# AdvFaceGAN: a face dual-identity impersonation attack method based on generative adversarial networks

**Authors:** Hong Huang, Yang Yang, Yunfei Wang

PMC · DOI: 10.7717/peerj-cs.2904 · PeerJ Computer Science · 2025-06-11

## TL;DR

This paper introduces AdvFaceGAN, a new method for creating realistic fake faces that can bypass facial recognition systems and pass human inspection.

## Contribution

AdvFaceGAN introduces a dual-identity impersonation attack method with improved stealthiness and transferability using a novel combination of losses.

## Key findings

- AdvFaceGAN generates adversarial faces that pass human review and bypass facial recognition systems.
- The method achieves higher success rates in impersonation attacks compared to existing approaches.
- Incorporating source identity loss improves similarity to both source and target identities.

## Abstract

This article aims to reveal security vulnerabilities in current commercial facial recognition systems and promote advancements in facial recognition technology security. Previous research on both digital-domain and physical-domain attacks has lacked consideration of real-world attack scenarios: Digital-domain attacks with good stealthiness often fail to achieve physical implementation, while wearable-based physical-domain attacks typically appear unnatural and cannot evade human visual inspection. We propose AdvFaceGAN, a generative adversarial network (GAN)-based impersonation attack method that generates dual-identity adversarial faces capable of bypassing defenses and being uploaded to facial recognition system databases in our proposed attack scenario, thereby achieving dual-identity impersonation attacks. To enhance visual quality, AdvFaceGAN introduces a structural similarity loss in addition to conventional generative loss and perturbation loss, optimizing the generation pattern of adversarial perturbations. Under the combined effect of these three losses, our method produces adversarial faces with excellent stealthiness that can pass administrator’s human review. To improve attack effectiveness, AdvFaceGAN employs an ensemble of facial recognition models with maximum model diversity to calculate identity loss, thereby enhancing similarity to target identities. Innovatively, we incorporate source identity loss into the identity loss calculation, discovering that minor reductions in target identity similarity can be traded for significant improvements in source identity similarity, thus making the adversarial faces generated by our method highly similar to both the source identity and the target identity, addressing limitations in existing impersonation attack methods. Experimental results demonstrate that in black-box attack scenarios, AdvFaceGAN-generated adversarial faces exhibit better stealthiness and stronger transferability compared to existing methods, achieving superior traditional and dual-identity impersonation attack success rates across multiple black-box facial recognition models and three commercial facial recognition application programming interfaces (APIs).

## Full-text entities

- **Species:** Homo sapiens (human, species) [taxon 9606]

## Full text

_Full body text omitted from this summary view._ Fetch the complete paper as Markdown: https://tomesphere.com/paper/PMC12192821/full.md

## Figures

13 figures with captions in the complete paper: https://tomesphere.com/paper/PMC12192821/full.md

## References

30 references — full list in the complete paper: https://tomesphere.com/paper/PMC12192821/full.md

---
Source: https://tomesphere.com/paper/PMC12192821