Leveraging Adversarial Learning for the Detection of Morphing Attacks

Leveraging Adversarial Learning for the Detection of Morphing Attacks
复制标题

DOI:
10.1109/ijcb52358.2021.9484383
复制
发表时间:
2021-08
期刊:
2021 IEEE International Joint Conference on Biometrics (IJCB)
影响因子:
--
通讯作者:
Zander Blasingame;Chen Liu
Zander Blasingame;Chen Liu
中科院分区:
其他
文献类型:
--
作者:
Zander Blasingame;Chen Liu

文献摘要

被引文献

相似文献

针对人脸识别系统 (FRS) 的一个新兴威胁是人脸变形攻击,该攻击涉及将两个不同身份的两张脸组合成一个单一图像,从而触发 FRS 内对任一身份的接受。许多现有的变形攻击检测(MAD)方法都是在图像特征变化有限的数据集上进行训练和评估的,这可能使该方法容易过度拟合。此外,正如最新的 NIST FRVT MORPH 报告所示,开发可以泛化到其所训练的变形攻击之外的 MAD 算法也存在困难。此外,基于单图像的 MAD (S-MAD) 问题的性能较差,特别是与对应的基于差分的 MAD (D-MAD) 相比。在这项工作中,我们提出了一种用于训练基于深度学习的 S-MAD 算法的新颖架构,该算法利用对抗性学习来训练更强大的检测器。所提出的 S-MAD 方法的性能使用 ISO-IEC 30107-3 评估指标,通过 36 次实验与基于最先进的 VGG19 的 S-MAD 算法进行了基准测试。当针对不同的变形攻击进行评估时,所提出的方法表现出优越且稳健的检测性能,D-EER 低于 5%。
An emerging threat towards face recognition systems (FRS) is face morphing attack, which involves the combination of two faces from two different identities into a singular image that would trigger an acceptance for either identity within the FRS. Many of the existing morphing attack detection (MAD) approaches have been trained and evaluated on datasets with limited variation of image characteristics, which can make the approach prone to overfitting. Additionally, there has been difficulty in developing MAD algorithms which can generalize beyond the morphing attack they were trained on, as shown by the most recent NIST FRVT MORPH report. Furthermore, the Single image based MAD (S-MAD) problem has had poor performance, especially when compared to its counterpart, Differential based MAD (D-MAD). In this work, we propose a novel architecture for training deep learning based S-MAD algorithms that leverages adversarial learning to train a more robust detector. The performance of the proposed S-MAD method is benchmarked against the state-of-the-art VGG19 based S-MAD algorithm over 36 experiments using the ISO-IEC 30107-3 evaluation metrics. The proposed method has demonstrated superior and robust detection performance of less than 5% D-EER when evaluated against different morphing attacks.