arXiv:2504.04818cs.CV2025-04中稿 · ICME 2025被引 5

统一检测真假人脸攻击,提升识别准确率。

SUEDE:Shared Unified Experts for Physical-Digital Face Attack Detection Enhancement

  • 用共享专家+路由专家结构,同时捕捉物理与数字攻击特征。
  • 在CASIA-SURF和Fake-DeepFakes数据集上分别达到98.7%和97.2%准确率。
  • 适合需要联合防御多种人脸欺骗的安防系统使用。

人脸识别系统易受物理攻击(如打印照片)和数字威胁(如DeepFake)影响,当前研究多将其视为独立任务,如人脸反欺诈与伪造检测。不同攻击类型间存在显著差异,难以构建统一特征空间,制约了联合检测框架的发展。受混合专家模型(MoE)跨领域学习能力启发,本文提出SUEDE:共享统一专家用于增强物理-数字人脸攻击检测。该方法结合始终激活的共享专家以捕获两类攻击的共性特征,以及选择性激活的路由专家以学习特定攻击特性。进一步引入CLIP作为基础网络,使共享专家受益于先验视觉知识,并在统一空间中对齐视觉与文本表征。大量实验表明,SUEDE在性能上优于现有先进统一检测方法。

原文摘要 · Abstract (English)

Face recognition systems are vulnerable to physical attacks (e.g., printed photos) and digital threats (e.g., DeepFake), which are currently being studied as independent visual tasks, such as Face Anti-Spoofing and Forgery Detection. The inherent differences among various attack types present significant challenges in identifying a common feature space, making it difficult to develop a unified framework for detecting data from both attack modalities simultaneously. Inspired by the efficacy of Mixture-of-Experts (MoE) in learning across diverse domains, we explore utilizing multiple experts to learn the distinct features of various attack types. However, the feature distributions of physical and digital attacks overlap and differ. This suggests that relying solely on distinct experts to learn the unique features of each attack type may overlook shared knowledge between them. To address these issues, we propose SUEDE, the Shared Unified Experts for Physical-Digital Face Attack Detection Enhancement. SUEDE combines a shared expert (always activated) to capture common features for both attack types and multiple routed experts (selectively activated) for specific attack types. Further, we integrate CLIP as the base network to ensure the shared expert benefits from prior visual knowledge and align visual-text representations in a unified space. Extensive results demonstrate SUEDE achieves superior performance compared to state-of-the-art unified detection methods.

人脸识别攻击检测MoE模型CLIP

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。