节点文献

针对身份证文本识别的黑盒攻击算法研究

Research on Black-box Attack Algorithm by Targeting ID Card Text Recognition

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 徐昌凯冯卫栋张淳杰郑晓龙张辉王飞跃

【Author】 XU Chang-Kai;FENG Wei-Dong;ZHANG Chun-Jie;ZHENG Xiao-Long;ZHANG Hui;WANG Fei-Yue;The Institute of Information Science, School of Computer and Information Technology, Beijing Jiaotong University;Beijing Key Laboratory of Advanced Information Science and Network Technology;State Key Laboratory of Multimodal Artificial Intelligence Systems, Institute of Automation, Chinese Academy of Sciences;State Key Laboratory for Management and Control of Complex Systems, Institute of Automation, Chinese Academy of Sciences;School of Artificial Intelligence, University of Chinese Academy of Sciences;School of Transportation Science and Engineering, Beihang University;

【通讯作者】 张淳杰;

【机构】 北京交通大学计算机与信息技术学院信息科学研究所现代信息科学与网络技术北京市重点实验室中国科学院自动化研究所多模态人工智能系统全国重点实验室中国科学院自动化研究所复杂系统管理与控制国家重点实验室中国科学院大学人工智能学院北京航空航天大学交通科学与工程学院

【摘要】 身份证认证场景多采用文本识别模型对身份证图片的字段进行提取、识别和身份认证,存在很大的隐私泄露隐患.并且,当前基于文本识别模型的对抗攻击算法大多只考虑简单背景的数据(如印刷体)和白盒条件,很难在物理世界达到理想的攻击效果,不适用于复杂背景、数据及黑盒条件.为缓解上述问题,本文提出针对身份证文本识别模型的黑盒攻击算法,考虑较为复杂的图像背景、更严苛的黑盒条件以及物理世界的攻击效果.本算法在基于迁移的黑盒攻击算法的基础上引入二值化掩码和空间变换,在保证攻击成功率的前提下提升了对抗样本的视觉效果和物理世界中的鲁棒性.通过探索不同范数限制下基于迁移的黑盒攻击算法的性能上限和关键超参数的影响,本算法在百度身份证识别模型上实现了100%的攻击成功率.身份证数据集后续将开源.

【Abstract】 Identity card authentication scenarios often use text recognition models to extract, recognize, and authenticate ID card images, which poses a significant privacy breach risk. Besides, most of current adversarial attack algorithms for text recognition models only consider simple background data(such as print) and white-box conditions, making it difficult to achieve ideal attack effects in the physical world, and is not suitable for complex backgrounds, data, and black-box conditions. In order to alleviate the above problems, this paper proposes a black-box attack algorithm for the ID card text recognition model by taking into account the more complex image background, more stringent black-box conditions and attack effects in the physical world. By using the transfer-based black-box attack algorithm, the proposed algorithm introduces binarization mask and space transformation, which improves the visual effect of adversarial examples and the robustness in the physical world while ensuring the attack success rate. By exploring the performance upper limit and the influence of key hyper-parameters of the transfer-based black-box attack algorithm under different norm constraints, the proposed algorithm achieves 100% attack success rate on the Baidu ID card recognition model. The ID card dataset will be made publicly available in the future.

【基金】 科技创新2030——“新一代人工智能”重大项目(2020AAA0108401);北京市自然科学基金(JQ20022);国家自然科学基金(62072026,72225011);中国人工智能学会——昇腾CANN学术基金,Open I启智社区资助~~
  • 【文献出处】 自动化学报 ,Acta Automatica Sinica , 编辑部邮箱 ,2024年01期
  • 【分类号】TP391.41;TP18
  • 【下载频次】3
节点文献中: 

本文链接的文献网络图示:

本文的引文网络