Deep learning models, particularly in face recognition systems, have shown notable susceptibility to adversarial attacks across both digital and physical domains. However, existing white-box attack methodologies often lack practical applicability and black-box approaches present a critical trade-off between attack transferability and perceptual stealthiness. To address this fundamental limitation, we pro-pose a novel adversarial example generation framework leveraging multi-scale style encoding networks. Our methodology simultaneously optimizes two critical objectives: preserving the attacker's distinguishable identity features while inducing high feature-space similarity with the target victim in deep face recognition models. This dual optimization enables the generation of adversarial samples that successfully deceive recognition systems into misclassifying the attacker as the target identity, yet remain visually consistent with the attacker's authentic characteristics. Comprehensive evaluations on the FFHQ and CelebA-HQ datasets demonstrate that the proposed framework achieves superior performance, surpassing existing methods in terms of attack success rate. Furthermore, comparative experiments show that the method improves both cross-model transferability and imperceptibility, offering a novel and effective approach for adversarial attacks against face recognition systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

MSIAA: Multi-scale Inversion Adversarial Attack on Face Recognition

  • Ruizhong Du,
  • Shenyu Li,
  • Mingyue Li

摘要

Deep learning models, particularly in face recognition systems, have shown notable susceptibility to adversarial attacks across both digital and physical domains. However, existing white-box attack methodologies often lack practical applicability and black-box approaches present a critical trade-off between attack transferability and perceptual stealthiness. To address this fundamental limitation, we pro-pose a novel adversarial example generation framework leveraging multi-scale style encoding networks. Our methodology simultaneously optimizes two critical objectives: preserving the attacker's distinguishable identity features while inducing high feature-space similarity with the target victim in deep face recognition models. This dual optimization enables the generation of adversarial samples that successfully deceive recognition systems into misclassifying the attacker as the target identity, yet remain visually consistent with the attacker's authentic characteristics. Comprehensive evaluations on the FFHQ and CelebA-HQ datasets demonstrate that the proposed framework achieves superior performance, surpassing existing methods in terms of attack success rate. Furthermore, comparative experiments show that the method improves both cross-model transferability and imperceptibility, offering a novel and effective approach for adversarial attacks against face recognition systems.