A Momentum-Based Local Face Adversarial Example Generation Algorithm

Small perturbations can make deep models fail. Since deep models are widely used in face recognition systems (FRS) such as surveillance and access control, adversarial examples may introduce more subtle threats to face recognition systems. In this paper, we propose a practical white-box adversarial...

Full description

Saved in:
Bibliographic Details
Published inAlgorithms Vol. 15; no. 12; p. 465
Main Authors Lang, Dapeng, Chen, Deyun, Huang, Jinjie, Li, Sizhao
Format Journal Article
LanguageEnglish
Published Basel MDPI AG 01.12.2022
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:Small perturbations can make deep models fail. Since deep models are widely used in face recognition systems (FRS) such as surveillance and access control, adversarial examples may introduce more subtle threats to face recognition systems. In this paper, we propose a practical white-box adversarial attack method. The method can automatically form a local area with key semantics on the face. The shape of the local area generated by the algorithm varies according to the environment and light of the character. Since these regions contain major facial features, we generated patch-like adversarial examples based on this region, which can effectively deceive FRS. The algorithm introduced the momentum parameter to stabilize the optimization directions. We accelerated the generation process by increasing the learning rate in segments. Compared with the traditional adversarial algorithm, our algorithms are very inconspicuous, which is very suitable for application in real scenes. The attack was verified on the CASIA WebFace and LFW datasets which were also proved to have good transferability.
ISSN:1999-4893
1999-4893
DOI:10.3390/a15120465