AdvBiom: Adversarial Attacks on Biometric Matchers
摘要
With the advent of deep learning models, face recognition systems have achieved impressive recognition rates. The workhorses behind this success are convolutional neural networks (CNNs) and the availability of large-scale face datasets for training. One of the challenges in modern face recognition systems is the addition of human-imperceptible noise. This is achieved by using an adversarial generator to face samples, which can evade most prevailing face recognition systems. The same approach can also be extended to other biometric traits in the future. In this work, we present how such a generator can be trained to achieve attack success rates as high as 99.67% (obfuscation with FaceNet) in a white-box attack and 97.22% (obfuscation with SphereFace) in a black-box attack while maintaining high structural similarity.