AdvHat: Real-World Adversarial Attack on ArcFace Face ID System

@article{Komkov2021AdvHatRA,
  title={AdvHat: Real-World Adversarial Attack on ArcFace Face ID System},
  author={Stepan Alekseevich Komkov and Aleksandr Petiushko},
  journal={2020 25th International Conference on Pattern Recognition (ICPR)},
  year={2021},
  pages={819-826}
}
In this paper we propose a novel easily reproducible technique to attack the best public Face ID system ArcFace in different shooting conditions. [...] Key Method The adversarial sticker is prepared with a novel algorithm for off-plane transformations of the image which imitates sticker location on the hat. Such an approach confuses the state-of-the-art public Face ID model LResNet100E-IR, ArcFace@ms1m-refine-v2 and is transferable to other Face ID models.Expand
Meaningful Adversarial Stickers for Face Recognition in Physical World
Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition
Threat of Adversarial Attacks on Face Recognition: A Comprehensive Survey
Robust Attacks on Deep Learning Face Recognition in the Physical World
Adversarial Image Attacks Using Multi-Sample and Most-Likely Ensemble Methods
We Can Always Catch You: Detecting Adversarial Patched Objects WITH or WITHOUT Signature
  • Binxiu Liang, Jiachun Li, Jianjun Huang
  • Computer Science
  • ArXiv
  • 2021
Clipped BagNet: Defending Against Sticker Attacks with Clipped Bag-of-features
FoggySight: A Scheme for Facial Lookup Privacy
GhostImage: Perception Domain Attacks against Vision-based Object Classification Systems
Adversarial Patch Attacks on Monocular Depth Estimation Networks
...
1
2
3
4
...

References

SHOWING 1-10 OF 52 REFERENCES
Adversarial Patch
Fooling Automated Surveillance Cameras: Adversarial Patches to Attack Person Detection
Synthesizing Robust Adversarial Examples
One Pixel Attack for Fooling Deep Neural Networks
A General Framework for Adversarial Examples with Objectives
SphereFace: Deep Hypersphere Embedding for Face Recognition
...
1
2
3
4
5
...