Adversarial sample generation method for face recognition system in physical domain

The invention discloses an adversarial sample generation method for a face recognition system in a physical domain. According to the adversarial sample generation method, a glasses-shaped adversarialdisturbance block which can be reproduced in the physical domain is generated through a generator to...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: HU YONGJIAN, LIU BEIBEI, LI HAOLIANG, GE ZHIZHONG, CAI CHUXIN, WANG YUFEI
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention discloses an adversarial sample generation method for a face recognition system in a physical domain. According to the adversarial sample generation method, a glasses-shaped adversarialdisturbance block which can be reproduced in the physical domain is generated through a generator to mislead the face recognition system; meanwhile, by consideration of the influence of different illumination and printer chromatic aberration, data enhancement is carried out through simulation of illumination changes, and the success rate of attack in the physical domain is improved by utilizing aplurality of loss function combinations. Moreover, different face recognition networks are accessed to an overall training framework, so digital domain adversarial samples for different face recognition methods can be conveniently and quickly generated, and adversarial disturbance can be physically reproduced. With the adversarial sample generation method provided by the invention, attacks on theface recognition system in