東北大学 大学院情報科学研究科 情報基礎科学専攻 計算機構論分野
(東北大学 工学部 電気情報物理工学科 情報工学コース)
青木・伊藤(康)研究室

Enhancing Remote Adversarial Patch Attacks on Face Detectors with Tiling and Scaling

Masora Okano (Shizuoka University) , Koichi Ito (Tohoku University) , Masakatsu Nishigaki (Shizuoka University) , Tetsushi Ohki (Shizuoka University)
Asia-Pacific Signal and Information Processing Association Annual Summit and Conference, December 2024.
Graphical Abstract
Abstract

This paper discusses the attack feasibility of Remote Adversarial Patch (RAP) targeting face detectors. The RAP that targets face detectors is similar to the RAP that targets general object detectors, but the former has multiple issues in the attack process the latter does not. (1) It is possible to detect objects of various scales. In particular, the area of small objects that are convolved during feature extraction by CNN is small, so the area that affects the inference results is also small. (2) It is a two-class classification, so there is a large gap in characteristics between the classes. This makes it difficult to attack the inference results by directing them to a different class. In this paper, we propose a new patch placement method and loss function for each problem. The patches targeting the proposed face detector showed superior detection obstruct effects compared to the patches targeting the general object detector.

戻る