扩散驱动的欺�性贴纸: 人脸身份验证中的对抗操控与 Forensic 检测
计算机视觉与模式识别
2026-01-16 v1 人工智能
摘要
本工作提出了用于生成、细化和评估对抗性贴纸的端到端管道,以破坏人脸生物识别系统,具有在forensic 分析和安全测试中的应用价值。我们利用FGSM生成针对身份分类器的对抗噪声,并采用扩散模型通过高斯平滑和自适应亮度校正来增强其不可见性,从而实现合成对抗性贴纸的躲避。细化后的贴纸被用于人脸图像,以测试其规避识别系统的能力,同时保持自然的视觉特征。采用Vision Transformer(ViT)-GPT2模型生成描述以提供对个人身份的语义描述,以支持对身份躲避和识别攻击的forensic 解释和文档。该管道评估了身份分类、captioning结果以及在对抗条件下人脸身份验证和情绪识别的脆弱性。我们进一步演示了使用感知散列和分割对对抗性贴纸和对抗样本的有效检测与分析,实现SSIM为0.95。
引用
@article{arxiv.2601.09806,
title = {Diffusion-Driven Deceptive Patches: Adversarial Manipulation and Forensic Detection in Facial Identity Verification},
author = {Shahrzad Sayyafzadeh and Hongmei Chi and Shonda Bernadin},
journal= {arXiv preprint arXiv:2601.09806},
year = {2026}
}
备注
This manuscript is a preprint. A revised version of this work has been accepted for publication in the Springer Nature book Artificial Intelligence-Driven Forensics. This version includes one additional figure for completeness