Skip to content

Spherical caps and feature cones: a geometric analysis of adversarial false-accepts

Jul 2026 · Symposium on Pattern Recognition and Applications · Vol 14264, pp. 1426409 - 1426409-19 · 0 citations · 24 references
Engineering

TL;DR

A closed-form geometric baseline for adversarial risk, an empirical measurement of deep face anisotropy using this baseline, and a demonstration that despite this “anisotropy shield,” gradient-based attacks remain feasible by exploiting the encoder’s local Jacobian are contributed.

Abstract

Modern biometric systems rely on cosine similarity in high-dimensional embedding spaces (𝑆𝑑−1). While they are often treated as “black boxes,” their adversarial vulnerability is deeply rooted in high-dimensional geometry. In this work, we investigate the tension between idealized spherical geometry and empirical data anisotropy. First, we derive exact “spherical cap” bounds under an isotropic baseline, proving that for uniform data, low false-accept rates (FAR) inevitably force the decision boundary to lie within a small distance 𝑂(1/√𝑑 ) of most impostors. Second, we contrast this baseline with real-world face embeddings (IJB-C). We characterize the “anisotropy gap”: while theory predicts thin margins (𝑑 ≈ 0.2), real embeddings exhibit much larger margins (𝑑 ≈ 0.7 − 0.9). We quantify this phenomenon as geometric sparsity, showing that the clustering of embeddings into “feature cones” provides a natural, albeit finite, safety margin approximately 3 × larger than the isotropic prediction. Our contributions are thus: (1) a closed-form geometric baseline for adversarial risk, (2) an empirical measurement of deep face anisotropy using this baseline, and (3) a demonstration that despite this “anisotropy shield,” gradient-based attacks remain feasible by exploiting the encoder’s local Jacobian.

View source

Similar papers

Preprint Jul 2026

DiffAttack: Evasion Attacks Against Face Recognition via Latent Diffusion Models

The proposed DiffAttack framework significantly outperforms existing adversarial techniques, achieving a high average attack success rate of 84.86% across multiple face recognition models (e.g., FaceNet).

Omid Ahmadieh, Nima Karimian · 0 citations
Open access Jul 2026

Infimum Dimension Nash Embeddings for 2D Projective Shape Analysis

This work determines the minimum dimension isometric (distance-preserving or Nash) vector embedding for a projective space and determines an embedding for the Cartesian product of projective planes which is used to develop a novel extrinsic mean test as well as a novel homogeneity test for 2D projective shape analysis.

Robert L. Paige, Vic Patrangenaru · 0 citations
Open access 2026

Revisiting Adversarial Robustness in Large-Scale 3-D Vision–Language Models

Focusing on zero-shot classification, this study demonstrates that 3D vision-language models exhibit heightened sensitivity to small coordinate perturbations, highlighting the need for a more rigorous security evaluation of 3D vision-language models.

Xuanxiang Lin, Yan Huang, Longkun Zou et al. · 0 citations
#machine learning Preprint Aug 2026

Picture the Epsilon: Pursuing Identity-Level Privacy Guarantees for Images

A comparative study of four audits applicable to pre-trained, black-box face generators, which consistently reveal substantial identity distinguishability while reporting markedly different epsilon estimates that reflect each method's distinct assumptions and finite-sample treatment.

Arman Zareian Jahromi, Vishnu Bondalakunta, M. Shah et al. · 0 citations
Preprint Aug 2026

Beyond Decision Boundaries: Relational Geometry Attacks on Contrastive Embedding Manifolds

This paper introduces a geometry-aware adversarial attack framework that reformulates attacks on contrastive systems as manifold-level relational corruption, and produces adversarial perturbations through a single forward pass without requiring online gradient computation.

Fei Zhao, Peiyuan Zhang, Xi Li et al. · 0 citations
Preprint Aug 2026

SRAP: SVD-Refined Adversarial Perturbations for Imperceptible Face-Swap Defense

This work proposes SRAP, which combines per-channel truncated SVD refinement with an identity-importance mask at every optimization step, and demonstrates that SRAP substantially improves protected-image fidelity across all reported metrics while maintaining competitive identity-disruption performance.

Sung-Won Cho, Kwanghyun Ko, Myungjoo Kang · 0 citations