adversarial patch attacks on retrieval-based systems and underline the urgent need for robust defense strategies.

对抗攻击人脸识别补丁攻击安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。