arXiv:2410.07988cs.CV2024-10被引 12

用潜在扩散模型从生物特征编码生成人脸变形图像,提升攻击多样性。

LADIMO: Face Morph Generation through Biometric Template Inversion with Latent Diffusion

  • 通过潜空间扩散模型逆向生物特征编码重建人脸图像
  • 单对人脸可生成无限变体,攻击成功率最高达87.3%
  • 适合研究人脸识别安全与对抗样本的开发者使用

人脸变形攻击严重威胁人脸识别系统的安全性,使合成图像能通过多个身份验证。为检测此类伪造图像,开发新型人脸变形方法以扩充训练数据集至关重要。本文提出一种基于表示层的人脸变形方法LADIMO,直接在两个面部识别嵌入(FRS latent representation)上进行变形。具体而言,我们训练一个潜空间扩散模型(Latent Diffusion Model)来逆向生物特征模板,从而从人脸识别嵌入中重构出人脸图像。后续漏洞分析表明,该方法在攻击潜力上显著优于已有的MIPGAN-II GAN基线方法。此外,结合随机化设计与身份条件机制,仅需一对原始人脸即可生成无限数量的变形攻击图像。我们发现每种变形变体具有独立的攻击成功率,通过简单重采样策略可最大化整体攻击效果。代码与预训练模型已公开:https://github.com/dasec/LADIMO

原文摘要 · Abstract (English)

Face morphing attacks pose a severe security threat to face recognition systems, enabling the morphed face image to be verified against multiple identities. To detect such manipulated images, the development of new face morphing methods becomes essential to increase the diversity of training datasets used for face morph detection. In this study, we present a representation-level face morphing approach, namely LADIMO, that performs morphing on two face recognition embeddings. Specifically, we train a Latent Diffusion Model to invert a biometric template - thus reconstructing the face image from an FRS latent representation. Our subsequent vulnerability analysis demonstrates the high morph attack potential in comparison to MIPGAN-II, an established GAN-based face morphing approach. Finally, we exploit the stochastic LADMIO model design in combination with our identity conditioning mechanism to create unlimited morphing attacks from a single face morph image pair. We show that each face morph variant has an individual attack success rate, enabling us to maximize the morph attack potential by applying a simple re-sampling strategy. Code and pre-trained models available here: https://github.com/dasec/LADIMO

人脸变形扩散模型安全攻防生成对抗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。