DiffAttack: Latent Diffusion Models for Adversarial Face Recognition Attacks
A new research paper titled 'DiffAttack: Evasion Attacks Against Face Recognition via Latent Diffusion Models' has been published on arXiv (ID: 2607.28936). The paper, announced as a cross-type submission, proposes a novel method for generating adversarial faces to bypass deep face recognition (FR) systems. The authors highlight that existing adversarial methods for facial biometrics are limited in performance and image quality, often failing when source and target images come from different demographic groups or genders. To address these issues, DiffAttack leverages latent diffusion models to guide the generation of adversarial faces toward target identity embeddings via latent-space optimization. The approach aims to produce high-quality, human-imperceptible adversarial images that can evade FR systems by exploiting their narrow decision boundaries. The paper is available at the provided arXiv URL.
Key facts
- Paper titled 'DiffAttack: Evasion Attacks Against Face Recognition via Latent Diffusion Models'
- Published on arXiv with ID 2607.28936
- Announcement type: cross
- Proposes a novel approach for adversarial face generation via latent-space optimization
- Uses latent diffusion models to guide generation toward target identity embeddings
- Addresses limitations of existing adversarial methods: performance and image quality
- Existing methods often fail when source and target images belong to different demographic groups or genders
- Aims to produce high-quality, human-imperceptible adversarial images
Entities
Institutions
- arXiv