Vulnerability Analysis of Face Morphing Attacks from Landmarks and Generative Adversarial Networks

Vulnerability Analysis of Face Morphing Attacks from Landmarks and Generative Adversarial Networks
复制标题

来自地标和生成对抗网络的人脸变形攻击的漏洞分析

DOI:
--
复制
发表时间:
2020
期刊:
arXiv.org
影响因子:
--
通讯作者:
S. Marcel
S. Marcel
中科院分区:
--
文献类型:
--
作者:
Eklavya Sarkar;Pavel Korshunov;Laurent Colbois;S. Marcel

文献摘要

被引文献

相似文献

变形攻击是对生物识别系统的威胁,其中身份文件中的生物识别参考可以被更改。这种形式的攻击在依赖身份证件的应用程序(例如边境安全或访问控制)中提出了一个重要问题。人脸变形攻击检测的研究正在迅速发展,但是公开的包含多种攻击形式的数据集却很少。本文通过提供一个新的数据集来弥补这一差距,该数据集具有四种不同类型的变形攻击,基于 OpenCV、FaceMorpher、WebMorph 和生成对抗网络 (StyleGAN),由三个公共人脸数据集的原始人脸图像生成。我们还进行了大量的实验来评估最先进的人脸识别系统的脆弱性,特别是 FaceNet、VGG-Face 和 ArcFace。实验表明,与 FaceNet 相比,VGG-Face 的人脸识别系统虽然不太准确,但也不易受到变形攻击。此外,我们观察到使用 StyleGAN 生成的幼稚变形不会构成重大威胁。
Morphing attacks is a threat to biometric systems where the biometric reference in an identity document can be altered. This form of attack presents an important issue in applications relying on identity documents such as border security or access control. Research in face morphing attack detection is developing rapidly, however very few datasets with several forms of attacks are publicly available. This paper bridges this gap by providing a new dataset with four different types of morphing attacks, based on OpenCV, FaceMorpher, WebMorph and a generative adversarial network (StyleGAN), generated with original face images from three public face datasets. We also conduct extensive experiments to assess the vulnerability of the state-of-the-art face recognition systems, notably FaceNet, VGG-Face, and ArcFace. The experiments demonstrate that VGG-Face, while being less accurate face recognition system compared to FaceNet, is also less vulnerable to morphing attacks. Also, we observed that naive morphs generated with a StyleGAN do not pose a significant threat.