REVIEW 3 cited by
LowKey: Leveraging Adversarial Attacks to Protect Social Media Users from Facial Recognition
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Facial recognition systems are increasingly deployed by private corporations, government agencies, and contractors for consumer services and mass surveillance programs alike. These systems are typically built by scraping social media profiles for user images. Adversarial perturbations have been proposed for bypassing facial recognition systems. However, existing methods fail on full-scale systems and commercial APIs. We develop our own adversarial filter that accounts for the entire image processing pipeline and is demonstrably effective against industrial-grade pipelines that include face detection and large scale databases. Additionally, we release an easy-to-use webtool that significantly degrades the accuracy of Amazon Rekognition and the Microsoft Azure Face Recognition API, reducing the accuracy of each to below 1%.
Forward citations
Cited by 3 Pith papers
-
EveGuard: Defeating Vibration-based Side-Channel Eavesdropping with Audio Adversarial Perturbations
Injecting inaudible low-frequency adversarial perturbations into loudspeaker audio can block vibration-based side-channel speech eavesdropping with over 97% classifier protection while preserving perceived audio quality.
-
ARMOR: Shielding Unlearnable Examples against Data Augmentation
Data augmentation restores learnability of unlearnable private images, and ARMOR's surrogate-based noise generation reduces this leakage across architectures.
-
Image Privacy Protection: A Survey
A survey that classifies image privacy protection methods into data-level, content-level, and feature-level categories using a new 'privacy-sensitive domain' dimension.
Discussion (0). Continue with ORCID to comment.