Improving Visual Quality and Transferability of Adversarial Attacks on Face Recognition Simultaneously with Adversarial Restoration

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhou, Fengfan, Ling, Hefei, Shi, Yuxuan, Chen, Jiazhong, Li, Ping
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914719240028160
author Zhou, Fengfan
Ling, Hefei
Shi, Yuxuan
Chen, Jiazhong
Li, Ping
author_facet Zhou, Fengfan
Ling, Hefei
Shi, Yuxuan
Chen, Jiazhong
Li, Ping
contents Adversarial face examples possess two critical properties: Visual Quality and Transferability. However, existing approaches rarely address these properties simultaneously, leading to subpar results. To address this issue, we propose a novel adversarial attack technique known as Adversarial Restoration (AdvRestore), which enhances both visual quality and transferability of adversarial face examples by leveraging a face restoration prior. In our approach, we initially train a Restoration Latent Diffusion Model (RLDM) designed for face restoration. Subsequently, we employ the inference process of RLDM to generate adversarial face examples. The adversarial perturbations are applied to the intermediate features of RLDM. Additionally, by treating RLDM face restoration as a sibling task, the transferability of the generated adversarial face examples is further improved. Our experimental results validate the effectiveness of the proposed attack method.
format Preprint
id arxiv_https___arxiv_org_abs_2309_01582
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Improving Visual Quality and Transferability of Adversarial Attacks on Face Recognition Simultaneously with Adversarial Restoration
Zhou, Fengfan
Ling, Hefei
Shi, Yuxuan
Chen, Jiazhong
Li, Ping
Computer Vision and Pattern Recognition
Adversarial face examples possess two critical properties: Visual Quality and Transferability. However, existing approaches rarely address these properties simultaneously, leading to subpar results. To address this issue, we propose a novel adversarial attack technique known as Adversarial Restoration (AdvRestore), which enhances both visual quality and transferability of adversarial face examples by leveraging a face restoration prior. In our approach, we initially train a Restoration Latent Diffusion Model (RLDM) designed for face restoration. Subsequently, we employ the inference process of RLDM to generate adversarial face examples. The adversarial perturbations are applied to the intermediate features of RLDM. Additionally, by treating RLDM face restoration as a sibling task, the transferability of the generated adversarial face examples is further improved. Our experimental results validate the effectiveness of the proposed attack method.
title Improving Visual Quality and Transferability of Adversarial Attacks on Face Recognition Simultaneously with Adversarial Restoration
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2309.01582