用扩散模型实现可控人脸融合,让伪造图像骗过多重身份验证。
MorphUNet: Alpha-Controlled Biometric Transport for Diffusion-Based Face Morphing Attacks

- 将双亲身份分解为外观与特征向量,通过独立注意力机制融合生成。
- 在FEI和FRLL数据集上攻击成功率达91.9%和88.6%,生成图像质量高。
- 适合研究伪造检测、生物识别安全的人员参考。
人脸融合攻击可生成能通过多个身份验证的合成图像,威胁边境管控与身份认证系统。本文提出MorphUNet,一种基于扩散模型的融合框架,将双亲生成建模为可控的生物特征传输:每个父母分别分解为CLIP外观与ArcFace身份特征,在CLIP兼容的标记空间中对齐,保留为独立的身份感知标记库。MorphUNet是首个在去噪U-Net中使用可训练双交叉注意力的扩散融合框架,包含一个生物特征传输层,在去噪过程中分别关注双亲特征,再通过融合参数alpha组合残差。采用DDIM反演潜空间插值作为连贯去噪起点,弱父引导选择策略优先选择使低相似度父本更显著的融合结果,减少向单一贡献者坍塌。我们在FEI和FRLL数据集上,针对三种前沿基线(StableMorph、MIPGAN-II、MorDIFF)及六种识别系统进行评估,并提出基于CFD的未见身份压力测试,涵盖性别与种族组合、人口分布变化及双亲相似度极端情况。MorphUNet在至少三套系统被攻破时达到最高攻击潜力(MAP),FEI为0.919,FRLL为0.886;同时在两数据集上取得最佳FID(FEI 35.19,FRLL 44.86)。在同数据集设置下,5%假正率下的最大误拒率(APCER)也最优;跨数据集迁移时仍极难检测,对应APCER分别为0.996(FEI)和0.946(FRLL)。完整评估涵盖MAP、MAD、各系统脆弱性、身份平衡、图像质量、上下相似度压力测试及CFD未见身份鲁棒性分析。
原文摘要 · Abstract (English)
Face morphing attacks create synthetic images verifiable against multiple identities, threatening border control and identity verification systems. We introduce MorphUNet, a diffusion morphing framework formulating two-parent generation as alpha-controlled biometric transport: each parent is decomposed into CLIP appearance and ArcFace identity evidence, aligned into a CLIP-compatible token space, with the two contributors preserved as separate identity-aware token banks. To our knowledge, MorphUNet is the first diffusion-based morphing framework using trainable parent-separated dual cross-attention inside the denoising U-Net: a Biometric Transport Layer carrying parent-specific identity evidence through denoising, attending to each parent separately before combining residuals via the morphing parameter alpha. DDIM-inverted latent interpolation gives a coherent denoising start, while weaker-parent-guided selection favours morphs maximising the lower parent-similarity score, reducing collapse toward one contributor. We evaluate MorphUNet against three state-of-the-art baselines (StableMorph, MIPGAN-II, and MorDIFF) on FEI and FRLL using six recognition systems, and propose CFD-based unseen-identity stress testing across gender and ethnicity pairing, demographic shifts, and parent-similarity extremes. MorphUNet achieves the best Morphing Attack Potential (MAP) when at least three of six systems are fooled by one morph, reaching 0.919 on FEI and 0.886 on FRLL, and obtains the best FID on both datasets (35.19 FEI, 44.86 FRLL). It also gives the highest APCER at 5% BPCER in the same-dataset setting, and remains highly difficult to detect under cross-dataset transfer, with APCER 0.996 on FEI and 0.946 on FRLL. The full evaluation analyses MAP, MAD, per-system vulnerability, identity balance, image quality, top/bottom-similarity stress tests, and CFD unseen-identity robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。