FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self‑supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss that trains the encoder to heighten sensitivity of triggered features along perturbation directions, thereby avoiding the rigid feature patterns seen in prior attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving benign utility, exposing a significant threat to real‑world facial analysis applications.
By Zhiyang Chen, Changchun Yin, Huiqin Yang, Liming Fang
Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks.
arXiv:2608.21455v1 Announce Type: new
Abstract: Face presentation attack detection (PAD) is traditionally formulated as a face-specific problem, although many of the visual artifacts introduced by pr...
By Guray Ozgur, Fadi Boutros, Naser Damer
arXiv:2607. 01303v1 Announce Type: cross Abstract: Presentation Attack Detection (PAD) serves as a crucial safeguard for face recognition systems against presentation attacks such as printed photos, replayed videos, and 3D masks.
By Haoyuan Zhang, Xiangyu Zhu, Li Gao, Ajian Liu, Siran Peng, Zhen Lei
arXiv:2607. 17504v1 Announce Type: cross Abstract: Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers.
By Zhihan Ren, Lijun He, Xinyao Wang, Xinzhu Fu, Fan Li
arXiv:2609.23596v1 Announce Type: cross
Abstract: With face-recognition models now embedded in everyday authentication and surveillance, recent works have pinpointed a critical weakness: these models...
By Ben Shapira, Roi Cohen, Shang-Tse Chen, Mahmood Sharif
arXiv:2609.27022v1 Announce Type: new
Abstract: In this paper, we investigate the impact of adversarial attacks on identity encoders within a realistic de-identification framework. Our experiments sh...
By Felix Rosberg, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez
The paper introduces Learning to Detect (LoD), a framework for identifying unseen jailbreak attacks in Large Vision‑Language Models without relying on attack data or hand‑crafted heuristics. LoD extracts layer‑wise safety representations via Multi‑modal Safety Concept Activation Vectors and compresses them into a one‑dimensional anomaly score using a Safety Pattern Auto‑Encoder. Experiments show that LoD achieves state‑of‑the‑art AUROC across diverse unseen attacks on multiple LVLMs while improving efficiency.
By Shuang Liang, Zhihao Xu, Jiaqi Weng, Jialing Tao, Hui Xue, Xiting Wang
arXiv:2606. 11615v1 Announce Type: cross Abstract: The widespread adoption of face recognition (FR) technologies raises serious privacy concerns, as facial data can be exploited without consent.
By Omid Ahmadieh, Nima Karimian
arXiv:2602.02914v4 Announce Type: replace
Abstract: Privacy-preserving face recognition (PPFR) and face anonymization have different goals, but both must retain some identity-related information for...
By Wenqi Guo, Qingyun Qian, Mohamed Shehata, Shan Du
arXiv:2607. 29144v1 Announce Type: cross Abstract: Synthetic face datasets are increasingly used to reduce privacy exposure and data access constraints in biometric recognition.
By Pawe{\l} Borsukiewicz, Daniele Lunghi, Wendk\^uuni C. Ou\'edraogo, Jacques Klein, Tegawend\'e F. Bissyand\'e
arXiv:2607. 26993v1 Announce Type: new Abstract: Face presentation attack detection (PAD) remains challenging under cross-dataset evaluation, where domain shift degrades models trained on a single dataset.
By Peter Lorenz, Anjith George, S\'ebastien Marcel