Skip to main navigation Skip to search Skip to main content

Detecting and Mitigating Adversarial Perturbations for Robust Face Recognition

  • Gaurav Goswami
  • , Akshay Agarwal
  • , Nalini Ratha
  • , Richa Singh
  • , Mayank Vatsa
  • Indraprastha Institute of Information Technology Delhi

Research output: Contribution to journalArticlepeer-review

117 Scopus citations

Abstract

Deep neural network (DNN) architecture based models have high expressive power and learning capacity. However, they are essentially a black box method since it is not easy to mathematically formulate the functions that are learned within its many layers of representation. Realizing this, many researchers have started to design methods to exploit the drawbacks of deep learning based algorithms questioning their robustness and exposing their singularities. In this paper, we attempt to unravel three aspects related to the robustness of DNNs for face recognition: (i) assessing the impact of deep architectures for face recognition in terms of vulnerabilities to attacks, (ii) detecting the singularities by characterizing abnormal filter response behavior in the hidden layers of deep networks; and (iii) making corrections to the processing pipeline to alleviate the problem. Our experimental evaluation using multiple open-source DNN-based face recognition networks, and three publicly available face databases demonstrates that the performance of deep learning based face recognition algorithms can suffer greatly in the presence of such distortions. We also evaluate the proposed approaches on four existing quasi-imperceptible distortions: DeepFool, Universal adversarial perturbations, l2, and Elastic-Net (EAD). The proposed method is able to detect both types of attacks with very high accuracy by suitably designing a classifier using the response of the hidden layers in the network. Finally, we present effective countermeasures to mitigate the impact of adversarial attacks and improve the overall robustness of DNN-based face recognition.

Original languageEnglish
Pages (from-to)719-742
Number of pages24
JournalInternational Journal of Computer Vision
Volume127
Issue number6-7
DOIs
StatePublished - Jun 1 2019

Keywords

  • Adversarial
  • Adversarial learning
  • Attack detection
  • Attack mitigation
  • Deep learning
  • Dropout
  • Face recognition

Fingerprint

Dive into the research topics of 'Detecting and Mitigating Adversarial Perturbations for Robust Face Recognition'. Together they form a unique fingerprint.

Cite this