用强化学习让AI自己学会反欺骗,通用性更强且决策可解释。
Exploring Task-Solving Paradigm for Generalized Cross-Domain Face Anti-Spoofing via Reinforcement Fine-Tuning
- 通过强化微调让大模型自主探索反欺骗推理策略
- 在未知攻击类型上达到顶尖跨域泛化效果
- 无需人工标注文本,决策过程可解释
近年来新型呈现攻击频发,促使人脸识别反欺骗技术备受关注。然而现有方法多依赖训练数据模式记忆,导致对未知攻击类型泛化能力差且缺乏可解释性。本文提出一种基于强化微调的反欺骗方法,激发多模态大语言模型自主思考并学习如何解决反欺骗任务,而非单纯记忆真实特征。设计可验证的类别一致性奖励与推理一致性奖励,采用GRPO优化策略,引导模型从多角度探索推理路径以最大化预期奖励。通过迭代试错学习并保留高奖励轨迹,模型从广阔解空间中提炼出高度泛化的决策规则,有效应对跨域反欺骗任务。大量实验证明,该方法在跨域泛化性能上达到当前最优,在未见目标域的多种未知攻击类型上表现良好,且无需人工标注文本即可提供可解释的真伪判断依据。
原文摘要 · Abstract (English)
Recently the emergence of novel presentation attacks has drawn increasing attention to face anti-spoofing. However, existing methods tend to memorize data patterns from the training set, resulting in poor generalization to unknown attack types across different scenarios and limited interpretability. To address these challenges, this paper presents a reinforcement fine-tuning-based face anti-spoofing method that stimulates the capabilities of multimodal large language models to think and learn how to solve the anti-spoofing task itself, rather than relying on the memorization of authenticity patterns. We design verifiable class consistent reward and reasoning consistent reward, and employ a GRPO-based optimization strategy to guide the model in exploring reasoning policies from multiple perspectives to maximize expected rewards. As a result, through iterative trial-and-error learning while retaining only high-reward trajectories, the model distills highly generalizable decision-making rules from the extensive solution space to effectively address cross-domain face anti-spoofing tasks. Extensive experimental results demonstrate that our method achieves state-of-the-art cross-domain generalization performance. It generalizes well to diverse unknown attack types in unseen target domains while providing interpretable reasoning for its authenticity decisions without requiring labor-intensive textual annotations for training.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。