| 注册
首页|期刊导航|东华大学学报(英文版)|针对人脸识别的不完全物理对抗性攻击

针对人脸识别的不完全物理对抗性攻击

胡伟涛 许武军

东华大学学报(英文版)2025,Vol.42Issue(4):442-448,7.
东华大学学报(英文版)2025,Vol.42Issue(4):442-448,7.DOI:10.19884/j.1672-5220.202407001

针对人脸识别的不完全物理对抗性攻击

Incomplete Physical Adversarial Attack on Face Recognition

胡伟涛 1许武军2

作者信息

  • 1. 东华大学信息科学与技术学院,上海 201620
  • 2. 东华大学信息科学与技术学院,上海 201620||东华大学数字化纺织服装技术教育部工程研究中心,上海 201620
  • 折叠

摘要

Abstract

In recent work,adversarial stickers are widely used to attack face recognition(FR)systems in the physical world.However,it is difficult to evaluate the performance of physical attacks because of the lack of volunteers in the experiment.In this paper,a simple attack method called incomplete physical adversarial attack(IPAA)is proposed to simulate physical attacks.Different from the process of physical attacks,when an IPAA is conducted,a photo of the adversarial sticker is embedded into a facial image as the input to attack FR systems,which can obtain results similar to those of physical attacks without inviting any volunteers.The results show that IPAA has a higher similarity with physical attacks than digital attacks,indicating that IPAA is able to evaluate the performance of physical attacks.IPAA is effective in quantitatively measuring the impact of the sticker location on the results of attacks.

关键词

物理攻击/数字攻击/人脸识别/干扰变量/对抗样本

Key words

physical attack/digital attack/face recognition/interferential variable/adversarial example

分类

信息技术与安全科学

引用本文复制引用

胡伟涛,许武军..针对人脸识别的不完全物理对抗性攻击[J].东华大学学报(英文版),2025,42(4):442-448,7.

东华大学学报(英文版)

1672-5220

访问量0
|
下载量0
段落导航相关论文