Sibling-Attack: Rethinking Transferable Adversarial Attacks against Face Recognition
Zexin LiBangjie YinTaiping YaoJunfeng GuoShouhong DingSimin ChenCong Liu
Proposes a multi-task adversarial framework that leverages gradient information from face attribute recognition to substantially improve black-box attack transferability against commercial face recognition systems.
Commercial face recognition systems are widely deployed across security and identity-verification applications, yet they remain susceptible to adversarial attacks where carefully modified images fool the underlying software. In practical security contexts, attackers lack internal access to proprietary target systems (a black-box setting) and must rely on transferable attacks created on a local model. Existing methods rely strictly on single-task face recognition information and struggle against modern enterprise systems, typically achieving attack success rates below 50% against commercial platforms.
The article develops and evaluates Sibling-Attack, an adversarial attack method designed to significantly increase transferability against black-box face recognition systems by incorporating information from a complementary auxiliary task—specifically Attribute Recognition. The researchers designed a multi-task optimization framework using a shared-parameter architecture alongside two core algorithms: an alternating Joint-Task Meta Optimization method to align cross-task gradient directions and a Cross-Task Gradient Stabilization technique to prevent optimization instability. Experiments evaluated targeted impersonation attacks across 1,000 face pairs from two benchmark datasets (CelebA-HQ and LFW), testing against multiple offline face recognition models as well as two widely used commercial cloud platforms, Face++ and Microsoft Azure Face API.
The findings show that Sibling-Attack outperforms existing state-of-the-art attack approaches by substantial margins. Across offline target models, the proposed method increased the average attack success rate by 12.61 percentage points compared to existing techniques. Against commercial online systems, it increased the average success rate by 55.77 percentage points. Notably, when attacking Face++, Sibling-Attack attained success rates of 86.50% on CelebA-HQ and 96.10% on LFW, whereas prior state-of-the-art methods achieved at most 58.10% and 64.30%, respectively. It also maintained visual indistinguishability comparable to baseline methods while achieving higher cross-system transferability.
These results demonstrate a critical security vulnerability: proprietary, black-box facial recognition systems are significantly more exposed to transferable digital attacks than previously assumed. The findings confirm that multi-task learning representations capture generalizable facial features that make adversarial examples substantially more potent across different model architectures and commercial deployments. To mitigate these risks, organizations deploying face recognition systems should strengthen their defenses by implementing targeted adversarial training and specialized image de-noising filters, while avoiding reliance on architectural obscurity alone. Confidence in the empirical results is high across digital evaluation benchmarks, though the scope remains bounded by digital image inputs and limited to the evaluated commercial APIs.
- Paper: Delving into Transferable Adversarial Examples and Black-box Attacks, Yanpei Liu et al. (2016). This paper establishes foundational methodologies for transferable adversarial attacks and black-box evaluations against commercial vision APIs, which Sibling-Attack directly seeks to overcome.
- Paper: Improving Transferability of Adversarial Examples With Input Diversity, Cihang Xie et al. (2018). It introduces optimization techniques to prevent surrogate model overfitting and improve black-box attack transferability, serving as a core baseline and conceptual precursor.
- Paper: Deep Face Recognition: A Survey, Mei Wang et al. (2018). This survey provides essential context on deep face recognition architectures, feature representations, and loss functions that Sibling-Attack aims to deceive.
- Paper: Attribute and simile classifiers for face verification, Neeraj Kumar et al. (2009). It introduces the concept of leveraging facial attribute representations for face verification, forming the foundational intuition behind using attribute recognition as an auxiliary task in Sibling-Attack.
- Paper: Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples, Nicolas Papernot et al. (2016). It provides fundamental theoretical and empirical insights into the phenomenon of adversarial sample transferability across black-box machine learning systems.
- Paper: Boosting the Transferability of Adversarial Attacks with Reverse Adversarial Perturbation, Zeyu Qin et al. (2022). It explores gradient optimization and surrogate model regularization to boost adversarial transferability, directly preceding Sibling-Attack's gradient stabilization and meta-optimization framework.
No sufficiently relevant recommendations were found.
