MakeupAttack: Feature Space Black-box Backdoor Attack on Face Recognition via Makeup Transfer

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Sun, Ming, Jing, Lihua, Zhu, Zixuan, Wang, Rui
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866914920787869696
author Sun, Ming
Jing, Lihua
Zhu, Zixuan
Wang, Rui
author_facet Sun, Ming
Jing, Lihua
Zhu, Zixuan
Wang, Rui
contents Backdoor attacks pose a significant threat to the training process of deep neural networks (DNNs). As a widely-used DNN-based application in real-world scenarios, face recognition systems once implanted into the backdoor, may cause serious consequences. Backdoor research on face recognition is still in its early stages, and the existing backdoor triggers are relatively simple and visible. Furthermore, due to the perceptibility, diversity, and similarity of facial datasets, many state-of-the-art backdoor attacks lose effectiveness on face recognition tasks. In this work, we propose a novel feature space backdoor attack against face recognition via makeup transfer, dubbed MakeupAttack. In contrast to many feature space attacks that demand full access to target models, our method only requires model queries, adhering to black-box attack principles. In our attack, we design an iterative training paradigm to learn the subtle features of the proposed makeup-style trigger. Additionally, MakeupAttack promotes trigger diversity using the adaptive selection method, dispersing the feature distribution of malicious samples to bypass existing defense methods. Extensive experiments were conducted on two widely-used facial datasets targeting multiple models. The results demonstrate that our proposed attack method can bypass existing state-of-the-art defenses while maintaining effectiveness, robustness, naturalness, and stealthiness, without compromising model performance.
format Preprint
id arxiv_https___arxiv_org_abs_2408_12312
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle MakeupAttack: Feature Space Black-box Backdoor Attack on Face Recognition via Makeup Transfer
Sun, Ming
Jing, Lihua
Zhu, Zixuan
Wang, Rui
Computer Vision and Pattern Recognition
Backdoor attacks pose a significant threat to the training process of deep neural networks (DNNs). As a widely-used DNN-based application in real-world scenarios, face recognition systems once implanted into the backdoor, may cause serious consequences. Backdoor research on face recognition is still in its early stages, and the existing backdoor triggers are relatively simple and visible. Furthermore, due to the perceptibility, diversity, and similarity of facial datasets, many state-of-the-art backdoor attacks lose effectiveness on face recognition tasks. In this work, we propose a novel feature space backdoor attack against face recognition via makeup transfer, dubbed MakeupAttack. In contrast to many feature space attacks that demand full access to target models, our method only requires model queries, adhering to black-box attack principles. In our attack, we design an iterative training paradigm to learn the subtle features of the proposed makeup-style trigger. Additionally, MakeupAttack promotes trigger diversity using the adaptive selection method, dispersing the feature distribution of malicious samples to bypass existing defense methods. Extensive experiments were conducted on two widely-used facial datasets targeting multiple models. The results demonstrate that our proposed attack method can bypass existing state-of-the-art defenses while maintaining effectiveness, robustness, naturalness, and stealthiness, without compromising model performance.
title MakeupAttack: Feature Space Black-box Backdoor Attack on Face Recognition via Makeup Transfer
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2408.12312