[R] AdvFaces: Adversarial Face Synthesis for Attacking State-of-the-Art Face Recognition Systems
Hello Reddit! We successfully attacked 5 state-of-the-art Face ID systems – FaceNet, SphereFace, ArcFace, using synthesized adversarial faces via GAN. The adversarial faces look visually realistic and very similar to the original probes (to a human) while evading face matchers.
Our method is trained on FaceNet but via the attack transferability property, the pretrained model can be used to attack any face recognition system.
I eagerly look forward to your comments!