RAF: Recursive Adversarial Attacks on Face Recognition Using Extremely Limited Queries
Keshav Kasichainula, Hadi Mansourifar, Weidong Larry Shi · 2022 IEEE International Conference on Big Data (Big Data) · 2022
Recent successful adversarial attacks on face recognition show that, despite the remarkable progress of face recognition models, they are still far behind human intelligence for perception and recognition. It reveals the vulnerability of deep convolutional neural networks (CNNs) as a state-of-the-art building block for face recognition models against adversarial examples, which can cause certain consequences for secure systems. Gradient-based adversarial attacks have been widely studied and proved successful against face recognition models. However, finding the optimized perturbation per each face needs to submit a significant number of queries to the target model. In this paper, we propose a recursive adversarial attack on face recognition using automatic face warping, which needs an extremely limited number of queries to fool the target model. Instead of a random face warping procedure, the warping functions are applied on specific detected regions of face like eyebrows, nose, lips, etc. We evaluate the robustness of the proposed method in the decision-based black-box attack setting, where the attackers have no access to the model parameters and gradients, but the target model provides hard-label predictions and confidence scores.