【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study

【IEEE Access2021】Adversarial Attacks Against Face Recognition_A_Comprehensive_Study

  • 1. 相关工作
  • 2. 对抗攻击方法
  • 人脸对抗攻击
  • 3. 对抗防御方法

1. 相关工作

  • 介绍了目前常用的人脸识别的models,包括Facenet,VGG-face,Cosface,Arcface等等,后两者是基于相似度cosine.
  • Dataset:LFW,CASIA-Webface,MS-Celeb-1M,VGGface2,Megaface。

2. 对抗攻击方法

FGSM,L-BFGS,I-FGSM, JSMA,One-pixel attack, DeepFool,C&W等

人脸对抗攻击

  • Evolutionary attack (1+1-CMS-ES)降维搜索【Efficient Decision-based Black-box Adversarial Attacks on Face Recognition】
    【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第1张图片
    【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第2张图片
  • FIM:

【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第3张图片

  • 对抗眼镜(1,2)【Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition】【A General Framework for Adversarial Examples with Objectives】

【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第4张图片【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第5张图片

  • VLA-light-based:【VLA: A Practical Visible Light-based Attack on Face Recognition Systems in Physical World】

【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第6张图片

  • P-FGVM(惩罚FGVM):就是在FGVM基础上加一个lamda*(X-X^)更新loss
    【Adversarial face de-identification】
    【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第7张图片

  • FLM(Face landmark manipulation),基于几何的方法,通过面部特征点的移动,最后提出一个Semantic group用于分组更新【Fast Geometrically-Perturbed Adversarial Faces】
    【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第8张图片
    【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第9张图片

  • DFAnet,在model中加入dropout,用于随机丢失部分特征,来提高transferability【Towards Transferable Adversarial Attack against Deep Face Recognition】
    【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第10张图片

3. 对抗防御方法

基本上是三种类型——调整训练/测试阶段的输入、调整model网络结构,使用外部model
【对抗人脸攻击与防御综述】Adversarial Attacks Against Face Recognition, A Comprehensive Study_第11张图片

你可能感兴趣的:(图像识别系统对抗,人工智能,人脸识别,图像识别)