MSIAA: Multi-scale Inversion Adversarial Attack on Face Recognition
摘要
Deep learning models, particularly in face recognition systems, have shown notable susceptibility to adversarial attacks across both digital and physical domains. However, existing white-box attack methodologies often lack practical applicability and black-box approaches present a critical trade-off between attack transferability and perceptual stealthiness. To address this fundamental limitation, we pro-pose a novel adversarial example generation framework leveraging multi-scale style encoding networks. Our methodology simultaneously optimizes two critical objectives: preserving the attacker's distinguishable identity features while inducing high feature-space similarity with the target victim in deep face recognition models. This dual optimization enables the generation of adversarial samples that successfully deceive recognition systems into misclassifying the attacker as the target identity, yet remain visually consistent with the attacker's authentic characteristics. Comprehensive evaluations on the FFHQ and CelebA-HQ datasets demonstrate that the proposed framework achieves superior performance, surpassing existing methods in terms of attack success rate. Furthermore, comparative experiments show that the method improves both cross-model transferability and imperceptibility, offering a novel and effective approach for adversarial attacks against face recognition systems.