提出新损失函数,让人脸识别模型更抗人脸合成攻击
MorphGuard: Morph Specific Margin Loss for Enhancing Robustness to Face Morphing Attacks
- 采用双分支分类策略,解决合成人脸标签模糊问题
- 在公开数据集上显著提升对合成攻击的防御能力
- 可无缝接入现有识别系统,适合安全认证场景
人脸识别因深度学习技术进步而广泛应用,但也面临人脸合成等呈现攻击威胁,可能导致身份冒用。本文提出一种新方法,通过引入双分支分类策略,解决合成人脸标签不明确的问题,使模型能有效利用合成图像训练,增强区分真实与合成样本的能力。该方法在公开基准上验证有效,且可通用集成至现有训练流程,适用于各类基于分类的人脸识别系统。
原文摘要 · Abstract (English)
Face recognition has evolved significantly with the advancement of deep learning techniques, enabling its widespread adoption in various applications requiring secure authentication. However, this progress has also increased its exposure to presentation attacks, including face morphing, which poses a serious security threat by allowing one identity to impersonate another. Therefore, modern face recognition systems must be robust against such attacks. In this work, we propose a novel approach for training deep networks for face recognition with enhanced robustness to face morphing attacks. Our method modifies the classification task by introducing a dual-branch classification strategy that effectively handles the ambiguity in the labeling of face morphs. This adaptation allows the model to incorporate morph images into the training process, improving its ability to distinguish them from bona fide samples. Our strategy has been validated on public benchmarks, demonstrating its effectiveness in enhancing robustness against face morphing attacks. Furthermore, our approach is universally applicable and can be integrated into existing face recognition training pipelines to improve classification-based recognition methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。