Black-box attack against handwritten signature verification with region-restricted adversarial perturbations

作者:

Highlights:

• A black-box adversarial attack towards offline handwritten signature verification systems is proposed.

• Two novel techniques, i.e, region-restricted perturbations and hierarchical perturbation optimization, are developed for signature adversarial example generation.

• A new metric to measure the visual difference between signatures and adversarial examples is proposed.

摘要

•A black-box adversarial attack towards offline handwritten signature verification systems is proposed.•Two novel techniques, i.e, region-restricted perturbations and hierarchical perturbation optimization, are developed for signature adversarial example generation.•A new metric to measure the visual difference between signatures and adversarial examples is proposed.

论文关键词:Handwritten signature verification,Adversarial example,Black-box attack

论文评审过程:Received 22 December 2019, Revised 24 August 2020, Accepted 7 October 2020, Available online 10 October 2020, Version of Record 15 October 2020.

论文官网地址:https://doi.org/10.1016/j.patcog.2020.107689