隐藏于众目睽睽之下:一种针对可见光-红外融合人脸识别的有效物理对抗补丁攻击
Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection
浏览论文内容
中文总结 AI 辅助
针对可见光-红外融合人脸识别模型易受攻击问题,提出VIPatch物理对抗补丁攻击,通过制作梯度颜色掩码和创可贴贴纸并联合优化,在数字和物理域均实现超90%攻击成功率,且补丁不易被人察觉。
中文摘要 AI 辅助
基于深度学习的可见光-红外融合人脸识别模型在广泛应用中越来越普及,但仍易受对抗补丁攻击。大多数先前攻击仅针对数字域中的可见光或红外图像,对物理世界中的融合模型无效,且许多方法的补丁模式与现实世界差异大,易被察觉。本文提出VIPatch(可见光-红外补丁),一种为面部图像生成不显眼、逼真且自然的补丁的新型物理对抗补丁攻击。具体而言,VIPatch在可见光和红外图像上制作梯度颜色掩码和创可贴贴纸,并联合优化这两个元素,数字补丁进一步指导其物理对应物的制作。实验结果表明,VIPatch在数字和物理域中均实现了有竞争力的攻击成功率(超过90%),同时使补丁对人类观察者不显眼。
英文摘要
Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks. Most prior attacks target either the visual or the infrared image alone in the digital domain, which renders them ineffective against fused models in the physical world. Moreover, many of these methods are readily noticeable, as their patch patterns deviate substantially from those seen in the real world. In this paper, we introduce VIPatch (Visual-Infrared Patch), a novel physical adversarial patch attack that produces inconspicuous, realistic, and natural-looking patches for facial images. Specifically, VIPatch crafts a gradient-color mask together with a band-aid sticker across both the visual and infrared images, and jointly optimizes these two elements; the resulting digital patches further guide the fabrication of their physical counterparts. Experimental results show that VIPatch achieves competitive attack success rates (over 90%) in both the digital and physical domains, while keeping the patches unobtrusive to human observers.
发表机构
- City University of Hong Kong(香港城市大学)
- King Abdullah University of Science and Technology (KAUST)(阿卜杜拉国王科技大学)
机构由 AI 辅助整理,请以论文原文为准。