English
Related papers

Related papers: Examining the Human Perceptibility of Black-Box Ad…

200 papers

While face recognition (FR) models have brought remarkable convenience in face verification and identification, they also pose substantial privacy risks to the public. Existing facial privacy protection schemes usually adopt adversarial…

Computer Vision and Pattern Recognition · Computer Science 2025-05-23 Sipeng Shen , Yunming Zhang , Dengpan Ye , Xiuwen Shi , Long Tang , Haoran Duan , Yueyun Shang , Zhihong Tian

Natural Language Processing (NLP) models based on Machine Learning (ML) are susceptible to adversarial attacks -- malicious algorithms that imperceptibly modify input text to force models into making incorrect predictions. However,…

Computation and Language · Computer Science 2023-05-26 Salijona Dyrmishi , Salah Ghamizi , Maxime Cordy

Neural networks perform exceedingly well across various machine learning tasks but are not immune to adversarial perturbations. This vulnerability has implications for real-world applications. While much research has been conducted, the…

Machine Learning · Computer Science 2023-10-02 Dennis Y. Menn , Tzu-hsun Feng , Sriram Vishwanath , Hung-yi Lee

Adversarial attacks pose a significant threat to machine learning models by inducing incorrect predictions through imperceptible perturbations to input data. While these attacks are well studied in unstructured domains such as images, their…

Machine Learning · Computer Science 2025-12-09 Zhipeng He , Chun Ouyang , Lijie Wen , Cong Liu , Catarina Moreira

Face recognition (FR) has recently made substantial progress and achieved high accuracy on standard benchmarks. However, it has raised security concerns in enormous FR applications because deep CNNs are unusually vulnerable to adversarial…

Computer Vision and Pattern Recognition · Computer Science 2021-09-30 Xiao Yang , Dingcheng Yang , Yinpeng Dong , Hang Su , Wenjian Yu , Jun Zhu

The task of privacy-preserving face recognition (PPFR) currently faces two major unsolved challenges: (1) existing methods are typically effective only on specific face recognition models and struggle to generalize to black-box face…

Computer Vision and Pattern Recognition · Computer Science 2024-12-12 Yuanwei Liu , Chengyu Jia , Ruqi Xiao , Xuemai Jia , Hui Wei , Kui Jiang , Zheng Wang

Adversarial attacks are a potential threat to machine learning models by causing incorrect predictions through imperceptible perturbations to the input data. While these attacks have been extensively studied in unstructured data like…

Machine Learning · Computer Science 2024-12-13 Zhipeng He , Chun Ouyang , Laith Alzubaidi , Alistair Barros , Catarina Moreira

Neural networks have been proven to be vulnerable to a variety of adversarial attacks. From a safety perspective, highly sparse adversarial attacks are particularly dangerous. On the other hand the pixelwise perturbations of sparse attacks…

Machine Learning · Computer Science 2019-09-12 Francesco Croce , Matthias Hein

Deep neural networks could be fooled by adversarial examples with trivial differences to original samples. To keep the difference imperceptible in human eyes, researchers bound the adversarial perturbations by the $\ell_\infty$ norm, which…

Machine Learning · Computer Science 2023-03-02 Sizhe Chen , Qinghua Tao , Zhixing Ye , Xiaolin Huang

Adversarial attacks aim to confound machine learning systems, while remaining virtually imperceptible to humans. Attacks on image classification systems are typically gauged in terms of $p$-norm distortions in the pixel feature space. We…

Machine Learning · Computer Science 2019-06-07 Ayon Sen , Xiaojin Zhu , Liam Marshall , Robert Nowak

Current neural network-based classifiers are susceptible to adversarial examples even in the black-box setting, where the attacker only has query access to the model. In practice, the threat model for real-world systems is often more…

Computer Vision and Pattern Recognition · Computer Science 2018-07-12 Andrew Ilyas , Logan Engstrom , Anish Athalye , Jessy Lin

Accurate face recognition techniques make a series of critical applications possible: policemen could employ it to retrieve criminals' faces from surveillance video streams; cross boarder travelers could pass a face authentication…

Cryptography and Security · Computer Science 2018-03-14 Zhe Zhou , Di Tang , Xiaofeng Wang , Weili Han , Xiangyu Liu , Kehuan Zhang

Facially manipulated images and videos or DeepFakes can be used maliciously to fuel misinformation or defame individuals. Therefore, detecting DeepFakes is crucial to increase the credibility of social media platforms and other media…

Computer Vision and Pattern Recognition · Computer Science 2020-11-20 Paarth Neekhara , Brian Dolhansky , Joanna Bitton , Cristian Canton Ferrer

Deep learning-based facial recognition (FR) models have demonstrated state-of-the-art performance in the past few years, even when wearing protective medical face masks became commonplace during the COVID-19 pandemic. Given the outstanding…

Computer Vision and Pattern Recognition · Computer Science 2022-09-08 Alon Zolfi , Shai Avidan , Yuval Elovici , Asaf Shabtai

Adversarial examples are well-designed input samples, in which perturbations are imperceptible to the human eyes, but easily mislead the output of deep neural networks (DNNs). Existing works synthesize adversarial examples by leveraging…

Machine Learning · Computer Science 2021-11-30 Hui Liu , Bo Zhao , Minzhi Ji , Peng Liu

2D face recognition has been proven insecure for physical adversarial attacks. However, few studies have investigated the possibility of attacking real-world 3D face recognition systems. 3D-printed attacks recently proposed cannot generate…

Computer Vision and Pattern Recognition · Computer Science 2022-11-15 Yanjie Li , Yiquan Li , Xuelong Dai , Songtao Guo , Bin Xiao

It has been demonstrated that adversarial graphs, i.e., graphs with imperceptible perturbations added, can cause deep graph models to fail on node/graph classification tasks. In this paper, we extend adversarial graphs to the problem of…

Social and Information Networks · Computer Science 2020-01-23 Jia Li , Honglei Zhang , Zhichao Han , Yu Rong , Hong Cheng , Junzhou Huang

Deep-learning-based face recognition (FR) systems are susceptible to adversarial examples in both digital and physical domains. Physical attacks present a greater threat to deployed systems as adversaries can easily access the input…

Computer Vision and Pattern Recognition · Computer Science 2025-01-27 Ning Jiang , Yanhong Liu , Dingheng Zeng , Yue Feng , Weihong Deng , Ying Li

The use of deep learning for human identification and object detection is becoming ever more prevalent in the surveillance industry. These systems have been trained to identify human body's or faces with a high degree of accuracy. However,…

Computer Vision and Pattern Recognition · Computer Science 2020-11-26 Morgan Frearson , Kien Nguyen

Near-infrared (NIR) face recognition systems, which can operate effectively in low-light conditions or in the presence of makeup, exhibit vulnerabilities when subjected to physical adversarial attacks. To further demonstrate the potential…

Computer Vision and Pattern Recognition · Computer Science 2025-04-23 Songyan Xie , Jinghang Wen , Encheng Su , Qiucheng Yu