###
计算机系统应用英文版:2024,33(8):222-230
本文二维码信息
码上扫一扫!
基于共性梯度的人脸识别通用对抗攻击
(1.重庆邮电大学 通信与信息工程学院, 重庆 400065;2.信号与信息处理重庆市重点实验室, 重庆400065)
Universal Adversarial Attack for Face Recognition Based on Commonality Gradient
(1.School of Communications and Information Engineering, Chongqing University of Posts and Telecommunications, Chongqing 400065, China;2.Chongqing Key Laboratory of Signal and Information Processing, Chongqing 400065, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 253次   下载 779
Received:January 25, 2024    Revised:February 26, 2024
中文摘要: 人脸识别技术的恶意运用可能会导致个人信息泄露, 对个人隐私安全构成巨大威胁, 通过通用对抗攻击保护人脸隐私具有重要的研究意义. 然而, 现有的通用对抗攻击算法多数专注于图像分类任务, 应用于人脸识别模型时, 常面临攻击成功率低和生成扰动明显等问题. 为解决这一挑战, 研究提出了一种基于共性梯度的人脸识别通用对抗攻击方法. 该方法通过多张人脸图像的对抗扰动的共性梯度优化通用对抗扰动, 并利用主导型特征损失提升扰动的攻击能力, 结合多阶段训练策略, 实现了攻击效果与视觉质量的均衡. 在公开数据集上的实验证明, 该方法在人脸识别模型上的攻击性能优于Cos-UAP、SGA等方法, 并且生成的对抗样本具有更好的视觉效果, 表明了所提方法的有效性.
Abstract:The malicious use of facial recognition technology may lead to personal information leakage, posing a significant threat to individual privacy security. Safeguarding facial privacy through universal adversarial attacks holds crucial research significance. However, existing universal adversarial attack algorithms primarily focus on image classification tasks. When applied to facial recognition models, they often encounter challenges such as low attack success rates and noticeable perturbation generation. To address these challenges, this study proposes a universal adversarial attack method for face recognition based on commonality gradients. This method optimizes universal adversarial perturbation through the common gradient of the adversarial perturbations of multiple face images and uses dominant feature loss to improve the attack capability of the perturbation. Combined with the multi-stage training strategy, it achieves a balance between attack effect and visual quality. Experiments on public datasets prove that the method outperforms methods such as Cos-UAP and SGA in the attack performance on facial recognition models, and the generated adversarial samples have better visual effects, indicating the effectiveness of the proposed method.
文章编号:     中图分类号:    文献标志码:
基金项目:国家自然科学基金(62176035, 62201111); 重庆市教委科学技术研究计划(KJZD-K202100606)
引用文本:
段伟,高陈强,李鹏程,朱常杰.基于共性梯度的人脸识别通用对抗攻击.计算机系统应用,2024,33(8):222-230
DUAN Wei,GAO Chen-Qiang,LI Peng-Cheng,ZHU Chang-Jie.Universal Adversarial Attack for Face Recognition Based on Commonality Gradient.COMPUTER SYSTEMS APPLICATIONS,2024,33(8):222-230