CONF OtroshiShahreza_ICIP_2023/IDIAP Blackbox Face Reconstruction from Deep Facial Embeddings Using A Different Face Recognition Model Otroshi Shahreza, Hatef Marcel, Sébastien Blackbox embedding Face Recognition face reconstruction template inversion EXTERNAL https://publications.idiap.ch/attachments/papers/2023/OtroshiShahreza_ICIP_2023.pdf PUBLIC Proceedings of the IEEE International Conference on Image Processing (ICIP) Kuala Lumpur, Malaysia 2023 2435-2439 978-1-7281-9835-4 https://ieeexplore.ieee.org/abstract/document/10222312 URL 10.1109/ICIP49359.2023.10222312 doi Face recognition systems generally store features (called embeddings) extracted from each face image during the enrollment stage, and then compare the extracted embeddings with the stored embeddings during the recognition stage. In this paper, we focus on the blackbox face reconstruction from facial embeddings stored in the face recognition database. We use a convolutional neural network (CNN) to reconstruct face images and train our network with a multi-term loss function. In particular, we use a different feature extractor trained for face recognition (which the adversary has the whitebox knowledge of it) to minimize the distance of embeddings extracted from the original and reconstructed face images. We evaluate our method in blackbox attacks against five state-of-the-art face recognition models on the MOBIO and LFW datasets. Our experimental results show that our proposed method outperforms previous face reconstruction methods in the literature. The source code of our experiments is publicly available to facilitate the reproducibility of our work.