MorGAN: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Generative Adversarial Network

MorGAN: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Generative Adversarial Network
复制标题

DOI:
10.1109/btas.2018.8698563
复制
发表时间:
2018-10
期刊:
2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS)
影响因子:
--
通讯作者:
N. Damer;Alexandra Mosegui Saladie;Andreas Braun;Arjan Kuijper
N. Damer;Alexandra Mosegui Saladie;Andreas Braun;Arjan Kuijper
中科院分区:
其他
文献类型:
--
作者:
N. Damer;Alexandra Mosegui Saladie;Andreas Braun;Arjan Kuijper

文献摘要

被引文献

相似文献

面部变形攻击的目的是创建可验证的面部图像,以作为多个身份的面孔,这可能导致在边境过境等行动中建立错误的身份链接。研究的重点是通过考虑不同的图像属性来创建更准确的攻击检测方法。然而,迄今为止所考虑的所有攻击都是基于对变形面部图像中定位的面部标志的操纵。相比之下,这项工作提出了基于生成对抗网络生成的图像的新型面部变形攻击。我们提出了考虑表征损失的MorGAN结构来成功创建逼真的变形攻击。在此基础上,我们提出了一种新的人脸变形攻击数据库(MorGAN数据库),该数据库包含1000张人脸变形图像,分别用于提出的MorGAN和基于地标的攻击。针对所提出的攻击,我们对两种人脸识别方法进行了漏洞分析。此外,在已知和未知的情况下,研究了所提出的MorGAN攻击的可检测性。最后,我们指出了检测这种未知的新型攻击的挑战,并分析了检测这种攻击的不同特征的检测性能。
Face morphing attacks aim at creating face images that are verifiable to be the face of multiple identities, which can lead to building faulty identity links in operations like border crossing. Research has been focused on creating more accurate attack detection approaches by considering different image properties. However, all the attacks considered so far are based on manipulating facial landmarks localized in the morphed face images. In contrast, this work presents novel face morphing attacks based on image generated by generative adversarial networks. We present the MorGAN structure that considers the representation loss to successfully create realistic morphing attacks. Based on that, we present a novel face morphing attacks database (MorGAN database) that contains 1000 morph images for both, the proposed MorGAN and landmark-based attacks. We present vulnerability analysis of two face recognition approaches facing the proposed attacks. Moreover, the detectability of the proposed MorGAN attacks is studied, in the scenarios where this type of attacks is know and un- known. We concluded with pointing out the challenge of detecting such unknown novel attacks and an analysis of detection performances of different features in detecting such attacks.