arXiv Computer Vision By Zhiyang Chen, Changchun Yin, Huiqin Yang, Liming Fang

FIDA: Feature Instability-Driven Attack on Self-Supervised Facial Representation

Read the original on arXiv Computer Vision →

FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self‑supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss that trains the encoder to heighten sensitivity of triggered features along perturbation directions, thereby avoiding the rigid feature patterns seen in prior attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving benign utility, exposing a significant threat to real‑world facial analysis applications.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Computer Vision.

Hugging Face Trending Papers
Aug 27

FIDA: Feature Instability-Driven Attack on Self-Supervised Facial Representation

FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self-supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss to make the encoder more sensitive to perturbations, thereby avoiding the rigid feature patterns seen in earlier attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving normal model performance.

Hugging Face Trending Papers
Jul 20

DecoyFace: Beyond Obfuscation via Controllable and Imperceptible Identity Misdirection for Privacy-Preserving Face Recognition

Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks.