用注意力引导的局部分析,精准识别伪装妆容欺骗攻击。
Generalized Disguise Makeup Presentation Attack Detection Using an Attention-Guided Patch-Based Framework

- 先全局后局部:用注意力图指导分块检测
- 在自建数据集上达8.97%错误率,超越已有方法
- 适合需要高鲁棒性防攻击的生物识别系统
尽管人脸识别系统取得显著进展,仍易受人脸呈现攻击影响。其中,伪装妆容攻击尤为棘手,因其使用高级化妆品、假体及人工材料真实改变面部外观,常使人类也难以识别。尽管重要,该问题研究仍不足,公开数据集有限。为此,我们提出一种通用伪装妆容呈现攻击检测框架。方法采用两阶段设计:第一阶段通过度量学习训练的风格无关全脸模型,结合白化变换,利用Grad-CAM提取区域注意力得分;第二阶段依据这些得分,使用区域特定子网络进行局部分析,同样基于度量学习实现细粒度判别。我们还构建了一个在真实条件下采集的多样化活体与伪装妆容人脸数据集,涵盖不同人物、环境和伪装材料。实验表明,该方法在自建数据集和SIW-Mv2上均表现优异,自建数据集上达到8.97% ACER和9.76% EER,SIW-Mv2上对遮掩和冒充攻击为0% ACER,对化妆品攻击为1.34% EER。所提方法持续优于现有工作,且在其他伪造类型上保持稳健性能。
原文摘要 · Abstract (English)
Despite significant advances in facial recognition systems, they remain vulnerable to face presentation attacks. Among them, disguise makeup attacks are particularly challenging, as they use advanced cosmetics, prosthetic components, and artificial materials to realistically alter facial appearance, often making detection difficult even for humans. Despite their importance, this problem remains underexplored, and publicly available datasets are limited. To address this, we propose a generalized disguise makeup presentation attack detection framework. The method adopts a two-phase design in which a style-invariant full-face model, trained with metric learning and enhanced by a whitening transformation, extracts region attention scores via Grad-CAM. These scores guide a patch-based phase that performs localized analysis using region-specific subnetworks trained with metric learning for fine-grained discrimination. We also construct a new, diverse dataset of live and disguise makeup faces collected under real-world conditions, covering variations in subjects, environments, and disguise materials. Experimental results demonstrate strong generalization across both the collected dataset and SIW-Mv2, achieving 8.97% ACER and 9.76% EER on the collected dataset, and 0% ACER on Obfuscation and Impersonation and 1.34% on Cosmetics attacks of SIW-Mv2. The proposed method consistently outperforms prior works while maintaining robust performance across other spoof types.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。