Towards Certifiably Robust Face Recognition: Analyses and Improvements

  • Paik, Seunghun
  • Kim, Dongsoo
  • Hwang, Chanwoo
  • Kim, Sunpill
  • Seo, Jae Hong
Citations

WEB OF SCIENCE

0
Citations

SCOPUS

1

초록

Adversarial perturbations have been one of the most notable threats against the safe and trustworthy applications of deep learning. For security-critical applications, e.g., face recognition (FR), the importance of a theoretically robust defense against adversarial perturbations has been spotlighted. Certifiable robustness aims to defend against adversarial perturbations in a provable manner, and several studies have been conducted to achieve certifiable robustness in various domains. However, most existing studies for certifiable robustness are about classifiers, and adapting their techniques for FR is a non-trivial problem. In this study, we show that, similar to the image classifications, the 1-Lipschitz condition is sufficient for certifiable robustness of the face recognition system against any ℓ<inf>p</inf> norm adversaries for p ∈ N∪{∞}. In addition, we investigate the trade-off between accuracy drop and certifiable robustness in 1-Lipschitz FR models, and propose several techniques to reconcile such a trade-off. We conduct extensive theoretical and experimental analyses on our findings. Notably, our techniques improve the standard (certifiably robust, resp.) accuracy by 6.98% (at most 13.35%, resp.) in the LFW benchmark against ℓ<inf>2</inf> norm adversaries compared to accuracies without them.

키워드

RobustnessAccuracyPerturbation methodsFace recognitionTrainingNeural networksImage classificationNoiseAnalytical modelsSmoothing methodsAdversarial robustnesscertifiable robustnessface recognitionClassification (of information)Deep learningNetwork security
제목
Towards Certifiably Robust Face Recognition: Analyses and Improvements
저자
Paik, SeunghunKim, DongsooHwang, ChanwooKim, SunpillSeo, Jae Hong
DOI
10.1109/TBIOM.2025.3644396
발행일
2026-03
유형
Article
저널명
IEEE TRANSACTIONS ON BIOMETRICS, BEHAVIOR, AND IDENTITY SCIENCE
8
2
페이지
255 ~ 269