MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders
Investigating new methods of creating face morphing attacks is essential to foresee novel attacks and help mitigate them. Creating morphing attacks is commonly either performed on the image-level or on the representation-level. The representation-level morphing has been performed so far based on gen...
Gespeichert in:
Hauptverfasser: | , , , , , |
---|---|
Format: | Artikel |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
container_end_page | |
---|---|
container_issue | |
container_start_page | |
container_title | |
container_volume | |
creator | Damer, Naser Fang, Meiling Siebke, Patrick Kolf, Jan Niklas Huber, Marco Boutros, Fadi |
description | Investigating new methods of creating face morphing attacks is essential to
foresee novel attacks and help mitigate them. Creating morphing attacks is
commonly either performed on the image-level or on the representation-level.
The representation-level morphing has been performed so far based on generative
adversarial networks (GAN) where the encoded images are interpolated in the
latent space to produce a morphed image based on the interpolated vector. Such
a process was constrained by the limited reconstruction fidelity of GAN
architectures. Recent advances in the diffusion autoencoder models have
overcome the GAN limitations, leading to high reconstruction fidelity. This
theoretically makes them a perfect candidate to perform representation-level
face morphing. This work investigates using diffusion autoencoders to create
face morphing attacks by comparing them to a wide range of image-level and
representation-level morphs. Our vulnerability analyses on four
state-of-the-art face recognition models have shown that such models are highly
vulnerable to the created attacks, the MorDIFF, especially when compared to
existing representation-level morphs. Detailed detectability analyses are also
performed on the MorDIFF, showing that they are as challenging to detect as
other morphing attacks created on the image- or representation-level. Data and
morphing script are made public: https://github.com/naserdamer/MorDIFF. |
doi_str_mv | 10.48550/arxiv.2302.01843 |
format | Article |
fullrecord | <record><control><sourceid>arxiv_GOX</sourceid><recordid>TN_cdi_arxiv_primary_2302_01843</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>2302_01843</sourcerecordid><originalsourceid>FETCH-LOGICAL-a673-28232489a1768e87f230ed07d293914bf63166b610352214ee01dc82d857f0dd3</originalsourceid><addsrcrecordid>eNo1kL1OwzAcxL0woMIDMOEXSPBH4jhsUUKgUhESqlgjx_67WIS4cpyKvD1tKdMNd_rp7hC6oyTNZJ6TBxV-3CFlnLCUUJnxa3R49aFZt-0jfgftd6OLzo_4Yx5GCKp3g4sLVqPBVYxKf-EGIuj4b3iLW6UBHxn7TzfuLqkJ1wFUBIP7BTfO2nk6Qas5ehi1NxCmG3Rl1TDB7UVXaNs-beuXZPP2vK6rTaJEwRMmGWeZLBUthARZ2GNzMKQwrOQlzXorOBWiF5TwnDGaARBqtGRG5oUlxvAVuv_Dnod3--C-VVi60wHd-QD-C3s8VfU</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>article</recordtype></control><display><type>article</type><title>MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders</title><source>arXiv.org</source><creator>Damer, Naser ; Fang, Meiling ; Siebke, Patrick ; Kolf, Jan Niklas ; Huber, Marco ; Boutros, Fadi</creator><creatorcontrib>Damer, Naser ; Fang, Meiling ; Siebke, Patrick ; Kolf, Jan Niklas ; Huber, Marco ; Boutros, Fadi</creatorcontrib><description>Investigating new methods of creating face morphing attacks is essential to
foresee novel attacks and help mitigate them. Creating morphing attacks is
commonly either performed on the image-level or on the representation-level.
