用手机屏幕投射对抗补丁,骗过人脸识别摄像头
From Pixels to Reality: Physical-Digital Patch Attacks on Real-World Camera
- 用手机屏幕直接显示对抗补丁,无需打印
- 在真实场景中成功骗过多种商用识别系统
- 适合研究视觉安全与移动设备攻击的学者
本演示提出数字-物理对抗攻击(DiPA),一种针对广泛部署的基于摄像头的认证系统的新型实用攻击。攻击者将对抗补丁直接显示在智能手机屏幕上,而非依赖印刷物。这种纯数字的物理呈现方式实现了快速部署,无需总变差正则化,并提升了黑盒条件下的补丁迁移能力。DiPA融合了当前最先进的面部识别模型(ArcFace、MagFace、CosFace),增强了对未见商业系统的泛化能力。交互式演示展示了实时规避攻击效果:用户可动态调整补丁图案,观察其对感知管道的即时影响。实验表明,相较于现有物理攻击,DiPA在成功率、特征空间畸变和检测置信度降低方面表现更优,揭示了移动设备、普适视觉与传感器驱动认证基础设施之间的关键安全隐患。
原文摘要 · Abstract (English)
This demonstration presents Digital-Physical Adversarial Attacks (DiPA), a new class of practical adversarial attacks against pervasive camera-based authentication systems, where an attacker displays an adversarial patch directly on a smartphone screen instead of relying on printed artifacts. This digital-only physical presentation enables rapid deployment, removes the need for total-variation regularization, and improves patch transferability in black-box conditions. DiPA leverages an ensemble of state-of-the-art face-recognition models (ArcFace, MagFace, CosFace) to enhance transfer across unseen commercial systems. Our interactive demo shows a real-time dodging attack against a deployed face-recognition camera, preventing authorized users from being recognized while participants dynamically adjust patch patterns and observe immediate effects on the sensing pipeline. We further demonstrate DiPA's superiority over existing physical attacks in terms of success rate, feature-space distortion, and reductions in detection confidence, highlighting critical vulnerabilities at the intersection of mobile devices, pervasive vision, and sensor-driven authentication infrastructures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。