东华大学学报(英文版)2025,Vol.42Issue(4):442-448,7.DOI:10.19884/j.1672-5220.202407001
针对人脸识别的不完全物理对抗性攻击
Incomplete Physical Adversarial Attack on Face Recognition
胡伟涛 1许武军2
作者信息
- 1. 东华大学信息科学与技术学院,上海 201620
- 2. 东华大学信息科学与技术学院,上海 201620||东华大学数字化纺织服装技术教育部工程研究中心,上海 201620
- 折叠
摘要
Abstract
In recent work,adversarial stickers are widely used to attack face recognition(FR)systems in the physical world.However,it is difficult to evaluate the performance of physical attacks because of the lack of volunteers in the experiment.In this paper,a simple attack method called incomplete physical adversarial attack(IPAA)is proposed to simulate physical attacks.Different from the process of physical attacks,when an IPAA is conducted,a photo of the adversarial sticker is embedded into a facial image as the input to attack FR systems,which can obtain results similar to those of physical attacks without inviting any volunteers.The results show that IPAA has a higher similarity with physical attacks than digital attacks,indicating that IPAA is able to evaluate the performance of physical attacks.IPAA is effective in quantitatively measuring the impact of the sticker location on the results of attacks.关键词
物理攻击/数字攻击/人脸识别/干扰变量/对抗样本Key words
physical attack/digital attack/face recognition/interferential variable/adversarial example分类
信息技术与安全科学引用本文复制引用
胡伟涛,许武军..针对人脸识别的不完全物理对抗性攻击[J].东华大学学报(英文版),2025,42(4):442-448,7.