用大模型实现零样本人脸伪造攻击检测,无需训练即可应对未知攻击。
Are Foundation Models All You Need for Zero-shot Face Presentation Attack Detection?
- 利用基础模型直接进行零样本攻击检测,不依赖特定训练数据。
- 在SiW-Mv2数据集上超越现有最优方法,对未知2D/3D攻击检测准确率更高。
- 适合缺乏标注数据或需快速部署的实时安防场景。
尽管过去十年中人脸识别技术取得了显著进步,但其仍易受攻击呈现(AP)威胁。攻击者可轻易生成伪造内容,通过设备捕获欺骗系统,冒充授权用户获取敏感信息(如金融交易)。当前先进的深度学习攻击呈现检测(PAD)方法需大量数据训练,且在面对未见的攻击手段或数据库时性能下降,泛化能力差。为解决此问题,本文聚焦零样本PAD。首先评估基础模型在标准与挑战性场景下的有效性与泛化能力,随后提出一种简单但高效的零样本PAD框架。实验表明,该模型在复杂场景下仅需极少调整即可达到先进方法水平,其权重主要基于含真实与伪造样本的数据集优化。最优基础模型在留一法测试协议下,于包含挑战性未知2D/3D攻击的SiW-Mv2数据集上,显著优于现有最佳方法。
原文摘要 · Abstract (English)
Although face recognition systems have undergone an impressive evolution in the last decade, these technologies are vulnerable to attack presentations (AP). These attacks are mostly easy to create and, by executing them against the system's capture device, the malicious actor can impersonate an authorised subject and thus gain access to the latter's information (e.g., financial transactions). To protect facial recognition schemes against presentation attacks, state-of-the-art deep learning presentation attack detection (PAD) approaches require a large amount of data to produce reliable detection performances and even then, they decrease their performance for unknown presentation attack instruments (PAI) or database (information not seen during training), i.e. they lack generalisability. To mitigate the above problems, this paper focuses on zero-shot PAD. To do so, we first assess the effectiveness and generalisability of foundation models in established and challenging experimental scenarios and then propose a simple but effective framework for zero-shot PAD. Experimental results show that these models are able to achieve performance in difficult scenarios with minimal effort of the more advanced PAD mechanisms, whose weights were optimised mainly with training sets that included APs and bona fide presentations. The top-performing foundation model outperforms by a margin the best from the state of the art observed with the leaving-one-out protocol on the SiW-Mv2 database, which contains challenging unknown 2D and 3D attacks
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。