arXiv:2605.19020cs.CV2026-05

分析视觉大模型在开集虹膜活体检测中的失效问题,揭示其对新型攻击和跨谱检测的脆弱性。

A Systematic Failure Analysis of Vision Foundation Models for Open Set Iris Presentation Attack Detection

论文配图:A Systematic Failure Analysis of Vision Foundation Models for Open Set Iris Presentation Attack Detection
图 1 · 摘自论文原文
  • 用五种大模型评估开集条件下虹膜活体检测表现,涵盖未见攻击设备、传感器差异和跨谱迁移。
  • 模型在跨谱检测中性能骤降,低秩适配(LoRA)虽提升部分场景表现却加剧了攻击与光谱漂移下的失败。
  • 结论适用于安全敏感场景,提醒警惕闭集表现误导开集鲁棒性判断。

视觉基础模型在多种视觉任务中表现出强泛化能力,正被考虑用于生物特征识别。然而其在真实开集条件下的虹膜活体攻击检测(PAD)适用性尚未充分验证。本研究系统分析了通用视觉基础模型在基于眼周图像的开集虹膜PAD中的表现。评估了五种代表性模型,在三种明确分离分布偏移来源的开集协议下进行测试:未见过的活体攻击工具(PAIs)、不同传感器采集的未知数据集,以及从近红外(NIR)到可见光(VIS)谱的跨谱迁移。在统一实验框架中,评估了冻结特征表示与基于低秩适配(LoRA)的参数高效任务适应。结果表明,模型可在传感特性相似的数据集间迁移,但无法可靠泛化至未见攻击工具,且在跨谱评估中性能显著下降。尽管LoRA在某些跨数据集设置中提升表现,但常在攻击级别与光谱偏移下放大失败。通过分割虹膜输入、全主干微调、联合跨数据集与跨PAI偏移、反向从VIS到NIR转移等附加验证实验,进一步确认这些失败并非仅源于眼周输入、弱适应或单向光谱评估。研究指出,强闭集或跨数据集表现不应被视为开集安全性的证据,强调需构建对活体特征敏感且在实际部署变化中稳定的PAD表征。

原文摘要 · Abstract (English)

Vision foundation models have demonstrated strong transferability across diverse visual recognition tasks and are increasingly considered for biometric applications. Their suitability for iris Presentation Attack Detection (PAD), particularly under realistic open-set operating conditions, remains insufficiently examined. This work presents a systematic failure analysis of general-purpose vision foundation models for open-set iris PAD using periocular imagery. Five representative foundation models are evaluated under three open-set protocols that explicitly separate different sources of distribution shift: unseen Presentation Attack Instruments (PAIs), unseen datasets captured with different sensors and cross-spectral transfer from near-infrared (NIR) to visible spectrum (VIS) imagery. Both frozen feature representations and parameter-efficient task adaptation using Low-Rank Adaptation (LoRA) are assessed within a unified experimental framework. The results indicate that foundation models can transfer across datasets with similar sensing characteristics, but fail to generalise reliably to unseen attack instruments and degrade sharply under cross-spectral evaluation. While LoRA improves performance in certain cross-dataset settings, it frequently amplifies failure under attack-level and spectral shifts. Additional validation experiments using segmented iris inputs, full backbone fine-tuning, joint cross-dataset and cross-PAI shifts, and reverse VIS to NIR transfer further confirm that these failures are not simply artefacts of periocular input, weak adaptation, or one-directional spectral evaluation. These findings show that strong closed-set or cross-dataset performance should not be treated as evidence of robust open-set security, and highlight the need for PAD representations that maintain sensitivity to presentation artefacts while remaining stable under realistic deployment variation.

虹膜识别活体检测大模型风险开集学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。