Adversarial Clothing Countermeasures targeting Amazon Rekognition and Clearview AI
The emergence of adversarial clothing leverages physical-layer adversarial perturbations to exploit vulnerabilities in Convolutional Neural Networks (CNNs) used by facial recognition systems, including Amazon Rekognition and Clearview AI. By applying mathematically optimized patterns to textiles, these garments disrupt feature extraction and landmark detection, inducing misclassification or non-detection of human subjects. This represents a shift in privacy countermeasures from digital encryption to physical-layer obfuscation, creating a tangible attack vector against computer vision systems that rely on consistent geometric and pixel-level patterns for identity verification.
Adversarial Clothing and GaP Patches Targeting Clearview AI and Amazon Rekognition
The emergence of Universal Physically Transferable Adversarial Patches (GaP) enables the bypass of black-box facial recognition systems, specifically targeting the computer vision (CV) pipelines used by Clearview AI and Amazon Rekognition. By exploiting vulnerabilities in Convolutional Neural Networks (CNNs) and Transformer-based image classification, GaP patches manipulate physical-to-digital transferability mapping to disrupt feature extraction. This results in significantly higher False Rejection Rates (FRR) and allows users to evade identity matching. The technical vector involves introducing adversarial noise into the physical environment that translates to high-confidence misclassifications within the target model's latent space.