DeepAI AI Chat
Log In Sign Up

Adversarial Image Translation: Unrestricted Adversarial Examples in Face Recognition Systems

by   Kazuya Kakizaki, et al.
nec global

Thanks to recent advances in Deep Neural Networks (DNNs), face recognition systems have achieved high accuracy in classification of a large number of face images. However, recent works demonstrate that DNNs could be vulnerable to adversarial examples and raise concerns about robustness of face recognition systems. In particular adversarial examples that are not restricted to small perturbations could be more serious risks since conventional certified defenses might be ineffective against them. To shed light on the vulnerability of the face recognition systems to this type of adversarial examples, we propose a flexible and efficient method to generate unrestricted adversarial examples using image translation techniques. Our method enables us to translate a source into any desired facial appearance with large perturbations so that target face recognition systems could be deceived. We demonstrate through our experiments that our method achieves about 90% and 30% attack success rates under a white- and black-box setting, respectively. We also illustrate that our generated images are perceptually realistic and maintain personal identity while the perturbations are large enough to defeat certified defenses.


page 1

page 5


AdvFaces: Adversarial Face Synthesis

Face recognition systems have been shown to be vulnerable to adversarial...

Towards Assessing and Characterizing the Semantic Robustness of Face Recognition

Deep Neural Networks (DNNs) lack robustness against imperceptible pertur...

On Brightness Agnostic Adversarial Examples Against Face Recognition Systems

This paper introduces a novel adversarial example generation method agai...

Using a GAN to Generate Adversarial Examples to Facial Image Recognition

Images posted online present a privacy concern in that they may be used ...

Stealthy Physical Masked Face Recognition Attack via Adversarial Style Optimization

Deep neural networks (DNNs) have achieved state-of-the-art performance o...

How Deep Learning Sees the World: A Survey on Adversarial Attacks Defenses

Deep Learning is currently used to perform multiple tasks, such as objec...

Toward Face Biometric De-identification using Adversarial Examples

The remarkable success of face recognition (FR) has endangered the priva...