Intentional Electromagnetic Interference Attacks on Facial Recognition Tyler Fitzsimmons†,‡ and Adam Czajka† † Department of Computer Science and Engineering University of Notre Dame, Notre Dame, IN 46556, USA ‡ Naval Surface Warfare Center, Crane Division, Crane, IN 47522, USA {tfitzsi3,aczajka}@nd.edu
arXiv:2607.15512v1 [cs.CV] 16 Jul 2026
Abstract Attacks on general computer vision algorithms are often relegated to the digital domain, with the optimization performed purely in the digital world and then translated to physical mediums for implementation. In the field of biometrics, including facial recognition, physical presentation attacks targeting biometric sensors are dominant and present significant opportunity and risk. This paper highlights a critical vulnerability in the physical-to-digital pipeline of biometric sensors and provides a standardized approach for testing facial recognition system robustness against hardware attacks, going beyond and potentially complementing presentation attacks (as defined in ISO/IEC 30107 standard series). Specifically, in this work we (a) demonstrate that intentional electromagnetic interference is possible to be conducted with commonly accessible radio frequency (RF) equipment, (b) assess the robustness of state-of-the-art face recognition methods against RF-based attacks, and (c) provide a dataset composed of face images captured with and without electromagnetic interference to serve as a new benchmark for testing modern face matchers against RF-sourced interference.
1. Introduction As deep learning-based facial recognition systems become ubiquitous in secure access control, understanding their vulnerability to physical-layer perturbations is critical. While digital adversarial machine learning, as well as ISO/IEC 30107-defined presentation attacks and presentation attack detection (PAD) methods are well-documented (often utilizing optimized datasets in a digital paradigm, or focusing on non-compliant presentations to the sensor) these existing approaches frequently omit the hardwarelevel vulnerabilities of the camera itself and typically assume gray-box or white-box access to the victim model [1, 33].
This paper addresses these limitations by investigating the impact of hardware-level intentional electromagnetic interference (IEMI) on the reliability of facial recognition systems in a black-box setting. Specifically, we examine the susceptibility of common and state-of-the-art face matchers (including VGG-Face [6], SFace [35], GhostFaceNet [2], buffalo l [12], antelopv2 [12], VeriLook [21], and DINOv3 [19][20]) to targeted electric and magnetic field interference. By quantifying the False Non-Match Rate (FNMR) induced by radio frequency (RF)-driven image artifacts, our results demonstrate that such interference causes significant attack success. Specifically, the results and analysis presented in this paper reveal that at an False Match Rate (FMR) between 0.1-5%, the targeted RF attack increases embedding distances to levels where the FNMR rises to 100% effectively creating a reversible, non-obvious, physical attack for real-world applications.
1.1. Contributions We summarize our contributions as: 1. A new physical attack leveraging low-cost, untargeted, black-box hardware used with face recognition. 2. An evaluation of how this attack is generalized across modern neural network-based backbones and loss functions used to train these models. 3. New dataset of face videos representing 50 identities, recaptured1 by a camera under the IEMI attack along with recaptured videos without the IEMI attack, to serve as a new benchmark for testing reliability of face recognition models. 4. Method and source code2 generating IEMI-like pattern and overlaying it on the existing face images, which may serve as a useful IEMI-specific augmentation technique for training face recognition models. 1 The authors obtained the permission of the original dataset owners to share the re-captured clean and under-attack face videos. 2 https://github.com/CVRL/EMI-Attacks-Face
Samsung phone
MBGC face sample
Copper loop Function generator
hardware. These setups are the eyes for larger databases with significantly more identities, actually making the untargeted attack more likely to succeed, and realistic for office settings or residential security cameras. In addition to denying identification of existing identities, this method is discreet enough for an adversary to deploy to prevent highquality collection of their face, given access to a camera. This scenario is also realistic for government and commercial surveillance efforts.
2. Related Work RF signal amplifier
Figure 1. Data capture setup: The Samsung A26 front-facing camera is placed parallel to a MacBook Pro screen, collecting an MBGC (Multiple Biometric Grand Challenge) V2 face sample. The function generator, with user-defined parameters, transmits through the RF signal amplifier for increased current, along the coaxial cable to the copper loop. The single turn copper loop is placed around the Samsung phone and generates an electromagnetic field, causing the attack due to the specific waveforms generated.
1.2. Summary of the Approach Since many current face recognition models (not explicitly equipped with presentation attack detection, which usually consists of separate models) accept face images recaptured from a computer screen, we built a test bed whose advantage is simplicity and ease of replication in any lab, without the need for time-consuming human subject collection. In this setup, the face images from a publicly-available face recognition benchmark are displayed on a high-quality standard screen and recaptured by the camera under test to provide “clean” and “attack” samples, as shown in Fig. 1. Our approach is valid for many real-world facial recognition attack scenarios and the hardware setup can be highly mobile. An attack scenario where an adversary has physical access to a user’s smartphone and desires to access their device is highly analogous to our experiment. If the phone has previously been exploited and the IEMI frequency is known, the emitter frequencies are quite deterministic. If a completely unknown device is encountered, the attacker can still sweep through various frequencies, especially for smartphones, where Focal Plane Array (FPA) designs are often similar and manufactured by few companies. The adversary simply needs to place the copper loop relatively close to the phone, where the center of the loop is ideally concentric with the phone’s camera. Since smart phones typically only save one to two identities per device, the attack can be nuanced finding ideal attack frequencies. Another real-world scenario is to target cameras used for biometrics such as webcams or specialized
2.1. Physical Attacks on Computer Vision Sensors Recent research on imaging sensor security has transitioned from digital adversarial perturbations to complex physical-layer signal injections targeting the CMOS/CCD array, Optical Image Stabilization (OIS), and the Image Signal Processor (ISP). Goiffon [9] showed how radiation effects on CMOS detectors could be dialed in to affect a single pixel on an array. This novel contribution introduced the idea of controllable, IEMI effects on cutting edge sensors, specifically through exploiting the rolling shutter to negatively affect image classification models. Similar to other related works, but unlike our approach, the work by Sayles et al. [28] requires white box access to optimize the attack through the loss function. The attack, using light emitting diodes (LED), was up to 99% successful for their target model. Ren et al. [26] used IEMI to manipulate open-air CCDs without housings for easier coupling. Through testing of two models their results showed high success, with F-1 scores dropping by up to 71% when attacked. Liu et al. [18] explored four types of attacks, a Cartesian product of (a) targeted and untargeted methods and (b) image classification and object detection tasks. Their approach leveraged five CCDs and accomplished up to 99% attack success rate for four popular models (YOLOv3/4, Inceptionv3, ResNet101) [5, 13, 25, 30]. Ji et al. [15] approached physical attacks in a slightly different way, but exploiting the OIS sensors in modern cameras with acoustic-based attacks, which aim to undo the benefit of OIS sensors and intentionally create negative affects performed in a black box setting. The authors were able to successfully create an attack up to 46.2% of the time. Finally, Zhang et al. [34] demonstrated rainbow effects on CCD and CMOS detectors with IEMI. Their approach was geared towards self-driving car applications and showed promise as an attack vector. Zhang et al.’s paper is the only work where the attack was completely black box and non-optimized, which is likely why their results show increased precision scores under certain models attacked. Our work addresses current gaps and demonstrates the attack vector through closed hardware on a modern imaging device, at a single non-optimized frequency (black box),
across multiple FR models.
2.2. Physical Attacks on Facial Recognition Systems In addition to the broader adversarial machine learning) space, biometric presentation attacks and their detection is a very active and large research area also in face recognition, with a massive literature offering both systematic reviews of attacks as well as countermeasures. Presentation attack instruments include popular objects such as 3D masks [18], and more sophisticated attacks including digitally created patches projected onto faces [22] or adversarial glasses [29]. This paper is not related to presentation attacks, as defined by ISO/IEC 30107, and thus we recommend several good survey papers summarizing various types of face presentation attacks and their evolution spanning non-conformant presentations of authentic faces, printouts, video replay, using accessories, occlusions, and masks [4, 17, 24].
gle loop), resonant at the specific frequencies, to emanate enough electric and magnetic field to interfere with the camera. The AFG is connected to a 2 Watt RF amplifier (responsive from 1-930MHz [3]) for additional current. An important note in contrast with other prior work is that our target phone was not modified or opened in any way. That is, the effects reported in this paper have been generated using a non-modified commercial-off-the-shelf device. Table 1. Estimated cost of the equipment used in the experiments. The authors used devices available in their lab. However, cheaper versions can be used, which would result in a total cost around 398 USD (350 USD for a function generator and 30 USD for a camera).
Item
Cost (USD)
3. Approach
Function Generator RF Amplifier Copper Loop Camera/Phone
3,200 13 5 200
3.1. Face Image Samples
Total
3,418
The original (non-attack) face images were samples from the publicly available Multiple Biometric Grand Challenge (MBGC) Version 2 Dataset3 . These photos representing 50 unique identities were displayed on a MacBook Pro laptop screen and recaptured by the tested phone camera, as presented in Fig. 1. We chose this face image re-capturing approach, rather than collecting data with human subjects, to introduce the same physical noise in all test scenarios independent of face expression and differences in presentations, and to make similar tests easy to be replicated in other labs. The fact of photographing the already-captured faces is not important from the PAD point of view, since we are not assessing the PAD performance. Further, both the clean and attack samples were recaptured using the MacBook Pro display to eliminate any screen specific artifacts biasing one dataset.
