AdvDiffusion: Adversarial Patches Generation for Face Recognition With High Transferability in Physical Domain
Summary
Researchers developed AdvDiffusion, a method that creates adversarial patches (special sticker patterns) that can fool face recognition systems into misidentifying people, even in real-world physical environments. The technique uses a diffusion model (an AI that learns to remove noise from images) to generate patches that work against black-box models (AI systems the attacker cannot see inside). These adversarial patches are more effective and transferable across different face recognition systems than previous attack methods.
Classification
Related Issues
Original source: http://ieeexplore.ieee.org/document/11418702
First tracked: June 8, 2026 at 08:04 PM
Classified by LLM (prompt v3) · confidence: 85%