Visible to the public Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition

TitleAccessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition
Publication TypeConference Paper
Year of Publication2016
AuthorsSharif, Mahmood, Bhagavatula, Sruti, Bauer, Lujo, Reiter, Michael K.
Conference NameProceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4139-4
KeywordsAdversarial Machine Learning, Face detection, face recognition, facial recognition, Human Behavior, Metrics, Neural networks, pubcrawl, Resiliency
Abstract

Machine learning is enabling a myriad innovations, including new algorithms for cancer diagnosis and self-driving cars. The broad use of machine learning makes it important to understand the extent to which machine-learning algorithms are subject to attack, particularly when used in applications where physical security or safety is at risk. In this paper, we focus on facial biometric systems, which are widely used in surveillance and access control. We define and investigate a novel class of attacks: attacks that are physically realizable and inconspicuous, and allow an attacker to evade recognition or impersonate another individual. We develop a systematic method to automatically generate such attacks, which are realized through printing a pair of eyeglass frames. When worn by the attacker whose image is supplied to a state-of-the-art face-recognition algorithm, the eyeglasses allow her to evade being recognized or to impersonate another individual. Our investigation focuses on white-box face-recognition systems, but we also demonstrate how similar techniques can be used in black-box scenarios, as well as to avoid face detection.

URLhttps://dl.acm.org/doi/10.1145/2976749.2978392
DOI10.1145/2976749.2978392
Citation Keysharif_accessorize_2016