The representation-level morphing has been performed so far based on generative
adversarial networks (GAN) where the encoded images are interpolated in the
latent space to produce a morphed image based on the interpolated vector. Such
a process was constrained by the limited reconstruction fidelity of GAN
architectures. Recent advances in the diffusion autoencoder models have
overcome the GAN limitations, leading to high reconstruction fidelity. This
theoretically makes them a perfect candidate to perform representation-level
face morphing. This work investigates using diffusion autoencoders to create
face morphing attacks by comparing them to a wide range of image-level and
representation-level morphs. Our vulnerability analyses on four
state-of-the-art face recognition models have shown that such models are highly
vulnerable to the created attacks, the MorDIFF, especially when compared to
existing representation-level morphs. Detailed detectability analyses are also
performed on the MorDIFF, showing that they are as challenging to detect as
other morphing attacks created on the image- or representation-level. Data and
morphing script are made public: https://github.com/naserdamer/MorDIFF.</description><identifier>DOI: 10.48550/arxiv.2302.01843</identifier><language>eng</language><subject>Computer Science - Computer Vision and Pattern Recognition</subject><creationdate>2023-02</creationdate><rights>http://arxiv.org/licenses/nonexclusive-distrib/1.0</rights><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><link.rule.ids>228,230,781,886</link.rule.ids><linktorsrc>$$Uhttps://arxiv.org/abs/2302.01843$$EView_record_in_Cornell_University$$FView_record_in_$$GCornell_University$$Hfree_for_read</linktorsrc><backlink>$$Uhttps://doi.org/10.48550/arXiv.2302.01843$$DView paper in arXiv$$Hfree_for_read</backlink></links><search><creatorcontrib>Damer, Naser</creatorcontrib><creatorcontrib>Fang, Meiling</creatorcontrib><creatorcontrib>Siebke, Patrick</creatorcontrib><creatorcontrib>Kolf, Jan Niklas</creatorcontrib><creatorcontrib>Huber, Marco</creatorcontrib><creatorcontrib>Boutros, Fadi</creatorcontrib><title>MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders</title><description>Investigating new methods of creating face morphing attacks is essential to
foresee novel attacks and help mitigate them. Creating morphing attacks is
commonly either performed on the image-level or on the representation-level.
The representation-level morphing has been performed so far based on generative
adversarial networks (GAN) where the encoded images are interpolated in the
latent space to produce a morphed image based on the interpolated vector. Such
a process was constrained by the limited reconstruction fidelity of GAN
architectures. Recent advances in the diffusion autoencoder models have
overcome the GAN limitations, leading to high reconstruction fidelity. This
theoretically makes them a perfect candidate to perform representation-level
face morphing. This work investigates using diffusion autoencoders to create
face morphing attacks by comparing them to a wide range of image-level and
representation-level morphs. Our vulnerability analyses on four
state-of-the-art face recognition models have shown that such models are highly
vulnerable to the created attacks, the MorDIFF, especially when compared to
existing representation-level morphs. Detailed detectability analyses are also
performed on the MorDIFF, showing that they are as challenging to detect as
other morphing attacks created on the image- or representation-level. Data and
