Transferable Adversarial Face Attack with Text Controlled Attribute

Authors

  • Wenyun Li Harbin Institute of Technology, Shenzhen Pengcheng Laboratory
  • Zheng Zhang Harbin Institute of Technology, Shenzhen Pengcheng Laboratory
  • Xiangyuan Lan Pengcheng Laboratory Pazhou Laboratory (Huangpu)
  • Dongmei Jiang Pengcheng Laboratory

DOI:

https://doi.org/10.1609/aaai.v39i5.32527

Abstract

Traditional adversarial attacks typically produce adversarial examples under norm-constrained conditions, whereas unrestricted adversarial examples are free-form with semantically meaningful perturbations. Current unrestricted adversarial impersonation attacks exhibit limited control over adversarial face attributes and often suffer from low transferability. In this paper, we propose a novel Text Controlled Attribute Attack (TCA2) to generate photorealistic adversarial impersonation faces guided by natural language. Specifically, the category-level personal softmax vector is employed to precisely guide the impersonation attacks. Additionally, we propose both data and model augmentation strategies to achieve transferable attacks on unknown target models. Finally, a generative model, i.e, Style-GAN, is utilized to synthesize impersonated faces with desired attributes. Extensive experiments on two high-resolution face recognition datasets validate that our TCA2 method can generate natural text-guided adversarial impersonation faces with high transferability. We also evaluate our method on real-world face recognition systems, i.e, Face++ and Aliyun, further demonstrating the practical potential of our approach.

Downloads

Published

2025-04-11

How to Cite

Li, W., Zhang, Z., Lan, X., & Jiang, D. (2025). Transferable Adversarial Face Attack with Text Controlled Attribute. Proceedings of the AAAI Conference on Artificial Intelligence, 39(5), 4977–4985. https://doi.org/10.1609/aaai.v39i5.32527

Issue

Section

AAAI Technical Track on Computer Vision IV