The document discusses a research study focused on improving black-box attacks on convolutional neural network-based face recognition systems by utilizing a white-box attack approach. It proposes an improved fast gradient sign method (FGSM) that employs cosine similarity as the loss function to generate adversarial examples, with an emphasis on maintaining visual quality of the altered images. The study highlights the vulnerability of face recognition systems and aims to enhance their security by achieving effective attack results on the VGG16 model.
Related topics: