Research on adversarial attacks for facial recognition identifies and mitigates vulnerabilities in facial recognition systems, enhancing their security. Current adversarial attacks targeting facial attributes lack precision in controlling specific attributes, often altering multiple facial features instead of a single target attribute. Such imprecise modifications reduce the attack’s effectiveness and stealthiness. To address these issues, this paper proposes a method for generating adversarial examples based on multi-layer feature map fusion. First, we design a framework called StarAdv, which uses fused multi-layer feature maps with high concealment to achieve realistic facial image transformations under different attributes. This approach generates adversarial images visually similar to the originals while possessing specific misleading properties, enabling transferable attacks on facial recognition systems. Second, we introduce a Multi-layer Fusion module that captures weight information from each layer of the network’s residual blocks to adaptively fuse feature maps from different layers, producing high-concealment feature maps. Finally, we propose a Bilinear Feature Map Interpolation (BFMI) algorithm to interpolate the high-concealment features with the original image features, ensuring the final decoded adversarial samples maintain a natural appearance, further reducing the likelihood of detection. We conduct comprehensive experiments on the CelebA dataset, demonstrating that the adversarial facial images generated by our method possess semantic plausibility and authenticity in appearance and achieve a high attack success rate in both white-box and black-box settings.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adversarial Attacks on Facial Images Based on Attribute-Conditioned High-Camouflage Editing

  • Jingjing Zhang,
  • Huabin Wang,
  • Dongxu Shang,
  • Hongrui Yuan,
  • Liang Tao

摘要

Research on adversarial attacks for facial recognition identifies and mitigates vulnerabilities in facial recognition systems, enhancing their security. Current adversarial attacks targeting facial attributes lack precision in controlling specific attributes, often altering multiple facial features instead of a single target attribute. Such imprecise modifications reduce the attack’s effectiveness and stealthiness. To address these issues, this paper proposes a method for generating adversarial examples based on multi-layer feature map fusion. First, we design a framework called StarAdv, which uses fused multi-layer feature maps with high concealment to achieve realistic facial image transformations under different attributes. This approach generates adversarial images visually similar to the originals while possessing specific misleading properties, enabling transferable attacks on facial recognition systems. Second, we introduce a Multi-layer Fusion module that captures weight information from each layer of the network’s residual blocks to adaptively fuse feature maps from different layers, producing high-concealment feature maps. Finally, we propose a Bilinear Feature Map Interpolation (BFMI) algorithm to interpolate the high-concealment features with the original image features, ensuring the final decoded adversarial samples maintain a natural appearance, further reducing the likelihood of detection. We conduct comprehensive experiments on the CelebA dataset, demonstrating that the adversarial facial images generated by our method possess semantic plausibility and authenticity in appearance and achieve a high attack success rate in both white-box and black-box settings.