AI 中文总结
本研究实证考察去标识化系统中对抗攻击导致身份泄露的风险,发现攻击可跨模型迁移,并提出微调与低通滤波两种缓解策略,增强系统鲁棒性。
AI 中文摘要
在本文中,我们研究了在现实去标识化框架中对抗攻击对身份编码器的影响。我们的实验表明,攻击的可迁移性(从外部代理模型迁移到系统模型,例如从CosFace到ArcFace)使得攻击者能够在足够敏感的人脸识别系统中导致身份信息泄露。我们提供了实验证据,并提出了缓解此漏洞的策略。具体而言,我们展示了在对抗样本上进行微调有助于缓解基于失真的攻击(如雪、雾等)的影响,而简单的低通滤波器可以衰减对抗噪声的影响,且不影响去标识化图像。我们的缓解措施使得去标识化系统在保持其功能的同时,对对抗噪声具有显著更强的鲁棒性。
英文摘要
In this paper, we investigate the impact of adversarial attacks on identity encoders within a realistic de-identification framework. Our experiments show that the transferability of attacks transfers from an external surrogate model to the system model (e.g., CosFace to ArcFace) allows the adversary to cause identity information to leak in a sufficiently sensitive face recognition system. We present experimental evidence and propose strategies to mitigate this vulnerability. Specifically, we show how fine-tuning on adversarial examples helps to mitigate this effect for distortion-based attacks (i.e., snow, fog, etc.), while a simple low-pass filter can attenuate the effect of adversarial noise without affecting the de-identified images. Our mitigation results in a de-identification system that preserves its functionality while being significantly more robust to adversarial noise.