An Illumination Modulation-Based Adversarial Attack Against Automated Face Recognition System.

Zhaojie Chen,Puxi Lin,Zoe Lin Jiang,Zhanhang Wei,Sichen Yuan,Junbin Fang
DOI: https://doi.org/10.1007/978-3-030-71852-7_4
2020-01-01
Abstract:In recent years, physical adversarial attacks have been placed an increasing emphasis. However, previous studies usually use a printer to physically realize adversarial perturbations, and such an attack scheme will meet inevitable disadvantages of perturbation distortion and low concealment. In this paper, we propose a novel attack scheme based on illumination modulation. Because of the rolling shutter effect of CMOS sensor, the created perturbation will not be distorted and completely invisible. According to the attack scheme, we have proposed two novel attack methods, denial of service attack (DoS attack) and escape attack, and offered a real scene to apply the attack methods. The experimental results show that both of two attack methods have a good performance against AFR. DoS attack has an attack success rate of 92.13% and escape attack has an attack success rate of 82%.
What problem does this paper attempt to address?