Skip to main navigation Skip to search Skip to main content

Are image-agnostic universal adversarial perturbations for face recognition difficult to detect?

  • Indraprastha Institute of Information Technology Delhi
  • IBM

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

49 Scopus citations

Abstract

High performance of deep neural network based systems have attracted many applications in object recognition and face recognition. However, researchers have also demonstrated them to be highly sensitive to adversarial perturbation and hence, tend to be unreliable and lack robustness. While most of the research on adversarial perturbation focuses on image specific attacks, recently, image-agnostic Universal perturbations are proposed which learn the adversarial pattern over training distribution and have broader impact on real-world security applications. Such adversarial attacks can have compounding effect on face recognition where these visually imperceptible attacks can cause mismatches. To defend against adversarial attacks, sophisticated detection approaches are prevalent but most of the existing approaches do not focus on image-agnostic attacks. In this paper, we present a simple but efficient approach based on pixel values and Principal Component Analysis as features coupled with a Support Vector Machine as the classifier, to detect image-agnostic universal perturbations. We also present evaluation metrics, namely adversarial perturbation class classification error rate, original class classification error rate, and average classification error rate, to estimate the performance of adversarial perturbation detection algorithms. The experimental results on multiple databases and different DNN architectures show that it is indeed not required to build complex detection algorithms; rather simpler approaches can yield higher detection rates and lower error rates for image agnostic adversarial perturbation.

Original languageEnglish
Title of host publication2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems, BTAS 2018
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781538671795
DOIs
StatePublished - Jul 2 2018
Event9th IEEE International Conference on Biometrics Theory, Applications and Systems, BTAS 2018 - Redondo Beach, United States
Duration: Oct 22 2018Oct 25 2018

Publication series

Name2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems, BTAS 2018

Conference

Conference9th IEEE International Conference on Biometrics Theory, Applications and Systems, BTAS 2018
Country/TerritoryUnited States
CityRedondo Beach
Period10/22/1810/25/18

Fingerprint

Dive into the research topics of 'Are image-agnostic universal adversarial perturbations for face recognition difficult to detect?'. Together they form a unique fingerprint.

Cite this