3.2. Hardware The experiments in this paper focused on a camera installed in Samsung A26 phones, as the target for all attacks. While there are four cameras on the phone, three rear and one front-facing camera, the focus of the attacks was on the front-facing camera as it is the primary facial recognition camera [27]. Using the front facing camera, face pictures were presented to the camera under a static attack scenario (described below in Sec. 3.3) using IEMI to create the effects. This was accomplished by connecting an Arbitrary Function Generator (AFG, model Tektronix AFG31000 Series [31]) to a copper coil (24 AWG 9cm diameter, sin3 https : / / www . nist . gov / programs - projects / multiple-biometric-grand-challenge-mbgc
3.3. Attack Scenario To determine the static attack scenario, a set of experiments were performed to establish qualitative negative effects on the cameras ability to discern new faces and the overall maximization of camera distortion. The AFG baseline generator is capable of generating basic continuous functions, Amplitude/Frequency modulation (AM/FM), frequency sweeps, and bursts. Many of these capabilities were explored for a maximum negative effect on the camera, though this work specifically reports the effects of a single FM attack. The FM was experimentally varied across multiple carrier and modulation shapes, in addition to actual carrier and modulation frequencies. For the Samsung A26 phone, FM using a square carrier at 11.465 MHz with a triangle modulation at 190 kHz created noticeable distortions in captured images. The distortions were vertical lines with color changing properties, as seen in Fig. 2c. In addition, the vertical line width and horizontal scrolling of the lines varied with modulation frequency ±1 kHz. The overall attack aimed to reduce the obvious nature of most adversarial attacks while maximizing attack success. The vertical lines present at the specific frequency modulation represent an often successful attack, yet are subtle to human observers.
3.4. Face Matchers Selected for Experiments All image pairs were compared using six open-source face recognition models (VGG-Face [6], SFace [35], GhostFaceNet [2], two InsightFace models (buffalo l and antelopev2) [12], and DINOv3-based approach [19]) and one commercial face recognition method (VeriLook [21]), all
Table 2. Face Recognition Models Selected for Experiments.
Model
Year
Loss
Backbone/ Training Dataset
VGG-Face
2015
SFace
2021
Softmax Triplet Loss Sigmoid Hypersphere
VGG-16/ VGG-Face ResNet-50/ CASIAWebFace
GhostFace Net
2022
ArcFace
buffalo l
2023
ArcFace
antelopev2 VeriLook DINOv3
2024 2024 2025
ArcFace Proprietary Selfsupervised
Ghost Modules/ MS1MV3 ResNet-50/ MS1MV3 ViT/Glint360K Proprietary ViT/LVD1689M
developed in the last decade. The methods represent diverse architectures and training paradigms, providing comprehensive evaluation across face recognition technology. We selected VGG-Face because it is based on the VGG16 architecture adapted for facial recognition, trained on 2.6 million images. While not as deep as more recent architectures, its widespread deployment and documentation make it a valuable baseline for attack evaluation. The model uses Euclidean distance for face matching and has been extensively studied in adversarial robustness literature. VGGFace uses softmax loss for initial classification and triplet loss for fine-tuning. SFace uses a ResNet-50 backbone and addresses classimbalance challenges by optimizing face embeddings on a unit hypersphere, ensuring better generalization across varying facial attributes. Considering smaller test datasets, SFace demonstrates better performance over models such as VGG-Face. SFace uses a sigmoid-constrained hypersphere loss parameter, which does leverage angular margin but in a different way than ArcFace. GhostFaceNet employs “Ghost Modules,” which are a mobile-optimized architecture and uses ArcFace (additive angular margin) for its loss function. First introduced in GhostFaceNet, Ghost Modules still perform convolution operations but at significantly less FLOPS (Floating Operations per Second). Trained on MS1MV3, it achieves competitive accuracy to other models with significantly reduced parameters and computational cost. Considering increased popularity of edge processing for FR models, GhostFaceNet is an important model to be considered in comparisons. The buffalo l and antelopev2 are state-of-the-art models from the InsightFace framework [12]. The buffalo l method uses ResNet-50 trained on 5.2M refined images, while an-
telopev2 employs a Vision Transformer architecture trained on Glint360K (17M images, 360K identities) – the largest face domain training set among evaluated models. These models represent current industry best practices and provide insight into attack transferability to modern recognition systems. Both buffalo l and antelopev2 use ArcFace for their loss function. DINOv3 is a state-of-the-art and the latest selfsupervised, foundational, ViT-based model from Meta. The model selected for this work specifically uses dinov3-vits16-pretrain-lvd1689m weights (updated August 2025, [20]) obtained in training the ViT on approximately 1.6 billion images from LVD-1689m dataset, benefiting from a self-supervised (student-teacher distillation from larger model) loss. This diversity in distance metrics and loss functions allows for evaluation of attack effectiveness across different embedding space geometries. Results are reported for each model with respect to their original loss function. These open-source models cover a decade of facial recognition advancement and provide a range of backbones, training data, and training paradigms sufficient to make general conclusions. Diverging from the public models, VeriLook is a commercial software implementing proprietary algorithms and thus offering less information for evaluation. It was selected for this work since it represents a state-of-the-art commercial facial recognition technology reasonably well: (a) it follows ISO/IEC 30107-3 Level 2 presentation attack detection recommendations, and (b) has consistently ranked as top performer in NIST’s Face Recognition Technology Evaluation (FRTE) evaluations [23].
