《Richard Marriott(IDEMIA):變形檢測算法對壓縮的魯棒性.pdf》由會員分享,可在線閱讀,更多相關《Richard Marriott(IDEMIA):變形檢測算法對壓縮的魯棒性.pdf(14頁珍藏版)》請在三個皮匠報告上搜索。
1、ROBUSTNESS OF MORPHING ATTACK DETECTION TO COMPRESSIONRichard MarriottIFPC 202503/04/2025Morphing attacksROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025AccompliceMorphAttackerRpublique FranaiseMARRIOTTRichard,Thomas26/02/1985M 1,81m BLEUEExp.02/07/2034 1)Accomplice succeeds in having the morphed image
2、included in a genuine ID document2)Attacker uses morphed ID-doc.to gain unauthorised entry2An extreme use caseROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025 At 1100 bytes,we may still be able to recognise faces But can we still detect morphs?3The study:algorithm+operational thresholdROBUSTNESS OF S-MA
3、D TO COMPRESSION03/04/2025MACERBPCER_m=0.003MACER:Morphing Attack Classification Error Rate(i.e.False Negatives)(i.e.probability that an attacker will fool the detection algorithm)BPCER:Bona fide Presentation Classification Error Rate(i.e.False Positives)(i.e.probability that a genuine document is r
4、ejected due to false morph-detection)BPCER_m=0.01 0.015We will use this value as the“operational threshold”throughout this study4The study:datasets+metricsROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025DatasetImage-typeNum.imagesDataset 1ID-doc.4619Dataset 2ID-doc.5000Dataset 3ID-doc.5000Dataset 4Mugsh
5、ot8069Metrics:For each of these datasets we will look at the effect of compression on values of.MACERBPCER_m=0.01BPCERBPCER_m=0.015The study:crop+compression typesROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025216x216(IED 70px)AVIFHEIFJPEGJPEG2000WEBP1100 bytesBona fideMorph6Compression types-zoomedROB
6、USTNESS OF S-MAD TO COMPRESSION03/04/2025AVIFHEIFJPEGJPEG2000WEBPBona fideMorphArtifact visible in uncompressed morphed image1100 bytes7Does compression obscure morphing artifacts?ROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025Light compression does not increase MACER an attacker cant rely on compressi
7、on to mask artifactsHeavy compression can increase or decrease the rate of detections,depending on the compression type.8Does compression obscure morphing artifacts?ROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025JPEG(2kB)JPEG2000(1.1kB)Light compression does not increase MACER an attacker cant rely on
8、compression to mask artifactsHeavy compression can increase or decrease the rate of detections,depending on the compression type.9How does compression affect false detections?ROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025Lower quality,compressed images cause more false positivesWe can safely compress
9、to around 20kB10Can we do better by pre-processing images before compression?ROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025Here we see that,even with no compression,pre-processing images increases the BPCER.11Can we maintain performance by adapting the threshold as a function of observed file-size?ROB
10、USTNESS OF S-MAD TO COMPRESSION03/04/2025Adapting the threshold based on file-size does not help much to stabilise performance.12Preliminary work on improving robustness to compressionROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025We re-trained idemia_004 on images compressed to 1.1kB using AVIF.We see
11、 that performance can be improved by re-training but that it is still far from base levels._ idemia_004(Uncompressed)_ _ _ idemia_004(AVIF 1.1kB)_ idemia_004_AVIF(Uncompressed)_ _ _ idemia_004_AVIF(AVIF 1.1kB)13Conclusions and recommendationsROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025Conclusions:Co
12、mpression to 1.1kB is too extreme for morph detection QR codes should only be used for securely captured imagesCompression can hide morphing artifacts but also triggers increased numbers of detections(whether images are morphs or bona fide)An attacker therefore cannot use compression to evade detection Performance for heavily compressed images can be improved by specialised training but is still far from base levelsRecommendations:Compression should not be 20kB (for crop 216x216,IED=70px)AVIF,HEIF and WEBP formats are preferable to JPEG and JPEG200014