Table of Contents
Fetching ...

A Survey on Physical Adversarial Attacks against Face Recognition Systems

Mingsi Wang, Jiachen Zhou, Tianlin Li, Guozhu Meng, Kai Chen

TL;DR

This paper comprehensively collects and analyzes physical adversarial attack methods targeting FR systems and categorizes existing physical attacks into three categories based on the physical medium used and summarizes how the research in each category has evolved to address these challenges.

Abstract

As Face Recognition (FR) technology becomes increasingly prevalent in finance, the military, public safety, and everyday life, security concerns have grown substantially. Physical adversarial attacks targeting FR systems in real-world settings have attracted considerable research interest due to their practicality and the severe threats they pose. However, a systematic overview focused on physical adversarial attacks against FR systems is still lacking, hindering an in-depth exploration of the challenges and future directions in this field. In this paper, we bridge this gap by comprehensively collecting and analyzing physical adversarial attack methods targeting FR systems. Specifically, we first investigate the key challenges of physical attacks on FR systems. We then categorize existing physical attacks into three categories based on the physical medium used and summarize how the research in each category has evolved to address these challenges. Furthermore, we review current defense strategies and discuss potential future research directions. Our goal is to provide a fresh, comprehensive, and deep understanding of physical adversarial attacks against FR systems, thereby inspiring relevant research in this area.

A Survey on Physical Adversarial Attacks against Face Recognition Systems

TL;DR

This paper comprehensively collects and analyzes physical adversarial attack methods targeting FR systems and categorizes existing physical attacks into three categories based on the physical medium used and summarizes how the research in each category has evolved to address these challenges.

Abstract

As Face Recognition (FR) technology becomes increasingly prevalent in finance, the military, public safety, and everyday life, security concerns have grown substantially. Physical adversarial attacks targeting FR systems in real-world settings have attracted considerable research interest due to their practicality and the severe threats they pose. However, a systematic overview focused on physical adversarial attacks against FR systems is still lacking, hindering an in-depth exploration of the challenges and future directions in this field. In this paper, we bridge this gap by comprehensively collecting and analyzing physical adversarial attack methods targeting FR systems. Specifically, we first investigate the key challenges of physical attacks on FR systems. We then categorize existing physical attacks into three categories based on the physical medium used and summarize how the research in each category has evolved to address these challenges. Furthermore, we review current defense strategies and discuss potential future research directions. Our goal is to provide a fresh, comprehensive, and deep understanding of physical adversarial attacks against FR systems, thereby inspiring relevant research in this area.

Paper Structure

This paper contains 49 sections, 21 equations, 4 figures, 6 tables.

Figures (4)

  • Figure 1: Pipeline of the face recognition system. Physical attacks occur during the interaction between a person and the camera, while digital attacks directly operate on the digital pixels.
  • Figure 2: Timeline of advances and interconnections in 2D and 3D face recognition models.
  • Figure 3: Illustration of three categories of physical adversarial attacks against face recognition systems, based on disguises, infrared, and illumination. The goal of these attacks is either to impersonate another individual or evade recognition.
  • Figure 4: Examples of physical adversarial attacks against FR systems. Disguise-based attacks: (a) hat, (b-c) mask, (d) glass, (e-g) sticker, (h) makeup; Infrared-based attacks: (i) infrared, (j) laser; Illumination-based attacks: (k) projection, (l) relighting.

Theorems & Definitions (5)

  • Remark 1
  • Remark 2
  • Remark 3
  • Remark 4
  • Remark 5