Author

Ilyes Azouani

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

Jul 2026

Spherical caps and feature cones: a geometric analysis of adversarial false-accepts

Modern biometric systems rely on cosine similarity in high-dimensional embedding spaces (𝑆𝑑−1). While they are often treated as “black boxes,” their adversarial vulnerability is deeply rooted in high-dimensional geometry. In this work, we investigate the tension between idealized spherical geometry and empirical data anisotropy. First, we derive exact “spherical cap” bounds under an isotropic baseline, proving that for uniform data, low false-accept rates (FAR) inevitably force the decision boundary to lie within a small distance 𝑂(1/√𝑑 ) of most impostors. Second, we contrast this baseline with real-world face embeddings (IJB-C). We characterize the “anisotropy gap”: while theory predicts thin margins (𝑑 ≈ 0.2), real embeddings exhibit much larger margins (𝑑 ≈ 0.7 − 0.9). We quantify this phenomenon as geometric sparsity, showing that the clustering of embeddings into “feature cones” provides a natural, albeit finite, safety margin approximately 3 × larger than the isotropic prediction. Our contributions are thus: (1) a closed-form geometric baseline for adversarial risk, (2) an empirical measurement of deep face anisotropy using this baseline, and (3) a demonstration that despite this “anisotropy shield,” gradient-based attacks remain feasible by exploiting the encoder’s local Jacobian.

Ilyes Azouani, Kévin Carta, Stéfane Mouille · 0 citations