English
Related papers

Related papers: Amora: Black-box Adversarial Morphing Attack

200 papers

To perform adversarial attacks in the physical world, many studies have proposed adversarial camouflage, a method to hide a target object by applying camouflage patterns on 3D object surfaces. For obtaining optimal physical adversarial…

Computer Vision and Pattern Recognition · Computer Science 2022-03-21 Naufal Suryanto , Yongsu Kim , Hyoeun Kang , Harashta Tatimma Larasati , Youngyeo Yun , Thi-Thu-Huong Le , Hunmin Yang , Se-Yoon Oh , Howon Kim

Face morphing attacks threaten biometric verification, yet most morphing attack detection (MAD) systems require task-specific training and generalize poorly to unseen attack types. Meanwhile, open-source multimodal large language models…

Computer Vision and Pattern Recognition · Computer Science 2026-02-18 Marija Ivanovska , Vitomir Štruc

Modern image-to-text systems typically adopt the encoder-decoder framework, which comprises two main components: an image encoder, responsible for extracting image features, and a transformer-based decoder, used for generating captions.…

Computer Vision and Pattern Recognition · Computer Science 2023-07-20 Raz Lapid , Moshe Sipper

Automatic speech recognition (ASR) systems are known to be vulnerable to adversarial attacks. This paper addresses detection and defence against targeted white-box attacks on speech signals for ASR systems. While existing work has utilised…

Audio and Speech Processing · Electrical Eng. & Systems 2024-09-13 Nikolai L. Kühne , Astrid H. F. Kitchen , Marie S. Jensen , Mikkel S. L. Brøndt , Martin Gonzalez , Christophe Biscio , Zheng-Hua Tan

Face Recognition (FR) systems have been shown to be vulnerable to morphing attacks. We examine exactly how challenging morphs can become. By showing a worst-case construction in the embedding space of an FR system and using a mapping from…

Computer Vision and Pattern Recognition · Computer Science 2022-09-20 Una M. Kelly , Raymond Veldhuis , Luuk Spreeuwers

Adding perturbations to images can mislead classification models to produce incorrect results. Recently, researchers exploited adversarial perturbations to protect image privacy from retrieval by intelligent models. However, adding…

Computer Vision and Pattern Recognition · Computer Science 2023-01-03 Li Chen , Shaowei Zhu , Zhaoxia Yin

Deep learning based image classification models are shown vulnerable to adversarial attacks by injecting deliberately crafted noises to clean images. To defend against adversarial attacks in a training-free and attack-agnostic manner, this…

Computer Vision and Pattern Recognition · Computer Science 2021-08-03 Li Ding , Yongwei Wang , Xin Ding , Kaiwen Yuan , Ping Wang , Hua Huang , Z. Jane Wang

Face Recognition (FR) models are vulnerable to adversarial examples that subtly manipulate benign face images, underscoring the urgent need to improve the transferability of adversarial attacks in order to expose the blind spots of these…

Computer Vision and Pattern Recognition · Computer Science 2025-04-01 Fengfan Zhou , Bangjie Yin , Hefei Ling , Qianyu Zhou , Wenxuan Wang

Most researchers have tried to enhance the robustness of DNNs by revealing and repairing the vulnerability of DNNs with specialized adversarial examples. Parts of the attack examples have imperceptible perturbations restricted by Lp norm.…

Computer Vision and Pattern Recognition · Computer Science 2024-05-29 Yihao Huang , Liangru Sun , Qing Guo , Felix Juefei-Xu , Jiayi Zhu , Jincao Feng , Yang Liu , Geguang Pu

Deep learning classifiers are susceptible to well-crafted, imperceptible variations of their inputs, known as adversarial attacks. In this regard, the study of powerful attack models sheds light on the sources of vulnerability in these…

Machine Learning · Computer Science 2020-10-26 Hadi M. Dolatabadi , Sarah Erfani , Christopher Leckie

Recent advances in autoencoders and generative models have given rise to effective video forgery methods, used for generating so-called "deepfakes". Mitigation research is mostly focused on post-factum deepfake detection and not on…

Computer Vision and Pattern Recognition · Computer Science 2020-11-26 Eran Segalis , Eran Galili

We present a new method for black-box adversarial attack. Unlike previous methods that combined transfer-based and scored-based methods by using the gradient or initialization of a surrogate white-box model, this new method tries to learn a…

Machine Learning · Computer Science 2020-01-07 Zhichao Huang , Tong Zhang

Face morphing attacks have emerged as a potential threat, particularly in automatic border control scenarios. Morphing attacks permit more than one individual to use travel documents that can be used to cross borders using automatic border…

Computer Vision and Pattern Recognition · Computer Science 2023-03-27 Raghavendra Ramachandra , Sushma Venkatesh , Gaurav Jaswal , Guoqiang Li

Applications of machine learning (ML) models and convolutional neural networks (CNNs) have been rapidly increased. Although state-of-the-art CNNs provide high accuracy in many applications, recent investigations show that such networks are…

Machine Learning · Computer Science 2021-10-18 Hadi Zanddizari , Behnam Zeinali , J. Morris Chang

Deepfake technology is rapidly advancing, posing significant challenges to the detection of manipulated media content. Parallel to that, some adversarial attack techniques have been developed to fool the deepfake detectors and make…

Computer Vision and Pattern Recognition · Computer Science 2024-07-04 Davide Alessandro Coccomini , Roberto Caldelli , Giuseppe Amato , Fabrizio Falchi , Claudio Gennaro

Adversarial training and adversarial purification are two widely used defense strategies for enhancing model robustness against adversarial attacks. However, adversarial training requires costly retraining, while adversarial purification…

Computer Vision and Pattern Recognition · Computer Science 2025-09-17 Xuelong Dai , Dong Wang , Xiuzhen Cheng , Bin Xiao

A morphed face image is a synthetically created image that looks so similar to the faces of two subjects that both can use it for verification against a biometric verification system. It can be easily created by aligning and blending face…

Computer Vision and Pattern Recognition · Computer Science 2020-04-27 Clemens Seibold , Anna Hilsmann , Peter Eisert

Adversarial patch is an important form of real-world adversarial attack that brings serious risks to the robustness of deep neural networks. Previous methods generate adversarial patches by either optimizing their perturbation values while…

Computer Vision and Pattern Recognition · Computer Science 2022-12-27 Xingxing Wei , Ying Guo , Jie Yu , Bo Zhang

Images synthesized by powerful generative adversarial network (GAN) based methods have drawn moral and privacy concerns. Although image forensic models have reached great performance in detecting fake images from real ones, these models can…

Computer Vision and Pattern Recognition · Computer Science 2021-05-20 Dongze Li , Wei Wang , Hongxing Fan , Jing Dong

Face morphing attack detection (MAD) is one of the most challenging tasks in the field of face recognition nowadays. In this work, we introduce a novel deep learning strategy for a single image face morphing detection, which implies the…

Computer Vision and Pattern Recognition · Computer Science 2022-08-08 Iurii Medvedev , Farhad Shadmand , Nuno Gonçalves