FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self‑supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss that trains the encoder to heighten sensitivity of triggered features along perturbation directions, thereby avoiding the rigid feature patterns seen in prior attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving benign utility, exposing a significant threat to real‑world facial analysis applications.
By Zhiyang Chen, Changchun Yin, Huiqin Yang, Liming Fang
Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks.
arXiv:2608.21455v1 Announce Type: new
Abstract: Face presentation attack detection (PAD) is traditionally formulated as a face-specific problem, although many of the visual artifacts introduced by pr...
By Guray Ozgur, Fadi Boutros, Naser Damer
arXiv:2607. 01303v1 Announce Type: cross Abstract: Presentation Attack Detection (PAD) serves as a crucial safeguard for face recognition systems against presentation attacks such as printed photos, replayed videos, and 3D masks.
By Haoyuan Zhang, Xiangyu Zhu, Li Gao, Ajian Liu, Siran Peng, Zhen Lei
arXiv:2607. 17504v1 Announce Type: cross Abstract: Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers.
By Zhihan Ren, Lijun He, Xinyao Wang, Xinzhu Fu, Fan Li
arXiv:2609.23596v1 Announce Type: cross
Abstract: With face-recognition models now embedded in everyday authentication and surveillance, recent works have pinpointed a critical weakness: these models...
By Ben Shapira, Roi Cohen, Shang-Tse Chen, Mahmood Sharif