Poisoning attacks on face authentication systems by using the generative deformation model

被引:2
|
作者
Chan, Chak-Tong [1 ]
Huang, Szu-Hao [2 ]
Choy, Patrick Puiyui [2 ]
机构
[1] Natl Yang Ming Chiao Tung Univ, Inst Informat Management, 1001 Univ Rd, Hsinchu 300, Taiwan
[2] Natl Yang Ming Chiao Tung Univ, Dept Informat Management & Finance, 1001 Univ Rd, Hsinchu 300, Taiwan
关键词
Facial recognition; Adversarial attack; Poisoning attack; Computer vision; Image deformation; Information security;
D O I
10.1007/s11042-023-14695-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Various studies have revealed the vulnerabilities of machine learning algorithms. For example, a hacker can poison a deep learning facial recognition system by impersonating an administrator and obtaining confidential information. According to studies, poisoning attacks are typically implemented based on the optimization conditions of the machine learning algorithm. However, neural networks, because of their complexity, are typically unsuited for these attacks. Although several poisoning strategies have been developed against deep facial recognition systems, poor image qualities and unrealistic assumptions remain the drawbacks of these strategies. Therefore, we proposed a black-box poisoning attack strategy against facial recognition systems, which works by injecting abnormal data generated by using elastic transformation to deform the facial components. We demonstrated the performance of the proposed strategy using the VGGFace2 data set to attack various facial extractors. The proposed strategy outperformed its counterparts in the literature. The contributions of the study lie in 1) providing a novel method of attack against a nonoverfitting facial recognition system with fewer injections, 2) applying a new image transformation technique to compose malicious samples, and 3) formulating a method that leaves no trace of modification to the human eye.
引用
收藏
页码:29457 / 29476
页数:20
相关论文
共 50 条
  • [1] Poisoning attacks on face authentication systems by using the generative deformation model
    Chak-Tong Chan
    Szu-Hao Huang
    Patrick Puiyui Choy
    Multimedia Tools and Applications, 2023, 82 : 29457 - 29476
  • [2] Empirical Study of Face Authentication Systems Under OSNFD Attacks
    Li, Yan
    Li, Yingjiu
    Xu, Ke
    Yan, Qiang
    Deng, Robert H.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (02) : 231 - 245
  • [3] Preventing Machine Learning Poisoning Attacks Using Authentication and Provenance
    Stokes, Jack W.
    England, Paul
    Kane, Kevin
    2021 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2021), 2021,
  • [4] A geometry-aware generative model for face morphing attacks
    Deng, Zongyong
    Zhao, Qijun
    Ye, Libin
    He, Qiaoyun
    He, Zuyuan
    Huang, Jie
    KNOWLEDGE-BASED SYSTEMS, 2025, 314
  • [5] PoisonGAN: Generative Poisoning Attacks Against Federated Learning in Edge Computing Systems
    Zhang, Jiale
    Chen, Bing
    Cheng, Xiang
    Huynh Thi Thanh Binh
    Yu, Shui
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (05) : 3310 - 3322
  • [6] Defend Data Poisoning Attacks on Voice Authentication
    Li, Ke
    Baird, Cameron
    Lin, Dan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 1754 - 1769
  • [7] Poisoning Attacks to Compromise Face Templates
    Biggio, Batista
    Didaci, Luca
    Fumera, Giorgio
    Roli, Fabio
    2013 INTERNATIONAL CONFERENCE ON BIOMETRICS (ICB), 2013,
  • [8] Detecting and mitigating poisoning attacks in federated learning using generative adversarial networks
    Zhao, Ying
    Chen, Junjun
    Zhang, Jiale
    Wu, Di
    Blumenstein, Michael
    Yu, Shui
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (07):
  • [9] Poisoning GNN-based Recommender Systems with Generative Surrogate-based Attacks
    Thanh, Toan Nguyen
    Quach, Nguyen Duc Khang
    Nguyen, Thanh Tam
    Huynh, Thanh Trung
    Vu, Viet Hung
    Le Nguyen, Phi
    Jo, Jun
    Nguyen, Quoc Viet Hung
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2023, 41 (03)
  • [10] Hierarchical Generative Network for Face Morphing Attacks
    He, Zuyuan
    Deng, Zongyong
    He, Qiaoyun
    Zhao, Qijun
    2024 IEEE 18TH INTERNATIONAL CONFERENCE ON AUTOMATIC FACE AND GESTURE RECOGNITION, FG 2024, 2024,