Research of Adversarial Attack Method in Face Recognition System

Jin-yin CHEN,Jia-jun ZHOU,Shi-jing SHEN,Hai-bin ZHENG,Qi XUAN
DOI: https://doi.org/10.3969/j.issn.1000-1220.2019.08.028
2019-01-01
Abstract:At present,deep learning based applications are more and more extensive,but deep learning is vulnerable to artificially ad-versarial attacks. For the deep learning model application with high security requirements such as face recognition system,it is of great significance to study the vulnerability of the model against the attack to improve the robustness of the model. This paper focuses on the black box face recognition system based on deep learning,using a biological facial accessories(such as glasses frames)to constrain the perturbation region. The facial component is generated by the particle swarm optimization(PSO)strategy to attack the face recognition model. Here,we realized a digital attack against FaceNet,the latest face recognition framework,and achieved a good attack effect. Fi-nally,the defense test was conducted using adversarial training,which verifies that it can improve model robustness.
What problem does this paper attempt to address?