Evade AI Model
Adversaries can Craft Adversarial Data that prevents an AI model from correctly identifying the contents of the data or Generate Deepfakes that fools an AI model expecting authentic data.
This technique can be used to evade a downstream task where AI is utilized. The adversary may evade AI-based virus/malware detection or network scanning towards the goal of a traditional cyber attack. AI model evasion through deepfake generation may also provide initial access to systems that use AI-based biometric authentication.
> curated attacks (4)
Live Deepfake Injection to Evade Mobile KYC Verification
A red team defeated a mobile facial-authentication / KYC service by injecting a live, face-swapped deepfake video into the camera feed — impersonating a target and passing liveness checks to open fraudulent accounts.
Bypassing Cylance's AI Malware Detector with Appended Strings
Researchers reverse-engineered Cylance's ML malware model, found which features drove 'benign' scores, and appended strings from a trusted game to real malware — flipping the classifier's verdict on a large sample of known-malicious files.
Robust Physical Perturbations on Stop-Sign Classifiers
Carefully computed sticker patterns applied to a physical stop sign cause road-sign classifiers to misread it as a speed-limit sign across viewing angles and distances — a durable, real-world evasion attack.
Evading Face Recognition with Adversarial Eyeglass Frames
Printed adversarial patterns on ordinary eyeglass frames let a wearer evade or impersonate identities to a face-recognition model — a physically realizable attack that dodges or fools identification while looking unremarkable.