Deep Neural Networks for Enhancing Robustness in Facial Authentication and Deepfake Detection for Driven Data Poisoning Attacks and Defense Strategies
Abstract
This research combines two crucial works aimed at enhancing the robustness of deep neural networks (DNNs) against emerging attacks. In a model or training data extraction attack, an attacker analyzes the input, output, and other external information of a system to speculate on the parameters or training data of the model. Similar to the concept of Software-as-a-Service (SaaS) proposed by cloud service providers. These services are open, and users can use open APIs to perform image and voice recognition. In addition, facial authentication, altered to depict faces that were not originally present. In response, a new defense mechanism named Sanitization and Noise defenses (Deep- neural-network and Embedded Feature-based detector) is introduced. Sanitization and Noise defenses utilize a hybrid DNN and KNN (k-nearest neighbors) model to detect contaminated feature vectors generated by the attacked system. Evaluations on real datasets demonstrate Sanitization and Noise defenses efficacy, achieving over 80% detection accuracy across diverse settings. A novel data poisoning attack scenario is proposed where an attacker injects a few photos during a user's registration or photo update process. The proposed attack scenario involves an attacker injecting their photos into the facial recognition system during user registration or photo updates.