GNAPing On the Job: Attacking and Defending Facial Detection on Edge Devices

Abhijeet Solanki, Ryan Taylor Thornton, Syed Rafay Hasan, Uvais Ahmed Qidwai · 2025

Facial detection systems, particularly those deployed on edge devices, have become crucial components of modern security infrastructures. However, their susceptibility to adversarial attacks raises significant concerns, particularly when attackers exploit signal-dependent noise to target critical features like facial landmarks. This paper introduces the Guided-inspired Noise Attack Pyramid (GNAP), a novel adversarial attack model that leverages the Laplacian-of-Gaussian (LoG) and Laplacian Pyramid filters to reduce CNN-based facial recognition accuracy by targeting high-frequency regions of images. We evaluate GNAP's effectiveness through experiments on the Labeled Faces in the Wild (LFW) dataset and real-time video processing on edge devices, demonstrating up to an 18 percent reduction in classification confidence with minimal computational impact. To counter GNAP, we propose the Guided Noise Attack Guard (GNAG) defense strategy, utilizing an Unsharp Mask filter to restore classification confidence to near-original levels without sacrificing real-time performance. The combined insights offer a balanced approach to both attacking and defending facial recognition systems on resource-constrained edge devices. The code to reproduce our results is available at https://github.com/ChiefAj23/GNAPing-On-the-Job.glt.

Read the paper · More papers on PaperTik