arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.28936cs.CVcs.AI

DiffAttack:基于潜在扩散模型的人脸识别规避攻击

DiffAttack: Evasion Attacks Against Face Recognition via Latent Diffusion Models

Omid Ahmadieh, Nima Karimian

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对人脸识别系统易受对抗攻击的问题,提出DiffAttack框架,利用潜在扩散模型生成对抗人脸,在FFHQ、CelebA-HQ等基准上攻击成功率达84.86%,可迁移性优于现有方法。

中文摘要 AI 辅助

面部生物特征识别依赖于高维嵌入空间中用户属性的区分度,但深度人脸识别(FR)系统的决策边界通常足够狭窄,易被混淆,导致模型易受对抗攻击。此类场景下,FR系统无法区分真实源图像与精心制作的对抗人脸。现有针对面部生物特征的对抗方法在性能和生成人类不可察觉的高质量图像方面均存在局限,且当源图像与目标图像属于不同人口统计群体或性别时,这些方法往往失效。为解决这些局限,我们提出一种通过潜在空间优化生成对抗人脸的新方法,利用潜在扩散模型直接引导生成过程朝向由人脸识别模型测量的目标身份嵌入。我们提出的DiffAttack框架已在FFHQ和CelebA-HQ等标准基准上进行评估,其在多个人脸识别模型(如FaceNet)上实现了84.86%的高平均攻击成功率,显著优于现有对抗技术。值得注意的是,DiffAttack表现出更优的可迁移性,在FFHQ和CelebA-HQ等基准数据集上,相较于传统基于噪声的方法提升超过15.28%,相较于基于语义的方法提升约5.21%。

英文摘要

Facial biometric identification relies on the distinctiveness of user attributes within a high-dimensional embedding space. However, the decision boundaries of deep face recognition (FR) systems are often sufficiently narrow that they can be conflated, rendering the models vulnerable to adversarial attacks. In such scenarios, the FR system fails to distinguish between an authentic source and a meticulously crafted adversarial face. Existing adversarial methods targeting facial biometrics are limited in both performance and their ability to generate high-quality images that are imperceptible to humans. Moreover, these methods often fail when the source and target images belong to different demographic groups or genders. To address these limitations, we present a novel approach for adversarial face generation via latent-space optimization. We leverage latent diffusion models directly to guide generation toward target identity embeddings, as measured by a face recognition model. Our proposed \textbf{DiffAttack} framework has been evaluated on standard benchmarks, such as the FFHQ and CelebA-HQ datasets. DiffAttack significantly outperforms existing adversarial techniques, achieving a high average attack success rate of 84.86% across multiple face recognition models (e.g., FaceNet). Notably, DiffAttack demonstrates superior transferability, surpassing traditional noise-based methods by over 15.28% and semantic-based approaches by approximately 5.21% on benchmark datasets like FFHQ and CelebA-HQ.

发表机构

  • University of South Florida(南佛罗里达大学)
  • Bellini College of Artificial Intelligence, Cybersecurity and Computing(贝利尼人工智能、网络安全与计算学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