arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

StyleAT:防御人脸识别免受语义攻击

StyleAT: Defending Face Recognition Against Semantic Attacks

Ben Shapira, Roi Cohen, Shang-Tse Chen, Mahmood Sharif

arXiv 2609.23596首次发表:更新:

发表机构

Tel Aviv University; HPI / University of Potsdam; National Taiwan University(特拉维夫大学; 哈索·普拉特纳研究院 / 波茨坦大学; 国立台湾大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对人脸识别模型易受语义攻击的弱点,提出基于StyleGAN潜在空间的快速攻击BoundStyle及其对抗训练方案StyleAT,在提升鲁棒性的同时显著降低计算成本。

AI 中文摘要

随着人脸识别模型现已嵌入日常认证和监控中,近期研究指出了其一个关键弱点:这些模型对对抗性语义编辑仍然高度脆弱。即,对输入进行对抗性产生的语义修改,如轻微老化或姿态变化,可导致错误分类。某些现有攻击虽然强大,但计算成本高昂,使其不足以用于开发防御(例如,通过对抗训练)。为填补这一空白,我们引入了BoundStyle,一种在StyleGAN丰富的潜在空间中运行以最大化错误分类率的强效语义攻击。值得注意的是,BoundStyle在实现高攻击成功率的同时,比现有最先进的攻击快约9.5倍,使其适用于对抗训练。基于BoundStyle,我们开发了StyleAT,一种高效的对抗训练方案,该方案整合了低预算攻击变体,却能防御更强且未见过的语义攻击。我们在训练时未见过的两个数据集和七个模型上进行了评估,发现StyleAT提升了针对最先进攻击的鲁棒准确率,并在各种设置下优于常见防御方法。

英文摘要

With face-recognition models now embedded in everyday authentication and surveillance, recent works have pinpointed a critical weakness: these models remain acutely vulnerable to adversarial semantic edits. I.e., adversarially produced semantic alterations to the input, such as slight aging or pose changes, can induce misclassifications. Certain existing attacks are powerful, but they can be computationally costly, rendering them inadequate for developing defenses (e.g., through adversarial training). To fill the gap, we introduce BoundStyle, a potent semantic attack operating in StyleGAN's rich latent space to maximize misclassification rates. Notably, BoundStyle achieves high attack success rates while being ${\sim}{\times}9.5$ faster than existing state-of-the-art attacks, making it suitable for adversarial training. Building on BoundStyle, we develop StyleAT, an efficient adversarial training scheme that incorporates low-budget attack variants yet defends against stronger and unseen semantic attacks. We evaluate on two datasets unseen during training and seven models, and find that StyleAT boosts robust accuracy against state-of-the-art attacks and outperforms common defenses in various settings.

CommentsAccepted at the 37th British Machine Vision Conference (BMVC 2026), Lancaster, UK. 14 pages main text plus 13 pages of appendices, 15 figures, 12 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