Face morphing attacks seek to deceive a Face Recognition (FR) system by presenting a morphed image consisting of the biometric qualities from two different identities with the aim of triggering a false acceptance with one of the two identities, thereby presenting a significant threat to biometric systems. The success of a morphing attack is dependent on the ability of the morphed image to represent the biometric characteristics of both identities that were used to create the image. We present a novel morphing attack that uses a Diffusion-based architecture to improve the visual fidelity of the image and improve the ability of the morphing attack to represent characteristics from both identities. We demonstrate the high fidelity of the proposed attack by evaluating its visual fidelity via the Frechet Inception Distance. Extensive experiments are conducted to measure the vulnerability of FR systems to the proposed attack. The proposed attack is compared to two state-of-the-art GAN-based morphing attacks along with two Landmark-based attacks. The ability of a morphing attack detector to detect the proposed attack is measured and compared against the other attacks. Additionally, a novel metric to measure the relative strength between morphing attacks is introduced and evaluated.
翻译:人脸变形攻击旨在通过呈递包含两个不同身份生物特征信息的变形图像来欺骗人脸识别系统,试图触发系统对其中任一身份的误接受,从而对生物识别系统构成重大威胁。变形攻击的成功性取决于变形图像表征用于生成该图像的两个身份生物特征的能力。本文提出一种基于扩散架构的新型变形攻击方法,通过提升图像的视觉保真度来增强变形攻击表征两个身份特征的能力。通过弗雷歇初始距离评估视觉保真度,我们验证了所提攻击的高保真特性。实验全面衡量了人脸识别系统对该攻击的脆弱性,并将所提攻击与两种基于生成对抗网络的最先进变形攻击及两种基于特征点的攻击进行对比。同时测量了变形攻击检测器对该攻击的检测能力,并与其它攻击方法进行对比分析。此外,本文提出并评估了一种用于衡量不同变形攻击相对强弱程度的新型度量指标。