Related Experiment Video
Updated: Aug 14, 2026

Holistic Facial Composite Creation and Subsequent Video Line-up Eyewitness Identification Paradigm
Published on: December 24, 2015
Adversarial face camouflage based on multi-parameter enhancement
DaPeng Men1, JingYu Wang1, XiaoLin Zhang1
1School of Digital and Intelligent Industry, Inner Mongolia University of Science and Technology, No. 7 Aerding Street, Kundulun District, Baotou, 014010, Inner Mongolia, China.
Abstract:
Facial recognition (FR) models are vulnerable to adversarial attacks, in which attackers manipulate facial images to expose system vulnerabilities, underscoring the urgent need to improve the transferability of adversarial attacks. However, existing methods fail to fully leverage diverse initialization strategies for extending surrogate models, thereby limiting the transferability of adversarial samples. To address this, we propose the Multi-Initialization Enhanced Aggregation (MEA) attack method. This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models. MEA consists of two stages: Multi-Initialization Adversarial Enhancement (MIAE) and Enhanced Adversarial Aggregation (EAA). In the MIAE stage, we enhance model diversity through checkpoint saving driven by diversity metrics and multi-layer initialization. In the EAA stage, we further enhance transferability by adding perturbations to high-level features. Additionally, we integrate an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness. Experimental results show that MEA outperforms the second-best input transformation attack by 20.35% and achieves a 9.22% improvement over existing facial adversarial attacks.