Examining the Human Perceptibility of Black-Box Adversarial Attacks on Face Recognition

The modern open internet contains billions of public images of human faces across the web, especially on social media websites used by half the world's population. In this context, Face Recognition (FR) systems have the potential to match faces to specific names and identities, creating glaring privacy concerns. Adversarial attacks are a promising way to grant users privacy from FR systems by disrupting their capability to recognize faces. Yet, such attacks can be perceptible to human observers, especially under the more challenging black-box threat model. In the literature, the justification for the imperceptibility of such attacks hinges on bounding metrics such as ℓ_p norms. However, there is not much research on how these norms match up with human perception. Through examining and measuring both the effectiveness of recent black-box attacks in the face recognition setting and their corresponding human perceptibility through survey data, we demonstrate the trade-offs in perceptibility that occur as attacks become more aggressive. We also show how the ℓ_2 norm and other metrics do not correlate with human perceptibility in a linear fashion, thus making these norms suboptimal at measuring adversarial attack perceptibility.

READ FULL TEXT
research
10/15/2022

Is Face Recognition Safe from Realizable Attacks?

Face recognition is a popular form of biometric authentication and due t...
research
07/08/2020

Delving into the Adversarial Robustness on Face Recognition

Face recognition has recently made substantial progress and achieved hig...
research
01/28/2023

Semantic Adversarial Attacks on Face Recognition through Significant Attributes

Face recognition is known to be vulnerable to adversarial face images. E...
research
03/24/2020

Adversarial Light Projection Attacks on Face Recognition Systems: A Feasibility Study

Deep learning-based systems have been shown to be vulnerable to adversar...
research
03/19/2020

Face-Off: Adversarial Face Obfuscation

Advances in deep learning have made face recognition increasingly feasib...
research
04/08/2021

FACESEC: A Fine-grained Robustness Evaluation Framework for Face Recognition Systems

We present FACESEC, a framework for fine-grained robustness evaluation o...
research
07/27/2020

Black-Box Face Recovery from Identity Features

In this work, we present a novel algorithm based on an it-erative sampli...

Please sign up or login with your details

Forgot password? Click here to reset