用现有人脸识别系统检测人脸伪造攻击,提升安全性
Find the Differences: Differential Morphing Attack Detection vs Face Recognition

- 将人脸识别系统直接用于检测人脸变形攻击
- 新阈值可将未知类型攻击的漏洞控制在上限内
- 解决正常识别与防攻击之间的性能矛盾
人脸变形攻击对人脸识别(FR)构成挑战,已有多种防御方案。本文指出,人脸识别与差分形态攻击检测(D-MAD)本质上执行相似任务,并通过对比现有FR系统与两种D-MAD方法验证了这一点。研究发现,当前使用的决策阈值导致FR系统天然易受变形攻击,这解释了其在正常图像表现与抗攻击能力间的权衡。为此,提出利用已部署的FR系统进行攻击检测,并引入新评估阈值,确保对未知类型攻击的漏洞不超过预设上限。
原文摘要 · Abstract (English)
Morphing is a challenge to face recognition (FR) for which several morphing attack detection solutions have been proposed. We argue that face recognition and differential morphing attack detection (D-MAD) in principle perform very similar tasks, which we support by comparing an FR system with two existing D-MAD approaches. We also show that currently used decision thresholds inherently lead to FR systems being vulnerable to morphing attacks and that this explains the tradeoff between performance on normal images and vulnerability to morphing attacks. We propose using FR systems that are already in place for morphing detection and introduce a new evaluation threshold that guarantees an upper limit to the vulnerability to morphing attacks - even of unknown types.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。