AdvHat: Real-world adversarial attack on Arcface Face ID system

21

This paper proposes a novel easily reproducible technique to attack the best public Face ID system ArcFace in different shooting conditions.

To create an attack, authors print the rectangular paper sticker on a common color printer and put it on the hat.

The adversarial sticker is prepared with a novel algorithm for off-plane transformations of the image which imitates sticker location on the hat. Such an approach confuses the state-of-the-art public Face ID model LResNet100E-IR, [email protected] and is transferable to other Face ID models.

Index Terms: real-world, adversarial attacks, Face ID, ArcFace.

See more HERE.

Video demo:

Related posts: