BMIM: Generating Adversarial Attack on Face Recognition via Binary Mask

Author(s):  
Khushabu Agrawal ◽  
Charul Bhatnagar
Author(s):  
Bangjie Yin ◽  
Wenxuan Wang ◽  
Taiping Yao ◽  
Junfeng Guo ◽  
Zelun Kong ◽  
...  

Deep neural networks, particularly face recognition models, have been shown to be vulnerable to both digital and physical adversarial examples. However, existing adversarial examples against face recognition systems either lack transferability to black-box models, or fail to be implemented in practice. In this paper, we propose a unified adversarial face generation method - Adv-Makeup, which can realize imperceptible and transferable attack under the black-box setting. Adv-Makeup develops a task-driven makeup generation method with the blending module to synthesize imperceptible eye shadow over the orbital region on faces. And to achieve transferability, Adv-Makeup implements a fine-grained meta-learning based adversarial attack strategy to learn more vulnerable or sensitive features from various models. Compared to existing techniques, sufficient visualization results demonstrate that Adv-Makeup is capable to generate much more imperceptible attacks under both digital and physical scenarios. Meanwhile, extensive quantitative experiments show that Adv-Makeup can significantly improve the attack success rate under black-box setting, even attacking commercial systems.


2021 ◽  
Vol 3 (1) ◽  
pp. 1-8
Author(s):  
Yuetian Wang ◽  
Chuanjing Zhang ◽  
Xuxin Liao ◽  
Xingang Wang ◽  
Zhaoquan Gu

2010 ◽  
Vol 69 (3) ◽  
pp. 161-167 ◽  
Author(s):  
Jisien Yang ◽  
Adrian Schwaninger

Configural processing has been considered the major contributor to the face inversion effect (FIE) in face recognition. However, most researchers have only obtained the FIE with one specific ratio of configural alteration. It remains unclear whether the ratio of configural alteration itself can mediate the occurrence of the FIE. We aimed to clarify this issue by manipulating the configural information parametrically using six different ratios, ranging from 4% to 24%. Participants were asked to judge whether a pair of faces were entirely identical or different. The paired faces that were to be compared were presented either simultaneously (Experiment 1) or sequentially (Experiment 2). Both experiments revealed that the FIE was observed only when the ratio of configural alteration was in the intermediate range. These results indicate that even though the FIE has been frequently adopted as an index to examine the underlying mechanism of face processing, the emergence of the FIE is not robust with any configural alteration but dependent on the ratio of configural alteration.


Author(s):  
Chrisanthi Nega

Abstract. Four experiments were conducted investigating the effect of size congruency on facial recognition memory, measured by remember, know and guess responses. Different study times were employed, that is extremely short (300 and 700 ms), short (1,000 ms), and long times (5,000 ms). With the short study time (1,000 ms) size congruency occurred in knowing. With the long study time the effect of size congruency occurred in remembering. These results support the distinctiveness/fluency account of remembering and knowing as well as the memory systems account, since the size congruency effect that occurred in knowing under conditions that facilitated perceptual fluency also occurred independently in remembering under conditions that facilitated elaborative encoding. They do not support the idea that remember and know responses reflect differences in trace strength.


Sign in / Sign up

Export Citation Format

Share Document