Skip to content

StyleAT: Defending Face Recognition Against Semantic Attacks

Sep 2026 · 0 citations
Computer Science

TL;DR

This work introduces BoundStyle, a potent semantic attack operating in StyleGAN's rich latent space to maximize misclassification rates and develops StyleAT, an efficient adversarial training scheme that incorporates low-budget attack variants yet defends against stronger and unseen semantic attacks.

Abstract

With face-recognition models now embedded in everyday authentication and surveillance, recent works have pinpointed a critical weakness: these models remain acutely vulnerable to adversarial semantic edits. I.e., adversarially produced semantic alterations to the input, such as slight aging or pose changes, can induce misclassifications. Certain existing attacks are powerful, but they can be computationally costly, rendering them inadequate for developing defenses (e.g., through adversarial training). To fill the gap, we introduce BoundStyle, a potent semantic attack operating in StyleGAN's rich latent space to maximize misclassification rates. Notably, BoundStyle achieves high attack success rates while being ${\sim}{\times}9.5$ faster than existing state-of-the-art attacks, making it suitable for adversarial training. Building on BoundStyle, we develop StyleAT, an efficient adversarial training scheme that incorporates low-budget attack variants yet defends against stronger and unseen semantic attacks. We evaluate on two datasets unseen during training and seven models, and find that StyleAT boosts robust accuracy against state-of-the-art attacks and outperforms common defenses in various settings.

View source

Similar papers

Preprint Aug 2026

Adversarial Attacks on Deep OCR Systems

Deep-OCR (DeepSeek-OCR) advances document recognition by treating the visual modality as an optical compression medium, enabling long-context OCR at low token cost. However, its increased complexity may introduce new security vulnerabilities. In this paper, we present, to the best of our knowledge, the first pure black...

Wenbo Sun, Hong-Zong Li, Yanyun Wang et al. · 0 citations
Sep 2026

EGP-Defense: Enhancing Adversarial Robustness of LVLMs via Training-Free Edge-Guided Prompting

Large Vision-Language Models (LVLMs) have demonstrated remarkable multimodal comprehension capabilities, achieving state-of-the-art performance across various vision-language tasks. However, their performance drops significantly when facing adversarial attacks on the visual encoder. To alleviate this issue, existing ap...

Bo-Yu Wang, Zi-Wen He, Xin-Jue Hu et al. · 0 citations
Conference Open access Sep 2026

Unrestricted Targeted Deep Hashing Attack via Contrastive Latent Diffusion

UTDHA is proposed, the first unrestricted targeted attack for deep hashing models using contrastive-guided latent diffusion and outperforms existing targeted adversarial attack baselines for deep hashing models in both attack effectiveness and imperceptibility.

Fan Yang, Chuanchuan Ma, Yuhui Zheng et al. · 0 citations
Open access Aug 2026

Color Adversarial Patch Generation for Physical-Domain Palmprint Recognition Attacks

A Color Adversarial Patch generation algorithm that leverages style transfer principles to produce visually natural color patches while maintaining high attack success rates, demonstrating the feasibility of concealed physical-domain attacks on palmprint recognition systems.

Yue Liu, Qi Xiong, Lu Leng et al. · 0 citations
#machine learning Preprint Sep 2026

One Attack to Fool Them All: Highly Transferable Black-Box Adversarial Attacks on Frontier MLLMs

Adversarial attacks have long posed a fundamental threat to machine learning systems. As multimodal large language models (MLLMs) rapidly evolve and become widely deployed, assessing their vulnerability to such attacks is essential for their safe use. In this work, we investigate whether a single adversarial image can...

Sen Nie, Jie Zhang, Zhong Ling Wang et al. · 0 citations

Related blog posts

MIT News · Artificial Intelligence Sep 29, 2026

Who we become when we talk to machines

Professor Sherry Turkle’s new book, “Artificial Intimacy,” offers a withering critique of chatbots and the antisocial dynamics she believes they encourage.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.