TU Darmstadt / ULB / TUbiblio

MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders

Damer, Naser ; Fang, Meiling ; Siebke, Patrick ; Kolf, Jan Niklas ; Huber, Marco ; Boutros, Fadi (2023)
MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders.
11th International Workshop on Biometrics and Forensics. Barcelona, Spain (19.-20.04.2023)
doi: 10.1109/IWBF57495.2023.10157869
Konferenzveröffentlichung, Bibliographie

Kurzbeschreibung (Abstract)

Investigating new methods of creating face morphing attacks is essential to foresee novel attacks and help mitigate them. Creating morphing attacks is commonly either performed on the image-level or on the representation-level. The representation-level morphing has been performed so far based on generative adversarial networks (GAN) where the encoded images are interpolated in the latent space to produce a morphed image based on the interpolated vector. Such a process was constrained by the limited reconstruction fidelity of GAN architectures. Recent advances in the diffusion autoencoder models have overcome the GAN limitations, leading to high reconstruction fidelity. This theoretically makes them a perfect candidate to perform representation-level face morphing. This work investigates using diffusion autoencoders to create face morphing attacks by comparing them to a wide range of image-level and representation-level morphs. Our vulnerability analyses on four state-of-the-art face recognition models have shown that such models are highly vulnerable to the created attacks, the MorDIFF, especially when compared to existing representation-level morphs. Detailed detectability analyses are also performed on the MorDIFF, showing that they are as challenging to detect as other morphing attacks created on the image- or representation-level. Data and morphing script are made public. https://github.com/naserdamer/MorDIFF

Typ des Eintrags: Konferenzveröffentlichung
Erschienen: 2023
Autor(en): Damer, Naser ; Fang, Meiling ; Siebke, Patrick ; Kolf, Jan Niklas ; Huber, Marco ; Boutros, Fadi
Art des Eintrags: Bibliographie
Titel: MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders
Sprache: Englisch
Publikationsjahr: 26 Juni 2023
Verlag: IEEE
Buchtitel: 2023 11th International Workshop on Biometrics and Forensics (IWBF)
Veranstaltungstitel: 11th International Workshop on Biometrics and Forensics
Veranstaltungsort: Barcelona, Spain
Veranstaltungsdatum: 19.-20.04.2023
DOI: 10.1109/IWBF57495.2023.10157869
Kurzbeschreibung (Abstract):

Investigating new methods of creating face morphing attacks is essential to foresee novel attacks and help mitigate them. Creating morphing attacks is commonly either performed on the image-level or on the representation-level. The representation-level morphing has been performed so far based on generative adversarial networks (GAN) where the encoded images are interpolated in the latent space to produce a morphed image based on the interpolated vector. Such a process was constrained by the limited reconstruction fidelity of GAN architectures. Recent advances in the diffusion autoencoder models have overcome the GAN limitations, leading to high reconstruction fidelity. This theoretically makes them a perfect candidate to perform representation-level face morphing. This work investigates using diffusion autoencoders to create face morphing attacks by comparing them to a wide range of image-level and representation-level morphs. Our vulnerability analyses on four state-of-the-art face recognition models have shown that such models are highly vulnerable to the created attacks, the MorDIFF, especially when compared to existing representation-level morphs. Detailed detectability analyses are also performed on the MorDIFF, showing that they are as challenging to detect as other morphing attacks created on the image- or representation-level. Data and morphing script are made public. https://github.com/naserdamer/MorDIFF

Freie Schlagworte: Biometrics, Morphing attack, Machine learning, Deep learning
Fachbereich(e)/-gebiet(e): 20 Fachbereich Informatik
20 Fachbereich Informatik > Graphisch-Interaktive Systeme
Hinterlegungsdatum: 19 Jul 2023 07:21
Letzte Änderung: 19 Jul 2023 07:21
PPN:
Export:
Suche nach Titel in: TUfind oder in Google
Frage zum Eintrag Frage zum Eintrag

Optionen (nur für Redakteure)
Redaktionelle Details anzeigen Redaktionelle Details anzeigen