Robust Physical-World Attacks on Face Recognition

作者:

Highlights:

• A novel physical attack method, dubbed PadvFace, that models complicated physical-world condition variations in attacking face recognition.

• Explore the attack complexity with various physical-world conditions and propose an efficient curriculum adversarial attack (CAA) algorithm.

• Build a standardized testing protocol for facilitating the fair evaluation of physical attacks on face recognition.

• Conduct a comprehensive experimental study and obtain the superior performance of physical attacks.

摘要

•A novel physical attack method, dubbed PadvFace, that models complicated physical-world condition variations in attacking face recognition.•Explore the attack complexity with various physical-world conditions and propose an efficient curriculum adversarial attack (CAA) algorithm.•Build a standardized testing protocol for facilitating the fair evaluation of physical attacks on face recognition.•Conduct a comprehensive experimental study and obtain the superior performance of physical attacks.

论文关键词:Physical-world adversarial attack,Face recognition,Environmental variations,Curriculum learning

论文评审过程:Received 29 January 2022, Revised 12 August 2022, Accepted 27 August 2022, Available online 6 September 2022, Version of Record 15 September 2022.

论文官网地址:https://doi.org/10.1016/j.patcog.2022.109009