TY - GEN
T1 - An Illumination Modulation-Based Adversarial Attack Against Automated Face Recognition System
AU - Chen, Zhaojie
AU - Lin, Puxi
AU - Jiang, Zoe Lin
AU - Wei, Zhanhang
AU - Yuan, Sichen
AU - Fang, Junbin
N1 - Publisher Copyright:
© 2021, Springer Nature Switzerland AG.
PY - 2021
Y1 - 2021
N2 - In recent years, physical adversarial attacks have been placed an increasing emphasis. However, previous studies usually use a printer to physically realize adversarial perturbations, and such an attack scheme will meet inevitable disadvantages of perturbation distortion and low concealment. In this paper, we propose a novel attack scheme based on illumination modulation. Because of the rolling shutter effect of CMOS sensor, the created perturbation will not be distorted and completely invisible. According to the attack scheme, we have proposed two novel attack methods, denial of service attack (DoS attack) and escape attack, and offered a real scene to apply the attack methods. The experimental results show that both of two attack methods have a good performance against AFR. DoS attack has an attack success rate of 92.13% and escape attack has an attack success rate of 82%.
AB - In recent years, physical adversarial attacks have been placed an increasing emphasis. However, previous studies usually use a printer to physically realize adversarial perturbations, and such an attack scheme will meet inevitable disadvantages of perturbation distortion and low concealment. In this paper, we propose a novel attack scheme based on illumination modulation. Because of the rolling shutter effect of CMOS sensor, the created perturbation will not be distorted and completely invisible. According to the attack scheme, we have proposed two novel attack methods, denial of service attack (DoS attack) and escape attack, and offered a real scene to apply the attack methods. The experimental results show that both of two attack methods have a good performance against AFR. DoS attack has an attack success rate of 92.13% and escape attack has an attack success rate of 82%.
KW - Automated face recognition
KW - Denial of service attack
KW - Escape attack
KW - Illumination modulation
KW - Physical adversarial attack
UR - https://www.scopus.com/pages/publications/85104475065
U2 - 10.1007/978-3-030-71852-7_4
DO - 10.1007/978-3-030-71852-7_4
M3 - 会议稿件
AN - SCOPUS:85104475065
SN - 9783030718510
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 53
EP - 69
BT - Information Security and Cryptology - 16th International Conference, Inscrypt 2020, Revised Selected Papers
A2 - Wu, Yongdong
A2 - Yung, Moti
PB - Springer Science and Business Media Deutschland GmbH
T2 - 16th International Conference on Information Security and Cryptology, Inscrypt 2020
Y2 - 11 December 2020 through 14 December 2020
ER -