3.5. Modeling of the IEMI Attacks To narrow possible frequencies and modulation schemes, a simple attack modeling approach was developed. The modeling algorithm establishes a baseline imaging array, IEMI parameters, and video frame rate. The method computes the IEMI on array and frames per second (fps). The IEMI parameters are independently computed to overlay the image. When the sinusoid matches the same time step as the IEMI, an 8-bit discretized intensity is computed to overlay the attack effect, as shown in Fig. 2d. Modeled affects were optimized for a fixed FPA of 4208 × 3120 pixels for the Samsung A26 phone (SK Hynix Hi-1339 FPA [32]). A standard grid search of carrier frequency, amplitude, bar angle, and frequency modulation specifications was run to determine optimal disruption parameters. While certain frequencies may return equally or higher attack success, measured as increased cosine similarity between representations of clean and attack samples, other physical design constraints like hardware induction capability also drive success and were not modeled. Since proper modeling of the
full attack chain would require more complex setup of the EMI effects on the analog circuity (specific for each FPA and readout circuit), we decided to omit the portion in line with traditional black box attacks, which is the focus of this paper. Therefore, the modeled parameters in the results section match the physical attack parameters: 11.465MHz carrier signal, 2Vpp (Volts peak-to-peak), and frequency modulated wave at 190kHz. It should also be noted the modeling is not intended to be an optimized adversarial attack. There are no machine learning models included in the modeling script. The goal is to simply generate images that have a level of qualitative disruption to provide a narrowed focus for the real-world physical attacks.
3.6. Data Collection Examples of original, clean, physically attacked and modeled attack images are shown in Fig. 2. To collect clean samples (Fig. 2b), face images representing 50 identities were displayed on the laptop screen and re-captured by the Samsung phone camera in a form of 8-second video clips (with K = 240 frames per clip). To capture attacked images (Fig. 2c), the AFG was turned on with the appropriate FM settings and connected to a copper loop. The 9 cm, single turn loop was held between 3 cm and directly on the phone, parallel to the screen and where the camera was centered in the loop. Next the same original images of the 50 identities were displayed on the laptop screen, presented to the phone at the same distance (but now with the IEMI attack active), and 8-second (= 240-frame) video clips were captured for that setup. Finally, the modeled attack samples (Fig. 2d) were generated as described in Sec. 3.5 for the same set of original face images representing the same 50 identities. We chose not to collect attack samples from human subjects, and instead imitating the clean samples as recaptures from a laptop screen. The main reason is better reproducibility of such a testing protocol, along with higher simplicity of non-human subject research. The results (see ”FNMR-C” rows in Tab. 3 through 5) justify this decision: testing with humans would not further prove success or failure, as the models had already low False Non-Match Rate (FNMR) values (with tight standard deviation calculated for multiple runs) on clean data captures for all baselines. In other words, while the bonafide sample is certainly a dependent variable for testing, our results show that it is less important once the models establish a reasonable FNMR.
3.7. Physical Safety Limits While we did not use human subjects during experiments, we made an effort to ensure that this approach is suitable for real world deployments. The Federal Communications Committee (FCC) outlines safe exposure limits
(a)
(b)
(c)
(d)
Figure 2. Example test images in 2x2 grid: (a) original, (b) clean, (c) physical RF attack, (d) digital RF-attack model.
for RF testing [7]. Based on the measured values in Sec. 4, human operators from the center of the copper loop should be no closer than 1.6 feet for occupational works and 2.1 feet away for the general population. These distances are also time-dependent averages, where occupational workers are averaged over six minutes and general population over 30 minutes. Based on our experimental setup and attack time scale, we determine this to still be an acceptable setup for real world attack applications, especially considering additional mitigation that can be implemented (RF shielding, different antenna design, remote control of attack hardware). In addition to human safety distances, the laptop used during experimentation was outside 1.6 feet radius and
{n : FNMRn,attack > FNMRn,clean } , N where n = 1, . . . , N , and | · | denotes the number of elements in a set. In our calculations N=50. To assess the statistical significance of the differences between PAS point estimators, we randomly sampled 120 frames 10 times from the 240 available frames and provide both mean and standard deviation values over these 10 runs. The overall FNMRclean and FNMRattack are computed using 50% (i.e., 120) randomly picked frames from all experiment 8-second clips (i.e., 50 identities × 240 frames = 12,000 data points in total). Again, to assess the statistical significance of the differences between FNMR values, we repeated this sampling (with replacement) 10 times, and report mean and standard deviation of the FNMR values. Finally, the ESR (Evasion Success Rate) computes how frequently an attacked identity is accepted as a new identity, under the appropriate FMR level.
