Similarity-based Gray-box Adversarial Attack Against Deep Face Recognition

01/11/2022
by   Hanrui Wang, et al.
7

The majority of adversarial attack techniques perform well against deep face recognition when the full knowledge of the system is revealed (white-box). However, such techniques act unsuccessfully in the gray-box setting where the face templates are unknown to the attackers. In this work, we propose a similarity-based gray-box adversarial attack (SGADV) technique with a newly developed objective function. SGADV utilizes the dissimilarity score to produce the optimized adversarial example, i.e., similarity-based adversarial attack. This technique applies to both white-box and gray-box attacks against authentication systems that determine genuine or imposter users using the dissimilarity score. To validate the effectiveness of SGADV, we conduct extensive experiments on face datasets of LFW, CelebA, and CelebA-HQ against deep face recognition models of FaceNet and InsightFace in both white-box and gray-box settings. The results suggest that the proposed method significantly outperforms the existing adversarial attack techniques in the gray-box setting. We hence summarize that the similarity-base approaches to develop the adversarial example could satisfactorily cater to the gray-box attack scenarios for de-authentication.

READ FULL TEXT

page 1

page 6

research
10/15/2022

Is Face Recognition Safe from Realizable Attacks?

Face recognition is a popular form of biometric authentication and due t...
research
01/28/2023

Semantic Adversarial Attacks on Face Recognition through Significant Attributes

Face recognition is known to be vulnerable to adversarial face images. E...
research
06/15/2021

Securing Face Liveness Detection Using Unforgeable Lip Motion Patterns

Face authentication usually utilizes deep learning models to verify user...
research
03/09/2022

Controllable Evaluation and Generation of Physical Adversarial Patch on Face Recognition

Recent studies have revealed the vulnerability of face recognition model...
research
06/27/2021

Darker than Black-Box: Face Reconstruction from Similarity Queries

Several methods for inversion of face recognition models were recently p...
research
04/14/2021

Meaningful Adversarial Stickers for Face Recognition in Physical World

Face recognition (FR) systems have been widely applied in safety-critica...
research
03/01/2021

Am I a Real or Fake Celebrity? Measuring Commercial Face Recognition Web APIs under Deepfake Impersonation Attack

Recently, significant advancements have been made in face recognition te...

Please sign up or login with your details

Forgot password? Click here to reset