[论文解读] MIPGAN -- Generating Robust and High QualityMorph Attacks Using Identity Prior Driven GAN
MIPGAN 提出了一种基于身份先验的 GAN 框架,用于生成高质量、鲁棒的面部合成图像,以绕过人脸识别系统(FRS)。通过将感知损失和身份感知损失整合到基于 StyleGAN 的架构中,该方法生成的合成面部图像具有最少的伪影和高分辨率,在数字、打印和压缩图像等各种图像类型下,对商业 FRS 均表现出极高的成功率。
Face morphing attacks target to circumvent Face Recognition Systems (FRS) by employing face images derived from multiple data subjects (e.g., accomplices and malicious actors). Morphed images can verify against contributing data subjects with a reasonable success rate, given they have a high degree of identity resemblance. The success of the morphing attacks is directly dependent on the quality of the generated morph images. We present a new approach for generating robust attacks extending our earlier framework for generating face morphs. We present a new approach using an Identity Prior Driven Generative Adversarial Network, which we refer to as extit{MIPGAN (Morphing through Identity Prior driven GAN)}. The proposed MIPGAN is derived from the StyleGAN with a newly formulated loss function exploiting perceptual quality and identity factor to generate a high quality morphed face image with minimal artifacts and with higher resolution. We demonstrate the proposed approach's applicability to generate robust morph attacks by evaluating it against a commercial Face Recognition System (FRS) and demonstrate the success rate of attacks. Extensive experiments are carried out to assess the FRS's vulnerability against the proposed morphed face generation technique on three types of data such as digital images, re-digitized (printed and scanned) images, and compressed images after re-digitization from newly generated extit{MIPGAN Face Morph Dataset}. The obtained results demonstrate that the proposed approach of morph generation profoundly threatens the FRS.
研究动机与目标
- 为解决对高质量、伪影极少的面部合成图像的迫切需求,以有效绕过人脸识别系统(FRS)。
- 提升在不同图像质量条件下(包括数字图像、重新数字化的图像(打印/扫描)以及压缩图像)的合成攻击鲁棒性。
- 开发一种生成模型,在确保合成面部图像的感知质量和分辨率的同时,保持身份相似性。
- 通过新创建的 MIPGAN 面部合成图像数据集,评估商业 FRS 对先进合成攻击的脆弱性。
- 通过在真实世界 FRS 流程中的系统性评估,展示合成攻击的实际威胁。
提出的方法
- MIPGAN 基于 StyleGAN 架构构建,以利用其高分辨率图像生成能力。
- 提出一种新型损失函数,结合感知损失和身份因子损失,以保留面部身份并减少伪影。
- 通过将生成合成图像的潜在空间与从真实面部图像中提取的身份嵌入对齐,强制实施身份先验。
- 模型在多样化的人脸对数据集上进行端到端训练,以生成在两个源主体上均保持相似性的合成图像。
- 训练过程同时优化视觉保真度和身份一致性,确保合成图像既逼真又能在欺骗 FRS 方面有效。
- 由此生成的 MIPGAN 面部合成图像数据集被用于在多种图像质量条件下评估攻击成功率。
实验结果
研究问题
- RQ1基于身份先验的 GAN 方法能否生成在视觉上逼真且能有效绕过商业 FRS 的合成面部图像?
- RQ2所提出的 MIPGAN 框架在不同图像质量级别(包括数字图像、重新数字化图像和压缩图像)下的表现如何?
- RQ3与先前方法相比,感知损失和身份感知损失的集成在多大程度上提升了生成合成图像的质量和鲁棒性?
- RQ4在真实部署条件下,MIPGAN 生成的合成图像在测试商业 FRS 时的成功率是多少?
- RQ5与现有基准相比,MIPGAN 生成的合成图像数据集在合成攻击的有效性和多样性方面表现如何?
主要发现
- MIPGAN 能够成功生成高分辨率的合成面部图像,且视觉伪影极少,显著优于以往的合成技术。
- 所提出的方法在绕过商业 FRS 方面取得了高成功率,证明了基于身份先验的生成方法的有效性。
- 在所有测试的图像类型中,包括重新数字化和压缩图像,攻击成功率依然强劲,表明对质量退化具有高度鲁棒性。
- 感知损失与身份感知损失的集成,使生成的合成图像在视觉上可信,且在语义上与参与合成的主体保持一致。
- MIPGAN 面部合成图像数据集使得对 FRS 脆弱性的系统性评估成为可能,揭示了真实部署场景下的显著安全缺陷。
- 结果证实,先进的基于 GAN 的合成技术对当前人脸识别系统的安全性构成了深远威胁。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。