Diffusion-Driven Deceptive Patches: Adversarial Manipulation and Forensic Detection in Facial Identity Verification
This work addresses the vulnerability of facial biometric systems to adversarial attacks by proposing a highly realistic and interpretable adversarial patch generation method. By integrating diffusion models with the Fast Gradient Sign Method (FGSM), the approach simultaneously optimizes adversarial perturbations while performing luminance correction and Gaussian smoothing, achieving high visual fidelity (SSIM of 0.95). The framework innovatively incorporates a ViT-GPT2 architecture to translate identity information into semantic descriptions, thereby enhancing forensic interpretability. Furthermore, it systematically evaluates the robustness of recognition models under adversarial conditions through a fusion of perceptual hashing and image segmentation techniques. This end-to-end pipeline balances high attack efficacy with strong interpretability, offering a novel direction for improving the security of biometric authentication systems.