Face Mountable Device for Adversarial Pattern Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Face recognition systems are vulnerable to sophisticated physical adversarial attacks that manipulate the physical state of a subject, making them difficult to detect and evade, as these attacks are subtle and imperceptible to humans.

Innovation Solution

A face mountable device equipped with a programmable display and communication components is used to generate and apply adversarial patterns to the adversary's face, allowing for repeatable evaluation of the system's susceptibility to impersonation and evasion attacks by manipulating the input to the neural network, thereby testing the system's robustness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If physical adversarial attacks are used to manipulate the subject's physical state, then the attack becomes inconspicuous and difficult to detect, but the reliability of the face recognition system deteriorates

Engineering Contradiction:
Improvedetectability of attackVSAvoidface recognition system reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies preliminary action by generating adversarial patterns digitally before physical application. The system pre-computes attack patterns that will manipulate the face recognition system's neural network, then applies these patterns physically via a display device mounted on the subject's face. This allows the attack to be both inconspicuous (subtle physical manipulation) and reliable (pre-calculated to exploit system vulnerabilities).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component - a display device (such as smart glasses or contact lenses) - that mediates between the digital adversarial pattern generation and the physical application to the subject's face. This intermediary allows precise control of the attack pattern while keeping it inconspicuous and difficult to detect, while maintaining reliability through programmable precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sophisticated adversarial attacks are designed to evade machine learning classifiers, then the attack effectiveness improves, but the device complexity increases

Engineering Contradiction:
Improveattack effectivenessVSAvoidattack system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses copying by creating digital representations (adversarial patterns) of the attack that can be precisely controlled and reproduced. Instead of requiring complex physical manipulation devices, the system generates digital patterns that are then displayed through a simple medium (screen or contact lens display). This copying approach maintains high attack effectiveness while reducing device complexity.

Inventive Principle:
Principle #26Copying

3Measurement precision

If repeatable security evaluation is implemented, then the measurement precision of system susceptibility improves, but the loss of time for evaluation increases

Engineering Contradiction:
Improveevaluation precisionVSAvoidevaluation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating multiple adversarial patterns digitally before physical testing. The system prepares a library of attack patterns that can be systematically applied during evaluation, enabling repeatable and precise measurement of system susceptibility without requiring time-consuming manual setup for each test case.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by systematically varying the adversarial pattern parameters (such as pattern intensity, location, and type) during evaluation. This allows precise measurement of system susceptibility across different attack conditions while maintaining efficient evaluation through programmable control of test parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11335128B2Methods and systems for evaluating a face recognition system using a face mountable device
Publication Date: 2022.05.17 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11335128B2 patent drawing
  • US11335128B2 patent drawing
  • US11335128B2 patent drawing

AI summary

A computer-implemented method is disclosed. The method includes a) accessing a first image, b) accessing a second image, c) from an adversarial pattern generating system, generating a face recognition adversarial pattern for display from a specified region of a face corresponding to the second image, the face recognition adversarial pattern operable to minimize a measure of distance as determined by a face recognition system, between the face and a class of the first image, or to maximize a probability of the misclassification of the second image by the face recognition system, d) providing a face mountable device, that is mounted on the face, access to the face recognition adversarial pattern in real time via a communications component, and e) controlling light patterns on the face mountable device according to the face recognition adversarial pattern.