计算机科学
对抗制
人工智能
面子(社会学概念)
一般化
面部识别系统
图像(数学)
黑匣子
过程(计算)
模式识别(心理学)
机器学习
计算机视觉
数学
社会学
数学分析
操作系统
社会科学
作者
Xingxing Wei,Shouwei Ruan,Yinpeng Dong,Hang Su,Xiaochun Cao
标识
DOI:10.1109/tpami.2025.3526188
摘要
Adversarial patch is one of the important forms of performing adversarial attacks in the physical world. To improve the naturalness and aggressiveness of existing adversarial patches, location-aware patches are proposed, where the patch's location on the target object is integrated into the optimization process to perform attacks. Although it is effective, efficiently finding the optimal location for placing the patches is challenging, especially under the black-box attack settings. In this paper, we first empirically find that the aggregation regions of adversarial patch's locations to show effective attacks for the same facial image are pretty similar across different face recognition models. Based on this observation, we then propose a novel framework called Distribution-Optimized Adversarial Patch (DOPatch) to efficiently search for the aggregation regions in a distribution modeling way. Using the distribution prior, we further design two query-based black-box attack methods: Location Optimization Attack (DOP-LOA) and Distribution Transfer Attack (DOP-DTA) to attack unseen face recognition models. We finally evaluate the proposed methods on various SOTA face recognition models and image recognition models (including the popular big models) to demonstrate our effectiveness and generalization. We also conduct extensive ablation studies and analyses to provide insights into the distribution of adversarial locations.
科研通智能强力驱动
Strongly Powered by AbleSci AI