General Adversarial Perturbation Simulating: Protect Unknown System by Detecting Unknown Adversarial Faces.

Hefei Ling,Feiran Sun,Jinyuan Zhang,Xiaorui Lin,Jiazhong Chen,Ping Li,Qian Wang
DOI: https://doi.org/10.1109/ijcnn54540.2023.10191564
2023-01-01
Abstract:Benefitting from the development of convolutional neural networks (CNNs), face recognition systems (FRSs) play a key role in many security-critical systems. However, FRSs have been proved to be vulnerable to adversarial faces (advfaces). Adv-faces aim to change classification results by adding a subtle perturbation on real faces. The existence of adv-faces poses a significant threat to financial and privacy security. Previous detection methods require either training on pre-computed advfaces or accessing to protected victim FRSs, bringing a dilemma in practical using. In this work, we heuristically propose an adversarial face detection method called General Adversarial Perturbation Simulating (GAPS) which is blind to both adversarial attacks and FRSs. Simulating noise patterns of several gradient-based adversarial perturbations, GAPS is able to generate simulated adversarial faces (sadv-faces) guiding detectors to learn general adversarial perturbation features and focus on classifying sensitive regions. Extensive experiments on LFW and CASIA-WebFace show that our method outperforms 9 state-of-the-art baseline methods and demonstrate the effectiveness of GAPS.
What problem does this paper attempt to address?