buf fal o
Ve riL o
DI NO
v3
ok
G Fac host eN et
FNMRclean 5.2 6.1 (± std) ±2.7 ±2.8 FNMRattack 7.58 8.12 (± std) ±19.8 ±20.1
6.0 ±3.5 8.4 ±19.9
0.0 ±0 0.0 ±0.0
0.0 ±0.0 0.0 ±0.0
0.0 ±0.0 22.0 ±0.0
0.66 ±4.3 100.0 ±0.0
PAS (± std) ESR
58.0 ±15.4 0.0
0.0 ±0.0 0.0
0.0 ±0.0 0.0
22.0 ±0.0 2.0
96.0 ±0.0 0.0
Metric
56.0 56.0 ±14.9 ±14.9 14.0 0.0
G Fac host eN et
buf fal ol
ant elo pev 2
DI
FNMRclean 7.2 7.2 (± std) ±2.1 ±2.5 FNMRattack 7.3 7.9 (± std) ±19.6 ±17.8
7.6 ±2.5 7.1 ±17.2
0.0 ±0.0 0.0 ±0.0
0.0 ±0.0 0.0 ±0.0
0.06 ±0.31 98.3 ±10.7
PAS (± std) ESR
54.0 ±14.9 54.0
0.0 ±0.0 0.0
0.0 ±0.0 0.0
86.0 ±0.0 0.0
Metric
52.0 54.0 ±14.6 ±14.9 30.0 54.0
NO
v3
SF ace
Table 4. Same as in Tab. 3, except that FMR=1% VG GFac e
ant elo pev 2
DI
6.2 ±1.8 7.1 ±17.1
0.0 ±0.0 0.0 ±0.0
0.0 ±0.0 0.0 ±0.0
0.03 ±0.19 73.2 ±37.2
52.0 54.0 ±14.6 ±14.8 96.0 88.0
54.0 ±14.8 88.0
0.0 ±0.0 0.0
0.0 ±0.0 0.0
40.0 ±0.0 0.0
PAS (± std) ESR
NO
v3
buf fal o
FNMRclean 3.9 6.1 (± std) ±1.5 ±3.1 FNMRattack 6.4 7.3 (± std) ±16.4 ±17.6
Metric
l
G Fac host eN et
Table 5. Same as in Tab. 3, except that FMR=5% SF ace
Since we do not assess the presentation attack detection in this work, and rather we evaluate the matching performance deterioration under the RF attacks, we are not using ISO/IEC 30107 PAD-specific metrics such as APCER and BPCER [14]. Instead, for evaluation of the attack success, we report False Non-Match Rate (FNMR) at several defined False Match Rate (FMR) values: 0.1%, 1% and 5%, and compare the FNMR values across two scenarios (when face recognition methods are fed with clean images and physical attack images). Note an exception for VeriLook, as the commercial software does not go above FMR=0.1% (softwaredefined hard limit), therefore it is only evaluated at a single threshold. First, to set the appropriate acceptance thresholds associated with FMR={0.1%,1%,5%}, we generated N (N − 1)/2 = 1, 225 impostor comparisons per model (using either Euclidean distance or cosine similarity, as appropriate) using original images from the MBGCv2 dataset representing N = 50 unique identities used in this study. Next, for each 8-second video clip we calculate subjectlevel FNMRn , by generating all possible genuine scores for that subject n (except for symmetric comparisons, thus calculating K(K − 1)/2 genuine comparison scores, where K is the number of available same-clip frames), and applying acceptance thresholds appropriate for the assumed FMR levels. Then, we define attack success for subject n if FNMRn,clean < FNMRn,attack holds true. We calculate the overall Physical Attack Success (PAS) as the rate of the number of subjects for whom the attack was successful, namely:
SF ace
3.8. Performance Metrics
l a nt elo pev 2
VG GFac e
Table 3. Results (in %) for the acceptance threshold at FMR=0.1%.
VG GFac e
had no adverse IEMI affects.
PAS =
4. Results and Discussion 4.1. Are the FM attacks successful? And if so, why? The performance results are presented in Tables 3-5, from which we can conclude that using IEMI to attack facial recognition systems is an effective method. The presented approach had varying levels of success across FMR values and models. While multiple frequencies and FM settings resulted in successful perturbations, the settings reported in this paper point to what in the optical and processing train was attacked. The front facing camera on the Samsung A26 has a sampled resolution of 1920 × 1080 pixels (4208 × 3120 pixels on the FPA) and records at 30 fps. The general starting point for center point frequencies that could cause disruption then is 62.208 MHz, determined by multiplying all 1920 ∗ 1080 ∗ 30 together.
Since imaging integration time can affect readout speeds, the frequency is a starting point and our reported carrier frequency of 11.465 MHz is not a direct harmonic. The MHz interference impacts the pixel clock timing, which translates to the vertical bars seen in Fig. 2c. The vertical lines appear to adversely affect the early-layers convolutional filters. The modulation adds another aspect. Utilizing a frequency modulated triangle wave at 190 kHz, the vertical bars now sweep and vibrate across the image. This aliasing effect is likely due to disrupted timing of the Horizontal Timing Control (HTC) within the readout circuit. The 11.465 MHz affect can be isolated without modulation to see a static set of vertical bars. Conversely, the FM can be isolated by changing the carrier frequency to a minimal interference and still observing the HTC disruption. To understand why the attack works at a fundamental level, Maxwell’s Law is the most appropriate explainability tool. According to Maxwell’s Law, the time-varying current injected into the copper loop generates both electric and magnetic fields. In the near-field region of our loop, the magnetic component is expected to be the primary vector for induction. During testing the loop orientation was changed between parallel and perpendicular with respect to the phone but the reported results focus solely on parallel experiments. Results are focused on parallel experiments since the electromagnetic field is strongest when the coil is parallel to the phone. Measuring the center of the loop provided a magnetic field of approximately 175 mGauss (mG) ±15 mG and an electric field strength of 192 Volts/meter (V/m) ±15 V/m. For comparison, a generic household hairdryer can produce 30-50 V/m of electric field and between 100-700 mG of magnetic field, but our device produces these values at higher, critical interference frequencies [10]. These values and orientations are important to understand which field is producing the dominant effect for reproducibility and transferability.
