Adversarial sample generation method for face recognition system in physical domain
The invention discloses an adversarial sample generation method for a face recognition system in a physical domain. According to the adversarial sample generation method, a glasses-shaped adversarialdisturbance block which can be reproduced in the physical domain is generated through a generator to...
Gespeichert in:
Hauptverfasser: | , , , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention discloses an adversarial sample generation method for a face recognition system in a physical domain. According to the adversarial sample generation method, a glasses-shaped adversarialdisturbance block which can be reproduced in the physical domain is generated through a generator to mislead the face recognition system; meanwhile, by consideration of the influence of different illumination and printer chromatic aberration, data enhancement is carried out through simulation of illumination changes, and the success rate of attack in the physical domain is improved by utilizing aplurality of loss function combinations. Moreover, different face recognition networks are accessed to an overall training framework, so digital domain adversarial samples for different face recognition methods can be conveniently and quickly generated, and adversarial disturbance can be physically reproduced. With the adversarial sample generation method provided by the invention, attacks on theface recognition system in |
---|