arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于演示攻击工具偏移和环境退化下虹膜演示攻击检测的紧凑视觉模型

Compact Vision Models for Iris Presentation Attack Detection under Presentation Attack Instrument Shift and Environmental Degradation

Athanasios Angelakis, Marta Gomez-Barrero

arXiv 2609.20386首次发表:更新:

发表机构

BioML Lab, RI CODE, UniBw; EDS, Amsterdam UMC, University of Amsterdam(BioML实验室,RI CODE,联邦国防军大学; EDS,阿姆斯特丹大学医学中心,阿姆斯特丹大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文在PAI偏移和环境退化下基准测试三个紧凑虹膜PAD模型,发现ZACH-ViT性能最优,但高错误率表明尚不满足未知攻击下的部署要求。

AI 中文摘要

虹膜演示攻击检测(PAD)在开发阶段表现可靠的子系统遇到验证数据中不存在的演示攻击工具(PAI)或采集条件时,具有安全关键性。我们在LivDet-Iris 2017的Notre Dame子集上,针对PAI驱动的域偏移和环境退化,对三个紧凑的从头训练的计算机视觉模型进行了基准测试,每个模型的可训练参数最多约为0.26百万。所有模型均在无外部预训练或数据增强的情况下训练,并在五个种子上进行评估。验证选择的阈值被原样转移到已知攻击、未知攻击、损坏和合并测试分区。从已知到未知攻击演示,攻击演示分类错误率(APCER)增加了17.11-30.47个百分点,检测等错误率(D-EER)增加了7.38-12.73个百分点。在验证选择的阈值下,ZACH-ViT获得了最低的未知攻击APCER(47.69±4.84%)和D-EER(38.87±0.93%),而Compact-TransMIL获得了最低的真实演示分类错误率(BPCER)。ZACH-ViT在APCER限制为10%时也给出了最低的未知攻击BPCER(81.29±1.95%)。高绝对误差表明,最佳紧凑模型的比较优势并不构成在未知PAI下的部署就绪性。

英文摘要

Iris presentation attack detection (PAD) is security-critical when a subsystem that appears reliable during development encounters presentation attack instruments (PAIs) or acquisition conditions absent from validation data. We benchmark three compact scratch-trained computer-vision models, each with at most approximately 0.26 million trainable parameters, on the Notre Dame subset of LivDet-Iris 2017 under PAI-driven domain shift and environmental degradation. All models are trained without external pretraining or data augmentation and evaluated over five seeds. A validation-selected threshold is transferred unchanged to the known-attack, unknown-attack, corrupted, and pooled test partitions. From known to unknown attack presentations, Attack Presentation Classification Error Rate (APCER) increases by 17.11-30.47 percentage points and Detection Equal Error Rate (D-EER) increases by 7.38-12.73 percentage points. At the validation-selected threshold, ZACH-ViT obtains the lowest unknown-attack APCER (47.69 +/- 4.84%) and D-EER (38.87 +/- 0.93%), while Compact-TransMIL obtains the lowest Bona Fide Presentation Classification Error Rate (BPCER). ZACH-ViT also gives the lowest unknown-attack BPCER at an APCER limit of 10% (81.29 +/- 1.95%). The high absolute errors show that the comparative advantage of the best compact model does not constitute deployment readiness under unknown PAIs.

CommentsAccepted at BIOSIG 2026. This preprint includes minor nomenclature and editorial corrections clarifying the project-specific Patch-ABMIL and Compact-TransMIL variants

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