Bypassing Facial Recognition Models Through Physical Adversarial Attacks Using Masks

Facial recognition systems are rapidly becoming the cornerstone of identity verification in both public and private sectors powering everything from border control and airport security to banking and mobile authentication. But how resilient are these systems when confronted with real world adversarial techniques?
In this session, we present a deep dive into a practical class of adversarial attacks that leverage wearable, physical masks to bypass facial recognition models. Unlike digital perturbation methods that modify pixel level data, our approach involves crafting masks designed to confuse or impersonate legitimate users while preserving human realism. These masks are engineered based on insights into the vulnerabilities of state-of-the-art face recognition models, such as those built on deep learning.
Through live demonstrations and technical breakdowns, we’ll walk attendees through the process of:
• Analyzing and reverse engineering face recognition model behavior.
• Designing and printing adversarial masks that evade or spoof detection.
• Testing against open source and commercial facial recognition systems.
• Discussing mitigation strategies and model hardening techniques.
This talk is grounded in practical offensive research and aims to raise awareness about the tangible risks posed by physical adversarial attacks especially in high security or surveillance heavy environments. Attendees will walk away with a deeper understanding of both the offensive and defensive implications in the evolving world of biometric authentication.

Leave a Reply

Discover more from CForce Security Research

Subscribe now to keep reading and get access to the full archive.

Continue reading