morphing script are made public: https://github.com/naserdamer/MorDIFF.</description><subject>Computer Science - Computer Vision and Pattern Recognition</subject><fulltext>true</fulltext><rsrctype>article</rsrctype><creationdate>2023</creationdate><recordtype>article</recordtype><sourceid>GOX</sourceid><recordid>eNo1kL1OwzAcxL0woMIDMOEXSPBH4jhsUUKgUhESqlgjx_67WIS4cpyKvD1tKdMNd_rp7hC6oyTNZJ6TBxV-3CFlnLCUUJnxa3R49aFZt-0jfgftd6OLzo_4Yx5GCKp3g4sLVqPBVYxKf-EGIuj4b3iLW6UBHxn7TzfuLqkJ1wFUBIP7BTfO2nk6Qas5ehi1NxCmG3Rl1TDB7UVXaNs-beuXZPP2vK6rTaJEwRMmGWeZLBUthARZ2GNzMKQwrOQlzXorOBWiF5TwnDGaARBqtGRG5oUlxvAVuv_Dnod3--C-VVi60wHd-QD-C3s8VfU</recordid><startdate>20230203</startdate><enddate>20230203</enddate><creator>Damer, Naser</creator><creator>Fang, Meiling</creator><creator>Siebke, Patrick</creator><creator>Kolf, Jan Niklas</creator><creator>Huber, Marco</creator><creator>Boutros, Fadi</creator><scope>AKY</scope><scope>GOX</scope></search><sort><creationdate>20230203</creationdate><title>MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders</title><author>Damer, Naser ; Fang, Meiling ; Siebke, Patrick ; Kolf, Jan Niklas ; Huber, Marco ; Boutros, Fadi</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-LOGICAL-a673-28232489a1768e87f230ed07d293914bf63166b610352214ee01dc82d857f0dd3</frbrgroupid><rsrctype>articles</rsrctype><prefilter>articles</prefilter><language>eng</language><creationdate>2023</creationdate><topic>Computer Science - Computer Vision and Pattern Recognition</topic><toplevel>online_resources</toplevel><creatorcontrib>Damer, Naser</creatorcontrib><creatorcontrib>Fang, Meiling</creatorcontrib><creatorcontrib>Siebke, Patrick</creatorcontrib><creatorcontrib>Kolf, Jan Niklas</creatorcontrib><creatorcontrib>Huber, Marco</creatorcontrib><creatorcontrib>Boutros, Fadi</creatorcontrib><collection>arXiv Computer Science</collection><collection>arXiv.org</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>Damer, Naser</au><au>Fang, Meiling</au><au>Siebke, Patrick</au><au>Kolf, Jan Niklas</au><au>Huber, Marco</au><au>Boutros, Fadi</au><format>journal</format><genre>article</genre><ristype>JOUR</ristype><atitle>MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders</atitle><date>2023-02-03</date><risdate>2023</risdate><abstract>Investigating new methods of creating face morphing attacks is essential to
foresee novel attacks and help mitigate them. Creating morphing attacks is
commonly either performed on the image-level or on the representation-level.
The representation-level morphing has been performed so far based on generative
adversarial networks (GAN) where the encoded images are interpolated in the
latent space to produce a morphed image based on the interpolated vector. Such
a process was constrained by the limited reconstruction fidelity of GAN
architectures. Recent advances in the diffusion autoencoder models have
overcome the GAN limitations, leading to high reconstruction fidelity. This
theoretically makes them a perfect candidate to perform representation-level
face morphing. This work investigates using diffusion autoencoders to create
face morphing attacks by comparing them to a wide range of image-level and
representation-level morphs. Our vulnerability analyses on four
state-of-the-art face recognition models have shown that such models are highly
vulnerable to the created attacks, the MorDIFF, especially when compared to
existing representation-level morphs. Detailed detectability analyses are also
performed on the MorDIFF, showing that they are as challenging to detect as
other morphing attacks created on the image- or representation-level. Data and
morphing script are made public: https://github.com/naserdamer/MorDIFF.</abstract><doi>10.48550/arxiv.2302.01843</doi><oa>free_for_read</oa></addata></record> |
fulltext | fulltext_linktorsrc |
identifier | DOI: 10.48550/arxiv.2302.01843 |
ispartof | |
issn | |
language | eng |
recordid | cdi_arxiv_primary_2302_01843 |
source | arXiv.org |
subjects | Computer Science - Computer Vision and Pattern Recognition |
title | MorDIFF: Recognition Vulnerability and Attack Detectability of Face Morphing Attacks Created by Diffusion Autoencoders |
url | https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2024-12-17T20%3A29%3A06IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-arxiv_GOX&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.genre=article&rft.atitle=MorDIFF:%20Recognition%20Vulnerability%20and%20Attack%20Detectability%20of%20Face%20Morphing%20Attacks%20Created%20by%20Diffusion%20Autoencoders&rft.au=Damer,%20Naser&rft.date=2023-02-03&rft_id=info:doi/10.48550/arxiv.2302.01843&rft_dat=%3Carxiv_GOX%3E2302_01843%3C/arxiv_GOX%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true |