Using LIP to Gloss Over Faces in Single-Stage Face Detection Networks
arXiv:1712.08263
Abstract
This work shows that it is possible to fool/attack recent state-of-the-art face detectors which are based on the single-stage networks. Successfully attacking face detectors could be a serious malware vulnerability when deploying a smart surveillance system utilizing face detectors. We show that existing adversarial perturbation methods are not effective to perform such an attack, especially when there are multiple faces in the input image. This is because the adversarial perturbation specifically generated for one face may disrupt the adversarial perturbation for another face. In this paper, we call this problem the Instance Perturbation Interference (IPI) problem. This IPI problem is addressed by studying the relationship between the deep neural network receptive field and the adversarial perturbation. As such, we propose the Localized Instance Perturbation (LIP) that uses adversarial perturbation constrained to the Effective Receptive Field (ERF) of a target to perform the attack. Experiment results show the LIP method massively outperforms existing adversarial perturbation generation methods -- often by a factor of 2 to 10.
to appear ECCV 2018 (accepted version)
References in corpus (7)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Understanding the Effective Receptive Field in Deep Convolutional Neural Networks
- Houdini: Fooling Deep Structured Prediction Models
- From Facial Parts Responses to Face Detection: A Deep Learning Approach
- Adversarial Examples for Semantic Segmentation and Object Detection
- WIDER FACE: A Face Detection Benchmark