Skip to main content
QUICK REVIEW

[论文解读] Morphing Attack Detection -- Database, Evaluation Platform and Benchmarking

Kiran Raja, Matteo Ferrara|arXiv (Cornell University)|Jun 11, 2020
Face recognition and analysis参考文献 42被引用 87
一句话总结

本文提出了一种新型隐蔽形态攻击检测(MAD)数据库及在线评估平台,以解决MAD算法在鲁棒性和泛化能力基准测试中的关键空白。该数据集包含150名多样化受试者,其形态化图像通过精心的受试者筛选和后期处理生成,包括打印-扫描仿真,以消除数字痕迹。关键结果表明,即使是最先进的方法在打印-扫描图像上的BPCER100仍超过90%,凸显了性能显著下降,并迫切需要在真实操作场景中开发更具鲁棒性的检测算法。

ABSTRACT

Morphing attacks have posed a severe threat to Face Recognition System (FRS). Despite the number of advancements reported in recent works, we note serious open issues such as independent benchmarking, generalizability challenges and considerations to age, gender, ethnicity that are inadequately addressed. Morphing Attack Detection (MAD) algorithms often are prone to generalization challenges as they are database dependent. The existing databases, mostly of semi-public nature, lack in diversity in terms of ethnicity, various morphing process and post-processing pipelines. Further, they do not reflect a realistic operational scenario for Automated Border Control (ABC) and do not provide a basis to test MAD on unseen data, in order to benchmark the robustness of algorithms. In this work, we present a new sequestered dataset for facilitating the advancements of MAD where the algorithms can be tested on unseen data in an effort to better generalize. The newly constructed dataset consists of facial images from 150 subjects from various ethnicities, age-groups and both genders. In order to challenge the existing MAD algorithms, the morphed images are with careful subject pre-selection created from the contributing images, and further post-processed to remove morphing artifacts. The images are also printed and scanned to remove all digital cues and to simulate a realistic challenge for MAD algorithms. Further, we present a new online evaluation platform to test algorithms on sequestered data. With the platform we can benchmark the morph detection performance and study the generalization ability. This work also presents a detailed analysis on various subsets of sequestered data and outlines open challenges for future directions in MAD research.

研究动机与目标

  • 解决人脸识别系统中形态攻击检测(MAD)缺乏标准化、多样化和真实基准的问题。
  • 通过提供用于在未见数据上测试的隐蔽数据集,克服MAD算法的泛化挑战。
  • 通过包含打印-扫描图像处理流程,模拟自动边境控制(ABC)中的真实操作条件。
  • 通过专用在线评估平台,实现MAD算法的持续基准测试。
  • 研究人口统计因素(年龄、性别、种族)和形态化参数对MAD性能的影响。

提出的方法

  • 构建了一个包含150名受试者的新型隐蔽数据集,涵盖多样化种族、年龄和性别,以提升人口统计泛化能力。
  • 使用先进形态化技术(如GIMP GAP、Sqirlz Morph、FaceFusion)生成形态化图像,通过仔细的受试者预选以确保高质量合成图像。
  • 应用后期处理以消除可见形态化痕迹,并通过打印和扫描图像来模拟真实条件,以消除数字线索。
  • 开发了在线评估平台,支持在隐蔽数据上对MAD算法进行盲测,实现持续基准测试。
  • 使用标准指标评估算法:等错误率(EER)、10%、20%和100%假接受率下的BPCER,以及拒绝率。
  • 在不同形态化因子(0.3和0.5)的子集上进行消融研究,分析算法在不同攻击强度下的鲁棒性。

实验结果

研究问题

  • RQ1当在真实打印-扫描条件下对未见、隐蔽数据进行测试时,现有MAD算法的性能如何退化?
  • RQ2人口统计因素(年龄、性别、种族)和形态化强度在多大程度上影响形态化图像的可检测性?
  • RQ3所提出的在线评估平台能否有效支持MAD算法的持续基准测试和泛化测试?
  • RQ4不同MAD方法在数字图像与重新数字化(打印-扫描)图像之间的性能差距如何?
  • RQ5混合或多模态检测策略与单方法策略相比,在检测高质量形态化图像方面表现如何?

主要发现

  • 表现最佳的D-MAD方法(DFR)在打印-扫描图像上的BPCER100为19.70%,表明在100%假接受率阈值下存在19.7%的错误接受率,远未达到实际应用要求。
  • 对于S-MAD算法,所有测试方法的BPCER100均超过90%(如WL为95.58%,Deep-S-MAD为100%),表明在打印-扫描条件下性能严重下降。
  • 所有MAD算法在从数字图像过渡到打印-扫描图像时均表现出一致的性能下降,部分方法的BPCER100上升了多达10个百分点。
  • 形态化因子(0.3与0.5)对检测性能有可测量但有限的影响,较低形态化强度下结果略优。
  • 不同形态化方法或检测技术之间未观察到显著改进,表明当前方法对真实图像退化缺乏鲁棒性。
  • 结果证实,跨数据库训练与测试对提升泛化能力至关重要,因为在一个数据集上训练的算法在未见、隐蔽数据上表现失败。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。