4.2. Generalization Across Methods The results also suggest that the attack generalizes across backbones and loss functions, with the exception of ArcFace or angular loss. As evident by the models utilizing ArcFace specifically, they are completely resilient to the attack. Conversely, a state-of-the-art ViT-based foundational model (included into DINOv3 suite), was the most susceptible to the attack in terms of FNMR. We posit the loss function specificity is due to the attack structure, where ArcFace is most discriminatory against subtle changes in identities. Models trained with other methods such as cross-entropy loss, triplet loss, and self-supervised (with student-teacher distillation) offer a mix of older approaches and new approaches meant for generalization. The partial exception to this observation is GhostFaceNet, which does use ArcFace loss. The major different between GhostFaceNet and
the other ArcFace loss models is their respective learning capacity. GhostFaceNet is meant for edge processing and only possess 0.82M parameters, whereas buffalo l has 25M and antelopev2 has 65M parameters. Therefore, while the loss function is working hard to repel the attack in GhostFaceNet, the tradeoff in increased performance appears to be attack resistance. While we do not have the same level of inspection for VeriLook compared to the other open source models, it was still vulnerable to the attack. Interestingly, when VeriLook was unable to correctly match an identity for a given attack video, the model failed for all frames in the video sequence, which is why FNMRattack and PAS match. Matching FNMRattack and PAS was unique to VeriLook. The ESR (Evasion Success Rate) was quite successful across VGG-Face, SFace, and GhostFaceNet. VGG-Face was the only model that showed non-zero ESR values across all FMR levels and had an incredible 96% success rate at FMR=5%. A visual of GhostFaceNet embeddings is shown in Fig. 4a-4b. The blue circles (clean images) and red X’s (attacked images) are often shown close together but further inspection shows the attacks move one identity close to another for ESR.
4.3. Generalization Across Hardware Existing literature has shown physical attacks generalize across similar cameras or sensors (e.g., resolution, readout frequency, manufacturer [16, 18]). Due to testing precedent, we hypothesize the attack generalizes to other smartphones or cameras using the Samsung Galaxy A26’s 13MP Hynix family CMOS. The Hynix CMOS is found in multiple Samsung Galaxy series smartphones [11].
4.4. Frequency Analysis In addition to examining the FNMR and PAS, we analyzed the attacks via 2D-FFT (Fast Fourier Transform). The images shown in Fig. 3a-3b visually demonstrate how the modeled images are ideal attacks and create uniform frequencies over the existing clean image. These results demonstrate where the modeled effect can be global in the image. Fig. 3b shows a rather smooth frequency amplitude spectrum, though the attack has increased the overall image intensity.
4.5. Model Embedding Space Analysis Another way to visualize the success the of the attack is through UMAP (Uniform Manifold Approximation and Projection) plots, using GhostFaceNet at FMR=5.0%. Fig. 4a shows the five identities with the largest differences in euclidean distance or cosine similarity, measured between the clean and attacked data. The purple dots are clean image identities and the attacked identities are orange dots. The UMAP tracks the embedding trajectory of the five identities with the largest attack success. To further illustrate why this
(a)
(b)
(c)
UMAP 2
GhostFaceNet: Top 5 Attacked Identities -> Nearest Neighbors
Figure 3. FFT amplitude spectra calculated for the same identity as in Fig. 2: (a) clean MBGCv2 sample, (b) physically attacked sample, and (c) modeled attack (as described in Sec. 3.5).
untargeted attack can be quite successful, Fig. 4a shows those same five identities and their new nearest neighbors within the clean image dataset. As it can be seen, all attacked images have “migrated” from their original identity to new identities and have been accepted as different identities by satisfying the GhostFaceNet FMR-level-defined acceptance threshold. This means the attack not only changed the original identity but, in an untargeted attack, pushed the image close enough to a different identity to then be successfully classified. This untargeted attack success is a subset of the PAS in Tables 3-5. We additionally visualize this affect in Fig. 4b, where identity #04267d146 is attacked and then successfully becomes identity #04225d316 in the MBGCv2 dataset.
5. Conclusions This work presents, to our knowledge, the first intentional electromagnetic interference (IEMI) attack on machine learning-based face recognition systems. Further, this work examines the effects of IEMI on CMOS detectors. The IEMI attack was successful in a black box setting across five models (out of seven methods used in evaluations). The attacks success across multiple backbones and loss functions, demonstrating a clear vulnerability in existing methods. The best defense is to use a model with ArcFace as its loss function. While we tested a commercial phone without any modifications, further investigation is required to determine breadth of hardware vulnerability. We offer source codes of the attack modeling technique, as well as clean and under-attack face videos with this paper to facilitate reproducibility and future research in this area. Finally, the results presented in this paper may stimulate adding the RF-based attacks to the portfolio of presentation attacks in developments of future versions of recommendation, such as ISO/IEC 30107 [14] or FIDO Alliance Face Verification Certification Program [8].
