Pith. sign in

REVIEW 1 cited by

Adversarial Mask: Real-World Universal Adversarial Attack on Face Recognition Model

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2111.10759 v3 pith:H22MW3V4 submitted 2021-11-21 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords adversarialmaskexperimentsfaceattacksdomainmasksmodels
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Deep learning-based facial recognition (FR) models have demonstrated state-of-the-art performance in the past few years, even when wearing protective medical face masks became commonplace during the COVID-19 pandemic. Given the outstanding performance of these models, the machine learning research community has shown increasing interest in challenging their robustness. Initially, researchers presented adversarial attacks in the digital domain, and later the attacks were transferred to the physical domain. However, in many cases, attacks in the physical domain are conspicuous, and thus may raise suspicion in real-world environments (e.g., airports). In this paper, we propose Adversarial Mask, a physical universal adversarial perturbation (UAP) against state-of-the-art FR models that is applied on face masks in the form of a carefully crafted pattern. In our experiments, we examined the transferability of our adversarial mask to a wide range of FR model architectures and datasets. In addition, we validated our adversarial mask's effectiveness in real-world experiments (CCTV use case) by printing the adversarial pattern on a fabric face mask. In these experiments, the FR system was only able to identify 3.34% of the participants wearing the mask (compared to a minimum of 83.34% with other evaluated masks). A demo of our experiments can be found at: https://youtu.be/_TXkDO5z11w.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Novel AI Camera Camouflage: Face Cloaking Without Full Disguise

    cs.CV 2024-12 reject novelty 2.0 of 10

    Subtle cosmetic lines near facial key points and an alpha-layer PNG trick are claimed to hide faces from commercial detectors, but the evidence is anecdotal and not reproducible.

Pith tools