《Richard Marriott(IDEMIA):变形检测算法对压缩的鲁棒性.pdf》由会员分享,可在线阅读,更多相关《Richard Marriott(IDEMIA):变形检测算法对压缩的鲁棒性.pdf(14页珍藏版)》请在三个皮匠报告上搜索。
1、ROBUSTNESS OF MORPHING ATTACK DETECTION TO COMPRESSIONRichard MarriottIFPC 202503/04/2025Morphing attacksROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025AccompliceMorphAttackerRpublique FranaiseMARRIOTTRichard,Thomas26/02/1985M 1,81m BLEUEExp.02/07/2034 1)Accomplice succeeds in having the morphed image
2、included in a genuine ID document2)Attacker uses morphed ID-doc.to gain unauthorised entry2An extreme use caseROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025 At 1100 bytes,we may still be able to recognise faces But can we still detect morphs?3The study:algorithm+operational thresholdROBUSTNESS OF S-MA
3、D TO COMPRESSION03/04/2025MACERBPCER_m=0.003MACER:Morphing Attack Classification Error Rate(i.e.False Negatives)(i.e.probability that an attacker will fool the detection algorithm)BPCER:Bona fide Presentation Classification Error Rate(i.e.False Positives)(i.e.probability that a genuine document is r
4、ejected due to false morph-detection)BPCER_m=0.01 0.015We will use this value as the“operational threshold”throughout this study4The study:datasets+metricsROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025DatasetImage-typeNum.imagesDataset 1ID-doc.4619Dataset 2ID-doc.5000Dataset 3ID-doc.5000Dataset 4Mugsh
5、ot8069Metrics:For each of these datasets we will look at the effect of compression on values of.MACERBPCER_m=0.01BPCERBPCER_m=0.015The study:crop+compression typesROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025216x216(IED 70px)AVIFHEIFJPEGJPEG2000WEBP1100 bytesBona fideMorph6Compression types-zoomedROB
6、USTNESS OF S-MAD TO COMPRESSION03/04/2025AVIFHEIFJPEGJPEG2000WEBPBona fideMorphArtifact visible in uncompressed morphed image1100 bytes7Does compression obscure morphing artifacts?ROBUSTNESS OF S-MAD TO COMPRESSION03/04/2025Light compression does not increase MACER an attacker cant rely on compressi