Real-World Transferable Adversarial Attack on Face-Recognition Systems
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909812709654528 |
|---|---|
| author | Kaznacheev, Andrey Mikhalchuk, Matvey Kuznetsov, Andrey Petiushko, Aleksandr Razzhigaev, Anton |
| author_facet | Kaznacheev, Andrey Mikhalchuk, Matvey Kuznetsov, Andrey Petiushko, Aleksandr Razzhigaev, Anton |
| contents | Adversarial attacks on face recognition (FR) systems pose a significant security threat, yet most are confined to the digital domain or require white-box access. We introduce GaP (Gaussian Patch), a novel method to generate a universal, physically transferable adversarial patch under a strict black-box setting. Our approach uses a query-efficient, zero-order greedy algorithm to iteratively construct a symmetric, grayscale pattern for the forehead. The patch is optimized by successively adding Gaussian blobs, guided only by the cosine similarity scores from a surrogate FR model to maximally degrade identity recognition. We demonstrate that with approximately 10,000 queries to a black-box ArcFace model, the resulting GaP achieves a high attack success rate in both digital and real-world physical tests. Critically, the attack shows strong transferability, successfully deceiving an entirely unseen FaceNet model. Our work highlights a practical and severe vulnerability, proving that robust, transferable attacks can be crafted with limited knowledge of the target system. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2509_23198 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Real-World Transferable Adversarial Attack on Face-Recognition Systems Kaznacheev, Andrey Mikhalchuk, Matvey Kuznetsov, Andrey Petiushko, Aleksandr Razzhigaev, Anton Computer Vision and Pattern Recognition Adversarial attacks on face recognition (FR) systems pose a significant security threat, yet most are confined to the digital domain or require white-box access. We introduce GaP (Gaussian Patch), a novel method to generate a universal, physically transferable adversarial patch under a strict black-box setting. Our approach uses a query-efficient, zero-order greedy algorithm to iteratively construct a symmetric, grayscale pattern for the forehead. The patch is optimized by successively adding Gaussian blobs, guided only by the cosine similarity scores from a surrogate FR model to maximally degrade identity recognition. We demonstrate that with approximately 10,000 queries to a black-box ArcFace model, the resulting GaP achieves a high attack success rate in both digital and real-world physical tests. Critically, the attack shows strong transferability, successfully deceiving an entirely unseen FaceNet model. Our work highlights a practical and severe vulnerability, proving that robust, transferable attacks can be crafted with limited knowledge of the target system. |
| title | Real-World Transferable Adversarial Attack on Face-Recognition Systems |
| topic | Computer Vision and Pattern Recognition |
| url | https://arxiv.org/abs/2509.23198 |