用T恤伪造人脸攻击可骗过人脸识别,新方法通过空间一致性检测有效识别。
Detection of T-shirt Presentation Attacks in Face Recognition Systems

- 结合人脸与人体检测器,分析位置关系来识别T恤攻击
- 在100种攻击工具、1608次攻击下验证了系统脆弱性
- 适合安防系统研发者和对抗攻击研究者参考
人脸识别系统常用于生物认证,但缺乏防护时易受呈现攻击。尽管已有检测方法在基准数据集上表现良好,但对新型攻击的泛化能力仍不足。本文基于TFPA数据库,使用100种不同呈现攻击工具实施了1,608次T恤攻击,并结合152次真实样本进行综合评估,证实此类攻击可严重威胁系统安全。为此,提出一种基于空间一致性的检测方法:利用先进的人脸与人体检测器,分析检测到的人脸与人体的空间位置关系,从而可靠识别出T恤攻击。
原文摘要 · Abstract (English)
Face recognition systems are often used for biometric authentication. Nevertheless, it is known that without any protective measures, face recognition systems are vulnerable to presentation attacks. To tackle this security problem, methods for detecting presentation attacks have been developed and shown good detection performance on several benchmark datasets. However, generalising presentation attack detection methods to new and novel types of attacks is an ongoing challenge. In this work, we employ 1,608 T-shirt attacks of the T-shirt Face Presentation Attack (TFPA) database using 100 unique presentation attack instruments together with 152 bona fide presentations. In a comprehensive evaluation, we show that this type of attack can compromise the security of face recognition systems. Furthermore, we propose a detection method based on spatial consistency checks in order to detect said T-shirt attacks. Precisely, state-of-the-art face and person detectors are combined to analyse the spatial positions of detected faces and persons based on which T-shirt attacks can be reliably detected.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。