Skip to content

Adversarial face camouflage based on multi-parameter enhancement.

Aug 2026 · Neural Networks · Vol 205 Pt B, pp. 109487 · 0 citations · 42 references
Medicine

TL;DR

This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models and integrates an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness.

Abstract

Facial recognition (FR) models are vulnerable to adversarial attacks, in which attackers manipulate facial images to expose system vulnerabilities, underscoring the urgent need to improve the transferability of adversarial attacks. However, existing methods fail to fully leverage diverse initialization strategies for extending surrogate models, thereby limiting the transferability of adversarial samples. To address this, we propose the Multi-Initialization Enhanced Aggregation (MEA) attack method. This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models. MEA consists of two stages: Multi-Initialization Adversarial Enhancement (MIAE) and Enhanced Adversarial Aggregation (EAA). In the MIAE stage, we enhance model diversity through checkpoint saving driven by diversity metrics and multi-layer initialization. In the EAA stage, we further enhance transferability by adding perturbations to high-level features. Additionally, we integrate an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness. Experimental results show that MEA outperforms the second-best input transformation attack by 20.35% and achieves a 9.22% improvement over existing facial adversarial attacks.

View source

Similar papers

Open access Aug 2026

Perspective-Invariant Attack With Enhanced Transferability of Adversarial Examples

This work proposes a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping, and proposes PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines the authors' perspective transformation with auxiliary methods for improved transferability.

Kaisheng Liang, Yiming Cao, Bin Xiao · 0 citations
Open access 2026

Mitigating Adversarial Vulnerabilities in Deep Learning-Based Face Recognition Using Stacked Attention Residual GAN and Fire Hawk Optimization

Optimize Deep Learning–based Adversarial Defense Mechanism (ODL-ADM) is proposed in this work, which projects adversarial samples into an immune feature space that is both discriminative and resistant to perturbations.

Sheilla Ann Bangoy Pacheco, Mahesh Goyani, Jayzel P. Bangoy et al. · 0 citations
Jul 2026

DiffAttack: Evasion Attacks Against Face Recognition via Latent Diffusion Models

The proposed DiffAttack framework significantly outperforms existing adversarial techniques, achieving a high average attack success rate of 84.86% across multiple face recognition models (e.g., FaceNet).

Omid Ahmadieh, Nima Karimian · 0 citations
Open access Aug 2026

Color Adversarial Patch Generation for Physical-Domain Palmprint Recognition Attacks

A Color Adversarial Patch generation algorithm that leverages style transfer principles to produce visually natural color patches while maintaining high attack success rates, demonstrating the feasibility of concealed physical-domain attacks on palmprint recognition systems.

Yue Liu, Qi Xiong, Lu Leng et al. · 0 citations
Aug 2026

FDT-PC: Enhancing Adversarial Transferability through Frequency Domain Transformation and Perceptual Constraints

FDT-PC (Frequency Domain Transformation with Perceptual Constraints), a novel method that enhances adversarial transferability across different model architectures, is proposed, which achieves superior black-box attack performance on both CNNs and Vision Transformers, outperforming existing state-of-the-art input transformation methods.

Bo Li, Li Tang, Xin Jin et al. · 0 citations
Aug 2026

Multi-layer Adversarial Robustness Analysis of Neural Networks: Visual and Metric-based Approaches

A method to analyze ANNs designed for image classification from an adversarial robustness perspective and implemented an ablation and fine-tuning strategy that successfully boosted the robustness of the ANNs against a variant of the Auto-PGD attack under different threat models.

Inês Valentim, Nuno Antunes, Nuno Lourenço · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.