arXiv:2607.01442cs.CRcs.CV2026-07综述被引 1

系统梳理伪造身份文件的三类攻击与检测方法,揭示真实场景与测试数据间的巨大差距。

From Forgeries to Foundation Models: A Systematic Survey of Identity Document Attack and Detection

论文配图:From Forgeries to Foundation Models: A Systematic Survey of Identity Document Attack and Detection
图 1 · 摘自论文原文
  • 构建统一威胁模型,涵盖展示、数字注入和生成式伪造三类攻击
  • 发现当前最强模型在未见伪造卡上误拒率仍超25%,泛化能力不足
  • 揭示非拉丁字符生成中的文字错位问题,适合安全与合规研究者参考

身份文件伪造已因生成式AI实现质变:低门槛高保真合成与现场篡改成为现实,但检测方法仍受限于不反映真实威胁的基准。攻击形式涵盖物理展示、数字注入和完全生成合成,导致不同的取证失效模式,亟需统一威胁模型与评估框架。本文首次在单一身份验证威胁模型下系统综述展示攻击、数字注入攻击及生成式人工智能驱动的合成攻击。我们追溯检测方法从规则启发式到取证定位、注入感知流程、基础模型及少样本框架的发展历程。对2019至2025年公开数据集的系统审计揭示了基准条件与实际部署间持续存在的‘现实差距’。进一步分析大型多模态模型在身份文件操作中的表现,识别出非拉丁文字拼写中常见的‘脚本依赖生成不稳定性’(SDGI)这一典型错误。最后,在未见过的合成身份证上进行零样本测试显示,即使是最强公开模型在安全运行条件下仍保持超过25%的APCER值,凸显跨域泛化的显著局限。文章最后提出面向取证可信、隐私保护与法律可问责的身份验证未来方向。

原文摘要 · Abstract (English)

Identity document forgery has undergone a fundamental capability shift: generative AI tools now enable high-fidelity document synthesis and field-level manipulation with minimal technical expertise, while detection methods remain constrained by benchmarks that do not reflect this threat. The resulting attack surface spans physical presentation, digital injection, and fully generative synthesis, introducing distinct forensic failure modes that require a unified threat model and evaluation framework. This survey provides, to our knowledge, the first unified treatment of Presentation Attacks, Digital Injection Attacks, and GenAI-driven synthesis within a single identity verification threat model. We trace detection methodologies from rule-based heuristics through forensic localisation, injection-aware pipelines, foundation models, and few-shot frameworks. A systematic audit of public datasets from 2019--2025 exposes a persistent Reality Gap between benchmark conditions and operational deployment. We further analyse large multimodal models for identity document manipulation, identifying Script-Dependent Generative Instability (SDGI) as a recurring typographic failure mode in non-Latin script inpainting. Finally, zero-shot benchmarking on unseen synthesised ID cards shows that even the strongest publicly available models achieve APCER values above 25% under security-oriented operating conditions, highlighting substantial limits in cross-domain generalisation. We conclude by outlining future directions toward forensically grounded, privacy-preserving, and legally accountable identity verification systems.

身份验证伪造检测生成式AI安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。