FLDATN: Black‐Box Attack for Face Liveness Detection Based on Adversarial Transformation Network

Yali Peng,Jianbo Liu,Min Long,Fei Peng
DOI: https://doi.org/10.1155/2024/8436216
IF: 8.993
2024-09-28
International Journal of Intelligent Systems
Abstract:Aiming at the shortcomings of the current face liveness detection attack methods in the low generation speed of adversarial examples and the implementation of white‐box attacks, a novel black‐box attack method for face liveness detection named as FLDATN is proposed based on adversarial transformation network (ATN). In FLDATN, a convolutional block attention module (CBAM) is used to improve the generalization ability of adversarial examples, and the misclassification loss function based on feature similarity is defined. Experiments and analysis on the Oulu‐NPU dataset show that the adversarial examples generated by the FLDATN have a good black‐box attack effect on the task of face liveness detection and can achieve better generalization performance than the traditional methods. In addition, since FLDATN does not need to perform multiple gradient calculations for each image, it can significantly improve the generation speed of the adversarial examples.
computer science, artificial intelligence
What problem does this paper attempt to address?