A white-box impersonation attack on the FaceID system in the real world

Lu Guo,Hua Zhang
DOI: https://doi.org/10.1088/1742-6596/1651/1/012037
2020-01-01
Journal of Physics: Conference Series
Abstract:Abstract The arcface model maximizes the classification boundary in the angular space, and is one type of the best models in the current face recognition model. We propose a mask sticker attack method to realize the impersonation attack of arcface model. The method specifically uses a parabolic transformation to simulate the bending situation of a sticker on a mask, and uses a multi-stage PGD attack to generate a adversarial sticker. Finally, the adversarial sticker is attached to the mask worn by the attacker to perform an impersonation attack. On targets of different skin colors, ages and genders, the method proposed in this article has an attack success rate of 0.65, and the final cosine similarity between attacker with mask sticker and target can reach about 0.5-0.7. In addition, we discuss the effect of sticker location and size on attack effect, as well as the generalization of this method on other models.
What problem does this paper attempt to address?