Enhancing Remote Adversarial Patch Attacks on Face Detectors with Tiling and Scaling

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Okano, Masora, Ito, Koichi, Nishigaki, Masakatsu, Ohki, Tetsushi
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909424459710464
author Okano, Masora
Ito, Koichi
Nishigaki, Masakatsu
Ohki, Tetsushi
author_facet Okano, Masora
Ito, Koichi
Nishigaki, Masakatsu
Ohki, Tetsushi
contents This paper discusses the attack feasibility of Remote Adversarial Patch (RAP) targeting face detectors. The RAP that targets face detectors is similar to the RAP that targets general object detectors, but the former has multiple issues in the attack process the latter does not. (1) It is possible to detect objects of various scales. In particular, the area of small objects that are convolved during feature extraction by CNN is small,so the area that affects the inference results is also small. (2) It is a two-class classification, so there is a large gap in characteristics between the classes. This makes it difficult to attack the inference results by directing them to a different class. In this paper, we propose a new patch placement method and loss function for each problem. The patches targeting the proposed face detector showed superior detection obstruct effects compared to the patches targeting the general object detector.
format Preprint
id arxiv_https___arxiv_org_abs_2412_07996
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Enhancing Remote Adversarial Patch Attacks on Face Detectors with Tiling and Scaling
Okano, Masora
Ito, Koichi
Nishigaki, Masakatsu
Ohki, Tetsushi
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
This paper discusses the attack feasibility of Remote Adversarial Patch (RAP) targeting face detectors. The RAP that targets face detectors is similar to the RAP that targets general object detectors, but the former has multiple issues in the attack process the latter does not. (1) It is possible to detect objects of various scales. In particular, the area of small objects that are convolved during feature extraction by CNN is small,so the area that affects the inference results is also small. (2) It is a two-class classification, so there is a large gap in characteristics between the classes. This makes it difficult to attack the inference results by directing them to a different class. In this paper, we propose a new patch placement method and loss function for each problem. The patches targeting the proposed face detector showed superior detection obstruct effects compared to the patches targeting the general object detector.
title Enhancing Remote Adversarial Patch Attacks on Face Detectors with Tiling and Scaling
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2412.07996