arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.21455cs.CV

番茄、土豆与洋葱:质疑人脸呈现攻击检测中人脸的必要性

Tomatoes, Potatoes, and Onions: Questioning the Need for Faces in Face Presentation Attack Detection

Guray Ozgur, Fadi Boutros, Naser Damer

首次发表
浏览论文内容

中文总结 AI 辅助

本研究提出无人脸数据集TPO,在其上训练的PAD模型在跨数据集人脸PAD基准上表现优异,证明可迁移的PAD表示可独立于人脸内容学习,为隐私保护PAD开发提供新方向。

中文摘要 AI 辅助

人脸呈现攻击检测(PAD)传统上被视为与人脸相关的特定问题,尽管打印、重放和重捕获过程引入的许多视觉伪影并非本质上与人脸外观相关。本研究探究在下游PAD训练中不使用人脸是否能学习到可迁移的PAD表示。为此,我们引入TPO,这是一个受控的无人脸呈现攻击数据集,包含近随机选择的番茄、土豆和洋葱的 bona fide(真实合法)、打印及重放记录,采集协议与常规人脸PAD数据集高度相似。采用基于基础模型的PAD架构,我们证明在TPO上训练的检测器在四个标准跨数据集人脸PAD基准上的平均AUC达92.70%,优于在合成人脸上的训练结果,且与在真实人脸数据集上训练的模型相比仍具竞争力。相反,在人脸PAD数据集上训练的模型向TPO的迁移性能始终高于随机水平,表明所学表示捕获的是呈现过程的特征而非物体语义。此外,在固定优化预算下,将TPO纳入常规人脸PAD训练可持续提升跨数据集性能,说明无人脸数据提供的是互补信息,而非仅仅是额外的训练样本。最后,表示和频率分析进一步提供证据,表明可迁移的PAD表示无法用单一光谱伪影解释,而是编码了跨物体类别共享的更丰富的呈现线索。综上,这些结果为可迁移的呈现攻击表示可独立于人脸内容学习提供了实证证据,为隐私保护和身份无关的PAD开发开辟了新机遇。

英文摘要

Face presentation attack detection (PAD) is traditionally formulated as a face-specific problem, although many of the visual artifacts introduced by print, replay, and recapture processes are not inherently tied to facial appearance. In this work, we investigate whether transferable PAD representations can be learned without using faces during downstream PAD training. To this end, we introduce TPO, a controlled face-free presentation attack dataset consisting of bona fide, print, and replay recordings of, almost randomly chosen, tomatoes, potatoes, and onions acquired under protocols that closely mirror conventional face PAD datasets. Using a foundation-model-based PAD architecture, we demonstrate that a detector trained on TPO achieves an average AUC of 92.70% across four standard cross-dataset face PAD benchmarks, outperforming training on synthetic faces and remaining competitive with models trained on real face datasets. Conversely, models trained on face PAD datasets transfer consistently above chance to TPO, suggesting that the learned representations capture characteristics of the presentation process rather than object semantics. Furthermore, incorporating TPO into conventional face PAD training consistently improves cross-dataset performance under fixed optimization budgets, indicating that face-free data provides complementary information rather than simply additional training samples. Finally, representation and frequency analyses provide further evidence that transferable PAD representations cannot be explained by a single spectral artifact but instead encode richer presentation cues shared across object categories. Together, these results provide empirical evidence that transferable presentation attack representations can be learned independently of facial content, opening new opportunities for privacy-preserving and identity-independent PAD development.

发表机构

  • Fraunhofer IGD(弗劳恩霍夫应用信息技术研究所)
  • TU Darmstadt(达姆施塔特工业大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