UMAP 1 (a)
04267d146 Original
04267d146 Clean
04267d146 Attacked
04225d316 Clean
(b)
Figure 4. (a) UMAP projection of the representations of top 5 attacked identities within the GhostFaceNet embedding space (at FMR=5.0%), and (b) the example illustration of successful untargeted attack. Remaining plots for all models are provided in Supplementary Materials.
6. Acknowledgments This material is based upon work partially supported by the OUSW/R&E (Office of the Under Secretary of War, Research and Engineering), National Defense Education Program (NDEP) SMART Scholarship Program, and Naval Surface Warfare Center (NSWC), Crane Division Ph.D. Fellowship Program. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the DoW or U.S. Navy.
References [1] N. Akhtar and A. Mian. Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 6:14410–14430, 2018. [2] M. Alansari, O. Abdul Hay, S. Javed, A. Shoufan, Y. Zweiri, and N. Werghi. Ghostfacenets: Lightweight face recognition model from cheap operations. IEEE Access, 11:43447– 43461, 2023. [3] Amazon.com. 1-930MHz 2.0W professional RF power amplifier module. https : / / www . amazon . com / dp / B09HX3C43K, 2026. Accessed: 2026-04-18. [4] A. Antil and C. Dhiman. Unmasking deception: A comprehensive survey on the evolution of face anti-spoofing methods. Neurocomputing, 617:128992, 2025. [5] A. Bochkovskiy, C.-Y. Wang, and H.-Y. M. Liao. Yolov4: Optimal speed and accuracy of object detection. arXiv preprint arXiv:2004.10934, 2020. [6] Q. Cao, L. Shen, W. Xie, O. M. Parkhi, and A. Zisserman. Vggface2: A dataset for recognising faces across pose and age. In 2018 13th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2018), 2018. [7] Federal Communications Commission. 47 CFR § 1.1310 Radiofrequency radiation exposure limits. Code of Federal Regulations, Title 47, Volume 1, 2011. Accessed: April 17, 2026. [8] FIDO Alliance. Face verification certification. https:// fidoalliance.org/certification/identityverification/face-verification/, 2026. [9] V. Goiffon. Radiation effects on cmos active pixel image sensors. Presented at IEEE Nucl. Space Radiat. Effects Conf., 2023. [10] GreenFacts. Magnetic fields generated by domestic appliances, 2004. Based on the IARC (2002) and California EMF Program (2002) reports. [11] GSMArena Team. Samsung Galaxy A26 review: Camera. GSMArena, Mar. 2025. Accessed: 2026-07-09. [12] J. Guo, J. Deng, A. Lattas, and S. Zafeiriou. Insightface: 2d and 3d face analysis project. https://github.com/ deepinsight/insightface, 2021. [13] K. He, X. Zhang, S. Ren, and J. Sun. Deep residual learning for image recognition. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 770–778, 2016. [14] Information technology – biometric presentation attack detection – part 3: Testing and reporting. Standard ISO/IEC 30107-3:2023, International Organization for Standardization, Geneva, CH, 2023. [15] X. Ji, Y. Cheng, Y. Cheng, K. Wang, and W. Xu. Poltergeist: Acoustic adversarial machine learning against cameras and computer vision. In 2021 IEEE Symposium on Security and Privacy (SP), pages 101–118. IEEE, 2021. [16] S. Köhler, G. Lovisotto, S. Birnbach, R. Baker, and I. Martinovic. They see me rollin’: Inherent vulnerability of the rolling shutter in cmos image sensors. In Proceedings of the 37th Annual Computer Security Applications Conference, ACSAC ’21, pages 399–413, New York, NY, USA, 2021. Association for Computing Machinery.
