MorphUNet:基于扩散的人脸变形攻击的α控制生物特征传输
MorphUNet: Alpha-Controlled Biometric Transport for Diffusion-Based Face Morphing Attacks
浏览论文内容
中文总结 AI 辅助
研究针对人脸变形攻击威胁,提出MorphUNet框架,将双亲生成设为α控制生物特征传输,用可训练双亲分离双交叉注意力,经实验评估其在多个指标上表现出色,在变形攻击潜力等方面优于基线,且难被检测。
中文摘要 AI 辅助
人脸变形攻击会创建可针对多个身份进行验证的合成图像,对边境管制和身份验证系统构成威胁。我们引入了MorphUNet,这是一个扩散变形框架,将双亲生成公式化为α控制的生物特征传输:每个亲本被分解为CLIP外观和ArcFace身份证据,对齐到一个与CLIP兼容的令牌空间,两个贡献者作为单独的身份感知令牌库保留。据我们所知,MorphUNet是第一个在去噪U-Net内部使用可训练的双亲分离双交叉注意力的基于扩散的变形框架:一个生物特征传输层通过去噪携带特定于亲本的身份证据,在通过变形参数α组合残差之前分别关注每个亲本。DDIM反转潜在插值给出了一个连贯的去噪起点,而较弱亲本引导的选择有利于使较低亲本相似度得分最大化的变形,减少向一个贡献者的坍缩。我们使用六个识别系统在FEI和FRLL上针对三个现有技术基线(StableMorph、MIPGAN-II和MorDIFF)评估了MorphUNet,并提出了基于CFD的跨性别和种族配对、人口统计变化以及亲本相似度极值的未见身份压力测试。当六个系统中的至少三个被一个变形欺骗时,MorphUNet实现了最佳的变形攻击潜力(MAP),在FEI上达到0.919,在FRLL上达到0.886,并在两个数据集上获得了最佳的FID(FEI为35.19,FRLL为44.86)。在同一数据集设置中,它在5%BPCER时也给出了最高的APCER,并且在跨数据集转移下仍然极难检测,FEI上的APCER为0.996,FRLL上的APCER为0.946。完整评估分析了MAP、MAD、每个系统的脆弱性、身份平衡、图像质量、顶部/底部相似度压力测试以及CFD未见身份鲁棒性。
英文摘要
Face morphing attacks create synthetic images verifiable against multiple identities, threatening border control and identity verification systems. We introduce MorphUNet, a diffusion morphing framework formulating two-parent generation as alpha-controlled biometric transport: each parent is decomposed into CLIP appearance and ArcFace identity evidence, aligned into a CLIP-compatible token space, with the two contributors preserved as separate identity-aware token banks. To our knowledge, MorphUNet is the first diffusion-based morphing framework using trainable parent-separated dual cross-attention inside the denoising U-Net: a Biometric Transport Layer carrying parent-specific identity evidence through denoising, attending to each parent separately before combining residuals via the morphing parameter alpha. DDIM-inverted latent interpolation gives a coherent denoising start, while weaker-parent-guided selection favours morphs maximising the lower parent-similarity score, reducing collapse toward one contributor. We evaluate MorphUNet against three state-of-the-art baselines (StableMorph, MIPGAN-II, and MorDIFF) on FEI and FRLL using six recognition systems, and propose CFD-based unseen-identity stress testing across gender and ethnicity pairing, demographic shifts, and parent-similarity extremes. MorphUNet achieves the best Morphing Attack Potential (MAP) when at least three of six systems are fooled by one morph, reaching 0.919 on FEI and 0.886 on FRLL, and obtains the best FID on both datasets (35.19 FEI, 44.86 FRLL). It also gives the highest APCER at 5% BPCER in the same-dataset setting, and remains highly difficult to detect under cross-dataset transfer, with APCER 0.996 on FEI and 0.946 on FRLL. The full evaluation analyses MAP, MAD, per-system vulnerability, identity balance, image quality, top/bottom-similarity stress tests, and CFD unseen-identity robustness.