AdvHat: Real-world adversarial attack on ArcFace Face ID system
arXiv:1908.08705 · doi:10.1109/ICPR48806.2021.9412236
Abstract
In this paper we propose a novel easily reproducible technique to attack the best public Face ID system ArcFace in different shooting conditions. To create an attack, we print the rectangular paper sticker on a common color printer and put it on the hat. The adversarial sticker is prepared with a novel algorithm for off-plane transformations of the image which imitates sticker location on the hat. Such an approach confuses the state-of-the-art public Face ID model LResNet100E-IR, ArcFace@ms1m-refine-v2 and is transferable to other Face ID models.
References in corpus (9)
- Explaining and Harnessing Adversarial Examples
- Generative Adversarial Networks
- Learning Face Representation from Scratch
- YOLO9000: Better, Faster, Stronger
- Adversarial Examples that Fool Detectors
- Physical Adversarial Examples for Object Detectors
- Universal adversarial perturbations
- Seeing isn't Believing: Practical Adversarial Attack Against Object Detectors
- Web-Scale Training for Face Identification
Cited by in corpus (32)
- Benchmarking Adversarial Patch Against Aerial Detection
- Universal Adversarial Examples in Remote Sensing: Methodology and Benchmark
- Physical Adversarial Attack meets Computer Vision: A Decade Survey
- Towards Understanding and Boosting Adversarial Transferability from a Distribution Perspective
- Fawkes: Protecting Privacy against Unauthorized Deep Learning Models
- CBA: Contextual Background Attack against Optical Aerial Detection in the Physical World
- Adversarial Patch Attacks on Monocular Depth Estimation Networks
- Computing Systems for Autonomous Driving: State-of-the-Art and Challenges
- Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors
- PatchCensor: Patch Robustness Certification for Transformers via Exhaustive Testing
- Geometry-Inspired Top-k Adversarial Perturbations
- Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition
- Deep Learning for Face Anti-Spoofing: A Survey
- GhostImage: Remote Perception Attacks against Camera-based Image Classification Systems
- Improving the Transferability of Adversarial Attacks on Face Recognition with Beneficial Perturbation Feature Augmentation
- Securing Face Liveness Detection Using Unforgeable Lip Motion Patterns
- Patch-wise++ Perturbation for Adversarial Targeted Attacks
- Artificial Immune System of Secure Face Recognition Against Adversarial Attacks
- Design and Interpretation of Universal Adversarial Patches in Face Detection
- Detecting Localized Adversarial Examples: A Generic Approach using Critical Region Analysis
- Fast Gradient Non-sign Methods
- Region-Wise Attack: On Efficient Generation of Robust Physical Adversarial Examples
- Patch-wise Attack for Fooling Deep Neural Network
- Improving the Transferability of Adversarial Examples with New Iteration Framework and Input Dropout
- Towards Black-box Attacks on Deep Learning Apps
- From Pixels to Words: Leveraging Explainability in Face Recognition through Interactive Natural Language Processing
- Robust Attacks on Deep Learning Face Recognition in the Physical World
- Dodging Attack Using Carefully Crafted Natural Makeup
- Learning To Characterize Adversarial Subspaces
- Gödel's Sentence Is An Adversarial Example But Unsolvable
- A Systematical Solution for Face De-identification
- We Can Always Catch You: Detecting Adversarial Patched Objects WITH or WITHOUT Signature