用双流注意力扩散模型实现更逼真的换脸攻击,突破现有技术局限。
DCMorph: Face Morphing via Dual-Stream Cross-Attention Diffusion

- 双流交叉注意力插值,显式融合双人脸特征。
- 球面插值保持结构一致,生成质量更高。
- 攻破四大主流识别系统,检测难度大,适合安全研究。
推进人脸换脸攻击技术对预判新型威胁、构建鲁棒的身份验证防御机制至关重要。本文提出DCMorph,一种基于双流扩散的换脸框架,在身份条件和潜在空间层面同步操作。不同于存在混合伪影的图像级方法或重建保真度有限的GAN方法,DCMorph通过两种机制实现:(1) 解耦的交叉注意力插值,将双源人脸的身份特征求注入去噪过程,实现现有扩散方法缺失的显式双身份条件;(2) 使用DDIM反演结合反转潜在表示间的球面插值,提供几何一致的初始潜在表示,保留结构属性。在四个最先进的面部识别系统上的漏洞分析表明,DCMorph在两个操作阈值下均取得最高攻击成功率,且目前的换脸检测方案难以识别。
原文摘要 · Abstract (English)
Advancing face morphing attack techniques is crucial to anticipate evolving threats and develop robust defensive mechanisms for identity verification systems. This work introduces DCMorph, a dual-stream diffusion-based morphing framework that simultaneously operates at both identity conditioning and latent space levels. Unlike image-level methods suffering from blending artifacts or GAN-based approaches with limited reconstruction fidelity, DCMorph leverages identity-conditioned latent diffusion models through two mechanisms: (1) decoupled cross-attention interpolation that injects identity-specific features from both source faces into the denoising process, enabling explicit dual-identity conditioning absent in existing diffusion-based methods, and (2) DDIM inversion with spherical interpolation between inverted latent representations from both source faces, providing geometrically consistent initial latent representation that preserves structural attributes. Vulnerability analyses across four state-of-the-art face recognition systems demonstrate that DCMorph achieves the highest attack success rates compared to existing methods at both operational thresholds, while remaining challenging to detect by current morphing attack detection solutions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。