MakeupAttack: Feature Space Black-box Backdoor Attack on Face Recognition via Makeup Transfer

Ming Sun,Lihua Jing,Zixuan Zhu,Rui Wang
2024-08-22
Abstract:Backdoor attacks pose a significant threat to the training process of deep neural networks (DNNs). As a widely-used DNN-based application in real-world scenarios, face recognition systems once implanted into the backdoor, may cause serious consequences. Backdoor research on face recognition is still in its early stages, and the existing backdoor triggers are relatively simple and visible. Furthermore, due to the perceptibility, diversity, and similarity of facial datasets, many state-of-the-art backdoor attacks lose effectiveness on face recognition tasks. In this work, we propose a novel feature space backdoor attack against face recognition via makeup transfer, dubbed MakeupAttack. In contrast to many feature space attacks that demand full access to target models, our method only requires model queries, adhering to black-box attack principles. In our attack, we design an iterative training paradigm to learn the subtle features of the proposed makeup-style trigger. Additionally, MakeupAttack promotes trigger diversity using the adaptive selection method, dispersing the feature distribution of malicious samples to bypass existing defense methods. Extensive experiments were conducted on two widely-used facial datasets targeting multiple models. The results demonstrate that our proposed attack method can bypass existing state-of-the-art defenses while maintaining effectiveness, robustness, naturalness, and stealthiness, without compromising model performance.
Computer Vision and Pattern Recognition
What problem does this paper attempt to address?
### Problems the Paper Attempts to Solve The paper primarily focuses on utilizing cosmetic transfer techniques for feature space black-box backdoor attacks in facial recognition systems, proposing a new method called MakeupAttack. Specifically, the paper attempts to address the following issues: 1. **Enhancing Attack Stealth**: Existing backdoor attack methods in facial recognition (such as facial markings, accessories, or image blending) are too conspicuous and easily detected and defended against. MakeupAttack uses cosmetic styles as triggers, improving the effectiveness of the attack while ensuring naturalness and stealth. 2. **Increasing Attack Diversity**: By using adaptive selection methods to increase the diversity of malicious samples, their feature distribution becomes more dispersed, thereby bypassing existing defense mechanisms. 3. **Improving Attack Robustness**: MakeupAttack can effectively implement attacks on various facial datasets and network architectures and maintain a high success rate under different defense strategies. 4. **Achieving Black-Box Attacks**: Unlike feature space attacks that require full access to the target model, MakeupAttack only needs to query the model to achieve the attack, adhering to the principles of black-box attacks. Through these improvements, MakeupAttack can effectively implant backdoors while maintaining model performance, and it possesses high stealth, naturalness, and attack efficacy.