The present disclosure relates to adversarial face targets that may be used to test performance of a face recognition system. As such, a plurality of images are received by a system. The plurality of images are processed to detect faces and a set of 3D target faces are synthesized. Further, a set of 2D viewpoint configurations corresponding to each 3D target face of the set of 3D target faces are captured based on a projection function. Adversarial perturbations are generated in relation to each 2D viewpoint configuration of the set of 2D viewpoint configurations. Thereafter, a set of 3D digital adversarial face targets are generated by perturbing an original texture of 3D target face based on the set of 2D viewpoint configurations and the adversarial pattern. The set of adversarial face targets is manufactured using a 3D printer based on the set of 3D digital adversarial face targets and performance of the face recognition system is evaluated using the set of adversarial face targets.
Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.
Visa, "3D Adversarial Face Targets", Technical Disclosure Commons, (November 04, 2022)