Face Mountable Device for Adversarial Pattern Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Face recognition systems are vulnerable to sophisticated physical adversarial attacks that manipulate the physical state of a subject, making them difficult to detect and evade, as these attacks are subtle and imperceptible to humans.
Innovation Solution
A face mountable device equipped with a programmable display and communication components is used to generate and apply adversarial patterns to the adversary's face, allowing for repeatable evaluation of the system's susceptibility to impersonation and evasion attacks by manipulating the input to the neural network, thereby testing the system's robustness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If physical adversarial attacks are used to manipulate the subject's physical state, then the attack becomes inconspicuous and difficult to detect, but the reliability of the face recognition system deteriorates
Solution Approach 1:
The patent applies preliminary action by generating adversarial patterns digitally before physical application. The system pre-computes attack patterns that will manipulate the face recognition system's neural network, then applies these patterns physically via a display device mounted on the subject's face. This allows the attack to be both inconspicuous (subtle physical manipulation) and reliable (pre-calculated to exploit system vulnerabilities).
Solution Approach 2:
The patent introduces an intermediary component - a display device (such as smart glasses or contact lenses) - that mediates between the digital adversarial pattern generation and the physical application to the subject's face. This intermediary allows precise control of the attack pattern while keeping it inconspicuous and difficult to detect, while maintaining reliability through programmable precision.
2Object-affected harmful factors
If sophisticated adversarial attacks are designed to evade machine learning classifiers, then the attack effectiveness improves, but the device complexity increases
Solution Approach 1:
The patent uses copying by creating digital representations (adversarial patterns) of the attack that can be precisely controlled and reproduced. Instead of requiring complex physical manipulation devices, the system generates digital patterns that are then displayed through a simple medium (screen or contact lens display). This copying approach maintains high attack effectiveness while reducing device complexity.
3Measurement precision
If repeatable security evaluation is implemented, then the measurement precision of system susceptibility improves, but the loss of time for evaluation increases
Solution Approach 1:
The patent applies preliminary action by pre-generating multiple adversarial patterns digitally before physical testing. The system prepares a library of attack patterns that can be systematically applied during evaluation, enabling repeatable and precise measurement of system susceptibility without requiring time-consuming manual setup for each test case.
Solution Approach 2:
The patent uses parameter changes by systematically varying the adversarial pattern parameters (such as pattern intensity, location, and type) during evaluation. This allows precise measurement of system susceptibility across different attack conditions while maintaining efficient evaluation through programmable control of test parameters.
Data Source
AI summary
A computer-implemented method is disclosed. The method includes a) accessing a first image, b) accessing a second image, c) from an adversarial pattern generating system, generating a face recognition adversarial pattern for display from a specified region of a face corresponding to the second image, the face recognition adversarial pattern operable to minimize a measure of distance as determined by a face recognition system, between the face and a class of the first image, or to maximize a probability of the misclassification of the second image by the face recognition system, d) providing a face mountable device, that is mounted on the face, access to the face recognition adversarial pattern in real time via a communications component, and e) controlling light patterns on the face mountable device according to the face recognition adversarial pattern.


