arXiv:2603.15050cs.CV2026-03中稿 · IWBF 2026

用频域结构残差提升单类人脸变形攻击检测能力

SRL-MAD: Structured Residual Latents for One-Class Morphing Attack Detection

  • 构建频域残差图,保留二维谱结构并学习环形投影
  • 分高低中频带建模跨带交互,识别变形痕迹
  • 仅用真实人脸训练,对未知攻击仍有效

人脸变形攻击严重威胁生物识别系统,可将多个身份融合为一张脸。现有监督式检测方法依赖标注攻击数据,泛化能力受限;因此单类攻击检测(one-class MAD)受到关注——模型仅在真实人脸样本上训练,通过识别异常来发现未见攻击。本文提出SRL-MAD,一种基于结构化残差傅里叶表示的单图像单类检测方法。从抑制图像特有频谱趋势的残差频谱图出发,采用环形结构保持傅里叶域二维组织,并以可学习环形投影替代传统方位平均。进一步引入频率先验:将频谱证据划分为低、中、高频段,学习跨段交互,增强对变形伪影的敏感度。所提取的结构化频谱特征被映射至直接评分的潜在空间,避免依赖重建误差。在FERET-Morph、FRLL-Morph和MorDIFF数据集上的大量实验表明,SRL-MAD持续优于近期单类及监督式MAD模型。结果表明,学习频率感知投影比传统方位平均更具判别力,适用于开放集下的形态攻击检测。

原文摘要 · Abstract (English)

Face morphing attacks represent a significant threat to biometric systems as they allow multiple identities to be combined into a single face. While supervised morphing attack detection (MAD) methods have shown promising performance, their reliance on attack-labeled data limits generalization to unseen morphing attacks. This has motivated increasing interest in one-class MAD, where models are trained exclusively on bona fide samples and are expected to detect unseen attacks as deviations from the normal facial structure. In this context, we introduce SRL-MAD, a one-class single-image MAD that uses structured residual Fourier representations for open-set morphing attack detection. Starting from a residual frequency map that suppresses image-specific spectral trends, we preserve the two-dimensional organization of the Fourier domain through a ring-based representation and replace azimuthal averaging with a learnable ring-wise spectral projection. To further encode domain knowledge about where morphing artifacts arise, we impose a frequency-informed inductive bias by organizing spectral evidence into low, mid, and high-frequency bands and learning cross-band interactions. These structured spectral features are mapped into a latent space designed for direct scoring, avoiding the reliance on reconstruction errors. Extensive evaluation on FERET-Morph, FRLL-Morph, and MorDIFF demonstrates that SRL-MAD consistently outperforms recent one-class and supervised MAD models. Overall, our results show that learning frequency-aware projections provides a more discriminative alternative to azimuthal spectral summarization for one-class morphing attack detection.

人脸识别攻击检测频域分析单类学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。