用无攻击训练的视觉特征检测人脸合成攻击,效果优于传统方法。
Evaluating the Effectiveness of Attack-Agnostic Features for Morphing Attack Detection
- 从纯真实数据预训练模型提取特征,不依赖攻击样本
- 线性SVM与高斯混合模型在多种攻击下准确率超现有方法
- 适用于未见过的攻击类型和打印扫描场景,适合安全系统部署
近年来,基于生成对抗网络(GANs)和扩散模型的新式人脸合成攻击日益多样化,严重威胁人脸识别系统。已有研究证明,仅在真实图像上预训练的大规模视觉模型所提取的攻击无关特征,能有效识别深度生成图像。本文进一步探究此类特征在人脸合成攻击检测(MAD)中的潜力。我们构建了监督型检测器,通过在提取特征上训练简单的二分类线性支持向量机(SVM),以及单类检测器,利用高斯混合模型(GMM)建模真实样本特征分布。方法在多种攻击类型及复杂场景下进行评估,包括对未见过攻击的泛化能力、不同源数据集适应性以及打印-扫描场景下的鲁棒性。结果表明,攻击无关特征可有效检测合成攻击,在多数场景中优于文献中的传统监督与单类检测器。同时,本文分析了各类特征表示的优劣,并讨论了未来提升模型鲁棒性与泛化能力的研究方向。
原文摘要 · Abstract (English)
Morphing attacks have diversified significantly over the past years, with new methods based on generative adversarial networks (GANs) and diffusion models posing substantial threats to face recognition systems. Recent research has demonstrated the effectiveness of features extracted from large vision models pretrained on bonafide data only (attack-agnostic features) for detecting deep generative images. Building on this, we investigate the potential of these image representations for morphing attack detection (MAD). We develop supervised detectors by training a simple binary linear SVM on the extracted features and one-class detectors by modeling the distribution of bonafide features with a Gaussian Mixture Model (GMM). Our method is evaluated across a comprehensive set of attacks and various scenarios, including generalization to unseen attacks, different source datasets, and print-scan data. Our results indicate that attack-agnostic features can effectively detect morphing attacks, outperforming traditional supervised and one-class detectors from the literature in most scenarios. Additionally, we provide insights into the strengths and limitations of each considered representation and discuss potential future research directions to further enhance the robustness and generalizability of our approach.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。