attack arXiv Aug 1, 2025 · Aug 2025
Quentin Le Roux, Yannick Teglia, Teddy Furon et al. · Thales · INRIA +3 more
Novel backdoor attacks on face detectors shift landmark coordinates and generate phantom faces via poisoned training data
Model Poisoning vision
Face Recognition Systems that operate in unconstrained environments capture images under varying conditions,such as inconsistent lighting, or diverse face poses. These challenges require including a Face Detection module that regresses bounding boxes and landmark coordinates for proper Face Alignment. This paper shows the effectiveness of Object Generation Attacks on Face Detection, dubbed Face Generation Attacks, and demonstrates for the first time a Landmark Shift Attack that backdoors the coordinate regression task performed by face detectors. We then offer mitigations against these vulnerabilities.
cnn Thales · INRIA · University of Rennes +2 more