仅用真实人脸图像,学习未知欺骗提示以提升人脸识别安全。
Learning Unknown Spoof Prompts for Generalized Face Anti-Spoofing Using Only Real Face Images
- 利用视觉语言模型生成真实与潜在欺骗的文本提示
- 在九个数据集上实现顶尖跨域泛化性能
- 无需欺骗样本,适合实际部署场景
人脸识别反欺骗是保障系统安全的关键技术,但其跨场景泛化能力仍受限。本文将泛化不足归因于协变量偏移(外部数据采集差异)和语义偏移(新型攻击形态差异)。为此,提出一种仅依赖单一源域真实人脸图像来学习未知欺骗提示的新方法。通过视觉语言模型挖掘通用知识,生成真实人脸及潜在未知欺骗的文本提示,增强模型对未见目标域的适应能力。具体提出多样欺骗提示优化框架,在宽松先验空间内约束未知欺骗提示,并最大化其与真实人脸的距离;同时强制不同欺骗提示间的语义独立性,以捕捉广泛欺骗模式。在九个数据集上的实验表明,所学提示有效传递视觉语言模型的知识,实现无欺骗样本情况下对多种未知攻击类型的先进跨域泛化性能。
原文摘要 · Abstract (English)
Face anti-spoofing is a critical technology for ensuring the security of face recognition systems. However, its ability to generalize across diverse scenarios remains a significant challenge. In this paper, we attribute the limited generalization ability to two key factors: covariate shift, which arises from external data collection variations, and semantic shift, which results from substantial differences in emerging attack types. To address both challenges, we propose a novel approach for learning unknown spoof prompts, relying solely on real face images from a single source domain. Our method generates textual prompts for real faces and potential unknown spoof attacks by leveraging the general knowledge embedded in vision-language models, thereby enhancing the model's ability to generalize to unseen target domains. Specifically, we introduce a diverse spoof prompt optimization framework to learn effective prompts. This framework constrains unknown spoof prompts within a relaxed prior knowledge space while maximizing their distance from real face images. Moreover, it enforces semantic independence among different spoof prompts to capture a broad range of spoof patterns. Experimental results on nine datasets demonstrate that the learned prompts effectively transfer the knowledge of vision-language models, enabling state-of-the-art generalization ability against diverse unknown attack types across unseen target domains without using any spoof face images.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。