[17] R. Leyva. Attacks against face recognition systems: A stateof-the-art review. Technical report, The Alan Turing Institute, 2023. [18] Z. Liu, F. Lin, Z. Ba, L. Lu, and K. Ren. Magshadow: Physical adversarial example attacks via electromagnetic injection. IEEE Transactions on Dependable and Secure Computing, 22(4):3307, -07 2025. [19] Meta AI. DINOv3: Foundation models producing excellent dense features. arXiv preprint arXiv:2508.10104, 2025. [20] Meta AI. Dinov3 ViT-L/16 pre-trained on LVD-1689M. https://huggingface.co/facebook/dinov3vitl16- pretrain- lvd1689m, 2025. Hugging Face Model Hub. [21] Neurotechnology. VeriLook SDK: Face Identification Technology. Neurotechnology, Vilnius, Lithuania, 2024. Available at https : / / www . neurotechnology . com / verilook.html. [22] D.-L. Nguyen, S. S. Arora, Y. Wu, and H. Yang. Adversarial light projection attacks on face recognition systems: A feasibility study. In 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pages 3548–3556. IEEE, 2020. [23] NIST. Face Technology Evaluations – FRTE/FATE. https://www.nist.gov/programs- projects/ face - technology - evaluations - frtefate, 2026. Accessed: 2026-04-27. [24] R. Ramachandra and C. Busch. Presentation attack detection methods for face recognition systems: A comprehensive survey. ACM Computing Surveys, 50(1):1–37, Mar. 2017. [25] J. Redmon and A. Farhadi. YOLO v3: An incremental improvement. arXiv preprint arXiv:1804.02767, 2018. [26] Y. Ren, Q. Jiang, C. Yan, X. Ji, and W. Xu. Ghostshot: Manipulating the image of ccd cameras with electromagnetic interference. In Proceedings of the 32nd Network and Distributed System Security (NDSS) Symposium, San Diego, CA, USA, February 2025. Internet Society. [27] Samsung Electronics. Galaxy A26 5g. https://www. samsung . com / us / smartphones / galaxy - a26 5g/, 2025. Accessed: 2026-04-18. [28] A. Sayles, A. Hooda, M. Gupta, R. Chatterjee, and E. Fernandes. Invisible perturbations: Physical adversarial examples exploiting the rolling shutter effect. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 14666–14675, 2021. [29] M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter. Accessorize to a crime. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, page 1528, 2025-10-24 2016. [30] C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna. Rethinking the inception architecture for computer vision. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 2818–2826, 2016. [31] Tektronix, Inc. Afg31000 series arbitrary function generator. https://www.tek.com/en/products/signalgenerators/arbitrary-function-generator/ afg31000, 2026. Accessed: 2026-04-18. [32] Wikipedia contributors. Samsung Galaxy A26 5G, 2026.
[33] Z. Yu, Y. Qin, X. Li, C. Zhao, Z. Lei, and G. Zhao. Deep learning for face anti-spoofing: A survey. IEEE Transactions on Pattern Analysis and Machine Intelligence, page 1–22, 2022. [34] Y. Zhang, L. Wang, S. Chen, and J. Liu. Rainbow artifacts from electromagnetic signal injection attacks on image sensors. arXiv preprint arXiv:2507.07773, 2025. [35] Y. Zhong, W. Deng, J. Hu, D. Zhao, X.-S. Li, and H. Wen. Sface: Sigmoid-constrained hypersphere loss for robust face recognition. IEEE Transactions on Image Processing, 30:2587–2598, 2021.
Intentional Electromagnetic Interference Attacks on Facial Recognition Supplementary Materials
1. Test Parameters Table 1. Experimental Reference Table Baseband Frequency
Voltage
Modulation Type
Modulation Freq.
11.455 MHz
2 Vpp
FM, Triangle
190 kHz
2. Model Embedding Space Analysis UMAP projection of the representations of top 5 attacked identities for each model tested at FMR=5.0% 1a-6b.
UMAP 2
VGG-Face: Top 5 Attacked Identities -> Nearest Neighbors
UMAP 1 (a) Attack trajectory for the VGG-Face model.
04297d292 Original
04297d292 Clean
04297d292 Attacked
04201d396 Clean
(b) Identity mapping for the VGG-Face model.
Figure 1. Evaluation of IEMI hardware attacks: The physical attack trajectory (top) and the respective identity transition (bottom) for VGG-Face.
UMAP 2
SFace: Top 5 Attacked Identities -> Nearest Neighbors
UMAP 1 (a) Attack trajectory for the SFace model.
04288d265 Original
04288d265 Clean
04288d265 Attacked
02463d566 Clean
(b) Identity mapping for the SFace model.
Figure 2. Evaluation of IEMI hardware attacks: SFace (continued).
UMAP 2
GhostFaceNet: Top 5 Attacked Identities -> Nearest Neighbors
UMAP 1 (a) Attack trajectory for the GhostFaceNet model.
04267d146 Original
04267d146 Clean
04267d146 Attacked
04225d316 Clean
(b) Identity mapping for the GhostFaceNet model.
Figure 3. Evaluation of IEMI hardware attacks: GhostFaceNet (continued).
UMAP 2
buffalo_l: Top 5 Attacked Identities -> Nearest Neighbors
UMAP 1 (a) buffalo l: Attack Trajectory
04297d292 Original
04297d292 Clean
04297d292 Attacked
04202d459 Clean
(b) buffalo l: Identity Mapping
Figure 4. Evaluation of IEMI hardware attacks: buffalo l (continued).
UMAP 2
antelopev2: Top 5 Attacked Identities -> Nearest Neighbors
UMAP 1 (a) antelopev2: Attack Trajectory
04459d71 Original
04459d71 Clean
04459d71 Attacked
04203d470 Clean
(b) antelopev2: Identity Mapping
Figure 5. Evaluation of IEMI hardware attacks: antelopev2 (continued).
UMAP 2
UMAP 1 (a) DINOv3: Attack Trajectory
04427d282 Original
04427d282 Clean
04427d282 Attacked
02463d566 Clean
(b) DINOv3: Identity Mapping
Figure 6. Evaluation of IEMI hardware attacks: DINOv3 (continued).