新数据集揭示弹性面具攻击对人脸识别的威胁
Introducing Nylon Face Mask Attacks: A Dataset for Evaluating Generalised Face Presentation Attack Detection
- 构建真实手机场景下尼龙面具攻击数据集
- 51281个攻击样本,4种场景测试模型泛化能力
- 验证现有防御方法在新型攻击下表现不佳
人脸识别系统广泛应用于手机认证、门禁和边境安全,但易受呈现攻击(PAs)影响。本文引入新型现实攻击工具——尼龙面具(NFMs),其弹性结构与逼真外观可高度模拟目标人脸几何特征。为模拟真实手机使用环境,使用iPhone 11 Pro采集了来自100名受试者的3,760个真实样本,以及涵盖4种不同呈现场景的51,281个尼龙面具攻击样本,涉及真人与人偶。通过五种先进呈现攻击检测(PAD)方法在该数据集上进行基准测试,结果显示各方法性能差异显著,暴露出当前技术对新型欺骗威胁泛化能力不足的问题,凸显开发更具鲁棒性防御机制的必要性。
原文摘要 · Abstract (English)
Face recognition systems are increasingly deployed across a wide range of applications, including smartphone authentication, access control, and border security. However, these systems remain vulnerable to presentation attacks (PAs), which can significantly compromise their reliability. In this work, we introduce a new dataset focused on a novel and realistic presentation attack instrument called Nylon Face Masks (NFMs), designed to simulate advanced 3D spoofing scenarios. NFMs are particularly concerning due to their elastic structure and photorealistic appearance, which enable them to closely mimic the victim's facial geometry when worn by an attacker. To reflect real-world smartphone-based usage conditions, we collected the dataset using an iPhone 11 Pro, capturing 3,760 bona fide samples from 100 subjects and 51,281 NFM attack samples across four distinct presentation scenarios involving both humans and mannequins. We benchmark the dataset using five state-of-the-art PAD methods to evaluate their robustness under unseen attack conditions. The results demonstrate significant performance variability across methods, highlighting the challenges posed by NFMs and underscoring the importance of developing PAD techniques that generalise effectively to emerging spoofing threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。