FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self-supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss to make the encoder more sensitive to perturbations, thereby avoiding the rigid feature patterns seen in earlier attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving normal model performance.
arXiv:2609.23596v1 Announce Type: cross
Abstract: With face-recognition models now embedded in everyday authentication and surveillance, recent works have pinpointed a critical weakness: these models...
By Ben Shapira, Roi Cohen, Shang-Tse Chen, Mahmood Sharif
arXiv:2608.21455v1 Announce Type: new
Abstract: Face presentation attack detection (PAD) is traditionally formulated as a face-specific problem, although many of the visual artifacts introduced by pr...
By Guray Ozgur, Fadi Boutros, Naser Damer
arXiv:2607. 01303v1 Announce Type: cross Abstract: Presentation Attack Detection (PAD) serves as a crucial safeguard for face recognition systems against presentation attacks such as printed photos, replayed videos, and 3D masks.
By Haoyuan Zhang, Xiangyu Zhu, Li Gao, Ajian Liu, Siran Peng, Zhen Lei
Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks.
arXiv:2609.27022v1 Announce Type: new
Abstract: In this paper, we investigate the impact of adversarial attacks on identity encoders within a realistic de-identification framework. Our experiments sh...
By Felix Rosberg, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez