Real-World Transferable Adversarial Attack on Face-Recognition Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kaznacheev, Andrey, Mikhalchuk, Matvey, Kuznetsov, Andrey, Petiushko, Aleksandr, Razzhigaev, Anton
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909812709654528
author Kaznacheev, Andrey
Mikhalchuk, Matvey
Kuznetsov, Andrey
Petiushko, Aleksandr
Razzhigaev, Anton
author_facet Kaznacheev, Andrey
Mikhalchuk, Matvey
Kuznetsov, Andrey
Petiushko, Aleksandr
Razzhigaev, Anton
contents Adversarial attacks on face recognition (FR) systems pose a significant security threat, yet most are confined to the digital domain or require white-box access. We introduce GaP (Gaussian Patch), a novel method to generate a universal, physically transferable adversarial patch under a strict black-box setting. Our approach uses a query-efficient, zero-order greedy algorithm to iteratively construct a symmetric, grayscale pattern for the forehead. The patch is optimized by successively adding Gaussian blobs, guided only by the cosine similarity scores from a surrogate FR model to maximally degrade identity recognition. We demonstrate that with approximately 10,000 queries to a black-box ArcFace model, the resulting GaP achieves a high attack success rate in both digital and real-world physical tests. Critically, the attack shows strong transferability, successfully deceiving an entirely unseen FaceNet model. Our work highlights a practical and severe vulnerability, proving that robust, transferable attacks can be crafted with limited knowledge of the target system.
format Preprint
id arxiv_https___arxiv_org_abs_2509_23198
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Real-World Transferable Adversarial Attack on Face-Recognition Systems
Kaznacheev, Andrey
Mikhalchuk, Matvey
Kuznetsov, Andrey
Petiushko, Aleksandr
Razzhigaev, Anton
Computer Vision and Pattern Recognition
Adversarial attacks on face recognition (FR) systems pose a significant security threat, yet most are confined to the digital domain or require white-box access. We introduce GaP (Gaussian Patch), a novel method to generate a universal, physically transferable adversarial patch under a strict black-box setting. Our approach uses a query-efficient, zero-order greedy algorithm to iteratively construct a symmetric, grayscale pattern for the forehead. The patch is optimized by successively adding Gaussian blobs, guided only by the cosine similarity scores from a surrogate FR model to maximally degrade identity recognition. We demonstrate that with approximately 10,000 queries to a black-box ArcFace model, the resulting GaP achieves a high attack success rate in both digital and real-world physical tests. Critically, the attack shows strong transferability, successfully deceiving an entirely unseen FaceNet model. Our work highlights a practical and severe vulnerability, proving that robust, transferable attacks can be crafted with limited knowledge of the target system.
title Real-World Transferable Adversarial Attack on Face-Recognition Systems
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2509.23198