Device-aware Optical Adversarial Attack for a Portable Projector-camera System

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Jiang, Ning, Liu, Yanhong, Zeng, Dingheng, Feng, Yue, Deng, Weihong, Li, Ying
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917901446938624
author Jiang, Ning
Liu, Yanhong
Zeng, Dingheng
Feng, Yue
Deng, Weihong
Li, Ying
author_facet Jiang, Ning
Liu, Yanhong
Zeng, Dingheng
Feng, Yue
Deng, Weihong
Li, Ying
contents Deep-learning-based face recognition (FR) systems are susceptible to adversarial examples in both digital and physical domains. Physical attacks present a greater threat to deployed systems as adversaries can easily access the input channel, allowing them to provide malicious inputs to impersonate a victim. This paper addresses the limitations of existing projector-camera-based adversarial light attacks in practical FR setups. By incorporating device-aware adaptations into the digital attack algorithm, such as resolution-aware and color-aware adjustments, we mitigate the degradation from digital to physical domains. Experimental validation showcases the efficacy of our proposed algorithm against real and spoof adversaries, achieving high physical similarity scores in FR models and state-of-the-art commercial systems. On average, there is only a 14% reduction in scores from digital to physical attacks, with high attack success rate in both white- and black-box scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2501_14005
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Device-aware Optical Adversarial Attack for a Portable Projector-camera System
Jiang, Ning
Liu, Yanhong
Zeng, Dingheng
Feng, Yue
Deng, Weihong
Li, Ying
Computer Vision and Pattern Recognition
Artificial Intelligence
Deep-learning-based face recognition (FR) systems are susceptible to adversarial examples in both digital and physical domains. Physical attacks present a greater threat to deployed systems as adversaries can easily access the input channel, allowing them to provide malicious inputs to impersonate a victim. This paper addresses the limitations of existing projector-camera-based adversarial light attacks in practical FR setups. By incorporating device-aware adaptations into the digital attack algorithm, such as resolution-aware and color-aware adjustments, we mitigate the degradation from digital to physical domains. Experimental validation showcases the efficacy of our proposed algorithm against real and spoof adversaries, achieving high physical similarity scores in FR models and state-of-the-art commercial systems. On average, there is only a 14% reduction in scores from digital to physical attacks, with high attack success rate in both white- and black-box scenarios.
title Device-aware Optical Adversarial Attack for a Portable Projector-camera System
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2501.14005