提出新框架,统一检测实体和数字人脸欺骗攻击。
Spoofing-aware Prompt Learning for Unified Physical-Digital Facial Attack Detection
- 分离物理与数字攻击的提示学习路径,避免优化冲突。
- 在UniAttackDataPlus数据集上显著提升联合检测性能。
- 适合需要强鲁棒性的人脸识别安全系统开发者。
真实世界的人脸识别系统易受实体展示攻击(PAs)和数字伪造攻击(DFs)威胁。本文旨在通过统一的物理-数字防御框架实现生物特征数据的全面保护。现有方法多采用带正则约束的CLIP模型以增强跨任务泛化能力,但同一提示空间下物理与数字攻击检测存在优化方向冲突。为此,我们提出一种欺骗感知提示学习框架(SPL-UAD),在提示空间中解耦物理与数字攻击的优化分支。具体地,构建可学习的并行提示分支,并引入自适应欺骗上下文提示生成机制,实现对两类攻击优化的独立控制。此外,设计了线索感知增强策略,利用双提示机制生成具有挑战性的样本挖掘任务,显著提升模型对未见攻击类型的鲁棒性。在大规模UniAttackDataPlus数据集上的大量实验表明,该方法在统一攻击检测任务中取得显著性能提升。
原文摘要 · Abstract (English)
Real-world face recognition systems are vulnerable to both physical presentation attacks (PAs) and digital forgery attacks (DFs). We aim to achieve comprehensive protection of biometric data by implementing a unified physical-digital defense framework with advanced detection. Existing approaches primarily employ CLIP with regularization constraints to enhance model generalization across both tasks. However, these methods suffer from conflicting optimization directions between physical and digital attack detection under same category prompt spaces. To overcome this limitation, we propose a Spoofing-aware Prompt Learning for Unified Attack Detection (SPL-UAD) framework, which decouples optimization branches for physical and digital attacks in the prompt space. Specifically, we construct a learnable parallel prompt branch enhanced with adaptive Spoofing Context Prompt Generation, enabling independent control of optimization for each attack type. Furthermore, we design a Cues-awareness Augmentation that leverages the dual-prompt mechanism to generate challenging sample mining tasks on data, significantly enhancing the model's robustness against unseen attack types. Extensive experiments on the large-scale UniAttackDataPlus dataset demonstrate that the proposed method achieves significant performance improvements in unified attack detection tasks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。