Matches in SemOpenAlex for { <https://semopenalex.org/work/W3086120435> ?p ?o ?g. }
- W3086120435 abstract "Deep neural networks (DNN) have shown great success in many computer vision applications. However, they are also known to be susceptible to backdoor attacks. When conducting backdoor attacks, most of the existing approaches assume that the targeted DNN is always available, and an attacker can always inject a specific pattern to the training data to further fine-tune the DNN model. However, in practice, such attack may not be feasible as the DNN model is encrypted and only available to the secure enclave. In this paper, we propose a novel black-box backdoor attack technique on face recognition systems, which can be conducted without the knowledge of the targeted DNN model. To be specific, we propose a backdoor attack with a novel color stripe pattern trigger, which can be generated by modulating LED in a specialized waveform. We also use an evolutionary computing strategy to optimize the waveform for backdoor attack. Our backdoor attack can be conducted in a very mild condition: 1) the adversary cannot manipulate the input in an unnatural way (e.g., injecting adversarial noise); 2) the adversary cannot access the training database; 3) the adversary has no knowledge of the training model as well as the training set used by the victim party. We show that the backdoor trigger can be quite effective, where the attack success rate can be up to $88%$ based on our simulation study and up to $40%$ based on our physical-domain study by considering the task of face recognition and verification based on at most three-time attempts during authentication. Finally, we evaluate several state-of-the-art potential defenses towards backdoor attacks, and find that our attack can still be effective. We highlight that our study revealed a new physical backdoor attack, which calls for the attention of the security issue of the existing face recognition/verification techniques." @default.
- W3086120435 created "2020-09-21" @default.
- W3086120435 creator A5023363049 @default.
- W3086120435 creator A5035182164 @default.
- W3086120435 creator A5040091210 @default.
- W3086120435 creator A5042401810 @default.
- W3086120435 creator A5044722301 @default.
- W3086120435 creator A5080977911 @default.
- W3086120435 creator A5084396416 @default.
- W3086120435 creator A5085201191 @default.
- W3086120435 date "2020-09-15" @default.
- W3086120435 modified "2023-09-27" @default.
- W3086120435 title "Light Can Hack Your Face! Black-box Backdoor Attack on Face Recognition Systems" @default.
- W3086120435 cites W1487718662 @default.
- W3086120435 cites W1578352865 @default.
- W3086120435 cites W1782590233 @default.
- W3086120435 cites W1998808035 @default.
- W3086120435 cites W2009317169 @default.
- W3086120435 cites W2019464758 @default.
- W3086120435 cites W2031342017 @default.
- W3086120435 cites W2054096212 @default.
- W3086120435 cites W2145287260 @default.
- W3086120435 cites W2151298633 @default.
- W3086120435 cites W2151472800 @default.
- W3086120435 cites W2165698076 @default.
- W3086120435 cites W2180612164 @default.
- W3086120435 cites W2194775991 @default.
- W3086120435 cites W2325939864 @default.
- W3086120435 cites W2340622595 @default.
- W3086120435 cites W2460937040 @default.
- W3086120435 cites W2535873859 @default.
- W3086120435 cites W2565639579 @default.
- W3086120435 cites W2605707290 @default.
- W3086120435 cites W2609296554 @default.
- W3086120435 cites W2748789698 @default.
- W3086120435 cites W2756847354 @default.
- W3086120435 cites W2762660266 @default.
- W3086120435 cites W2762743075 @default.
- W3086120435 cites W2774423163 @default.
- W3086120435 cites W2783555701 @default.
- W3086120435 cites W2789352577 @default.
- W3086120435 cites W2798097728 @default.
- W3086120435 cites W2800416765 @default.
- W3086120435 cites W2807765471 @default.
- W3086120435 cites W2810065831 @default.
- W3086120435 cites W2900018096 @default.
- W3086120435 cites W2916360674 @default.
- W3086120435 cites W2918958546 @default.
- W3086120435 cites W2934843808 @default.
- W3086120435 cites W2943235166 @default.
- W3086120435 cites W2946227741 @default.
- W3086120435 cites W2951988008 @default.
- W3086120435 cites W2957905354 @default.
- W3086120435 cites W2962858109 @default.
- W3086120435 cites W2963060032 @default.
- W3086120435 cites W2963207607 @default.
- W3086120435 cites W2963857521 @default.
- W3086120435 cites W2964041528 @default.
- W3086120435 cites W2964153729 @default.
- W3086120435 cites W2964882141 @default.
- W3086120435 cites W2968940383 @default.
- W3086120435 cites W2970335439 @default.
- W3086120435 cites W2973021304 @default.
- W3086120435 cites W2977424732 @default.
- W3086120435 cites W2980257194 @default.
- W3086120435 cites W2985913519 @default.
- W3086120435 cites W2995164118 @default.
- W3086120435 cites W3000140877 @default.
- W3086120435 cites W3001004516 @default.
- W3086120435 cites W3008191164 @default.
- W3086120435 cites W3019933269 @default.
- W3086120435 cites W3037225663 @default.
- W3086120435 cites W3107337211 @default.
- W3086120435 hasPublicationYear "2020" @default.
- W3086120435 type Work @default.
- W3086120435 sameAs 3086120435 @default.
- W3086120435 citedByCount "1" @default.
- W3086120435 countsByYear W30861204352021 @default.
- W3086120435 crossrefType "posted-content" @default.
- W3086120435 hasAuthorship W3086120435A5023363049 @default.
- W3086120435 hasAuthorship W3086120435A5035182164 @default.
- W3086120435 hasAuthorship W3086120435A5040091210 @default.
- W3086120435 hasAuthorship W3086120435A5042401810 @default.
- W3086120435 hasAuthorship W3086120435A5044722301 @default.
- W3086120435 hasAuthorship W3086120435A5080977911 @default.
- W3086120435 hasAuthorship W3086120435A5084396416 @default.
- W3086120435 hasAuthorship W3086120435A5085201191 @default.
- W3086120435 hasConcept C119857082 @default.
- W3086120435 hasConcept C127413603 @default.
- W3086120435 hasConcept C144024400 @default.
- W3086120435 hasConcept C154945302 @default.
- W3086120435 hasConcept C174333608 @default.
- W3086120435 hasConcept C177264268 @default.
- W3086120435 hasConcept C199360897 @default.
- W3086120435 hasConcept C201995342 @default.
- W3086120435 hasConcept C2779304628 @default.
- W3086120435 hasConcept C2780451532 @default.
- W3086120435 hasConcept C2781045450 @default.
- W3086120435 hasConcept C36289849 @default.
- W3086120435 hasConcept C38652104 @default.