用扩散模型生成逼真攻击人脸,骗过人脸识别系统
DiffAttack: Evasion Attacks Against Face Recognition via Latent Diffusion Models

- 在潜在空间优化生成目标身份的对抗性人脸
- 平均攻击成功率84.86%,超越现有方法
- 跨性别跨群体攻击效果好,适合安全测试场景
人脸生物识别依赖高维嵌入空间中用户特征的独特性。然而,深度人脸识别(FR)系统的决策边界往往过于狭窄,易受对抗攻击影响。在此类情况下,系统无法区分真实人脸与精心构造的对抗性人脸。现有针对人脸生物识别的对抗方法在性能和生成图像质量上均受限,且在源与目标图像属于不同人口统计组或性别时常失效。为此,我们提出一种基于潜在空间优化的新型对抗人脸生成方法。利用潜在扩散模型直接引导生成过程,使其逼近目标身份嵌入,以欺骗人脸识别模型。所提出的DiffAttack框架在标准数据集(如FFHQ和CelebA-HQ)上进行了评估,显著优于现有对抗技术,在多个面部识别模型(如FaceNet)上实现了84.86%的平均攻击成功率。值得注意的是,DiffAttack展现出更强的迁移能力,在FFHQ和CelebA-HQ等数据集上,相比传统噪声方法提升超过15.28%,相比语义方法提升约5.21%。
原文摘要 · Abstract (English)
Facial biometric identification relies on the distinctiveness of user attributes within a high-dimensional embedding space. However, the decision boundaries of deep face recognition (FR) systems are often sufficiently narrow that they can be conflated, rendering the models vulnerable to adversarial attacks. In such scenarios, the FR system fails to distinguish between an authentic source and a meticulously crafted adversarial face. Existing adversarial methods targeting facial biometrics are limited in both performance and their ability to generate high-quality images that are imperceptible to humans. Moreover, these methods often fail when the source and target images belong to different demographic groups or genders. To address these limitations, we present a novel approach for adversarial face generation via latent-space optimization. We leverage latent diffusion models directly to guide generation toward target identity embeddings, as measured by a face recognition model. Our proposed \textbf{DiffAttack} framework has been evaluated on standard benchmarks, such as the FFHQ and CelebA-HQ datasets. DiffAttack significantly outperforms existing adversarial techniques, achieving a high average attack success rate of 84.86% across multiple face recognition models (e.g., FaceNet). Notably, DiffAttack demonstrates superior transferability, surpassing traditional noise-based methods by over 15.28% and semantic-based approaches by approximately 5.21% on benchmark datasets like FFHQ and CelebA-HQ.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。