Deep learning-based face recognition has perceived a lot of success in recent years. The CNN-based face recognition systems outperformed human beings in both verification and identification scenarios. Despite these remarkable advances, deep learning techniques for face recognition are susceptible to adversarial attacks, posing a severe threat to face recognition system security. Therefore, defending against adversarial attacks is an important research topic for face recognition. In this paper, an intelligent optimized-deep learning based adversarial defense mechanism (ODL-ADM) is proposed to inactivate the adversarial perturbations through the projection of adversarial samples into immune space for face verification under complex conditions. The proposed model determines the immune space, which is deliberated as a subspace where perturbations have lesser adverse effect on the recognition model over other subspaces. This is accomplished through the use of a Learnable Convolutional Principle Component Network (LCPCN). The perturbed image is projected into the determined immune space to inactivate the adversarial perturbations injected into the input image. Here, a Stacked Attention based Residual Generative Adversarial Network (SARGAN) is employed to alleviate the adversarial perturbations. After removing any adversarial perturbations, Improved Cross-Triple MobileNetV1 model is used for face verification in order to correctly find the person in image. The loss function can be reduced by using an efficient optimization algorithm termed as Enhanced Fire Hawk Optimization (EFHO). As a result, the proposed ODL-ADM model obtains the overall accuracy of 99.41% respectively and it is superior to existing methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Robust Face Recognition Under Adversarial Attack Using SARGAN Model and Improved Cross Triple MobileNetV1

  • Sheilla Ann Bangoy Pacheco,
  • Jheanel Espiritu Estrada,
  • Mahesh M. Goyani

摘要

Deep learning-based face recognition has perceived a lot of success in recent years. The CNN-based face recognition systems outperformed human beings in both verification and identification scenarios. Despite these remarkable advances, deep learning techniques for face recognition are susceptible to adversarial attacks, posing a severe threat to face recognition system security. Therefore, defending against adversarial attacks is an important research topic for face recognition. In this paper, an intelligent optimized-deep learning based adversarial defense mechanism (ODL-ADM) is proposed to inactivate the adversarial perturbations through the projection of adversarial samples into immune space for face verification under complex conditions. The proposed model determines the immune space, which is deliberated as a subspace where perturbations have lesser adverse effect on the recognition model over other subspaces. This is accomplished through the use of a Learnable Convolutional Principle Component Network (LCPCN). The perturbed image is projected into the determined immune space to inactivate the adversarial perturbations injected into the input image. Here, a Stacked Attention based Residual Generative Adversarial Network (SARGAN) is employed to alleviate the adversarial perturbations. After removing any adversarial perturbations, Improved Cross-Triple MobileNetV1 model is used for face verification in order to correctly find the person in image. The loss function can be reduced by using an efficient optimization algorithm termed as Enhanced Fire Hawk Optimization (EFHO). As a result, the proposed ODL-ADM model obtains the overall accuracy of 99.41% respectively and it is superior to existing methods.