A Small Sticker is Enough: Spoofing Face Recognition Systems Via Small Stickers

Jiahui Yang,Yushi Cheng,Xiaoyu Ji,Wenyuan Xu
DOI: https://doi.org/10.1145/3573428.3573621
2023-01-01
Abstract:Face recognition systems are widely used in various security-crucial applications such as financial payments, device unlocking, and personnel access. With the rapid development of deep learning, face recognition systems nowadays are usually based on deep neural networks (DNNs). However, recent studies have shown that DNN-based face recognition algorithms are vulnerable to adversarial example attacks and thus may suffer from real-world threats. In this paper, we propose Adv-Sticker, a physical adversarial attack against face recognition systems leveraging a small printed sticker. By optimizing both the attack region and the adversarial sticker, we manage to reduce the size of the sticker to 3*3 cm and make it robust across various environmental conditions. Evaluation on four commonly-used face recognition algorithms (Facenet, Mobile-Facenet, Ir152, and Irse50) shows that Adv-Sticker can physically spoof face recognition systems with an overall attack success rate of 96.9% for the dodging attack, and 70.1% for the impersonation attack.
What problem does this paper attempt to address?