Face Recognition (FR) systems have been shown to be vulnerable to morphing attacks. We examine exactly how challenging morphs can become. By showing a worst-case construction in the embedding space of an FR system and using a mapping from embedding space back to image space we generate images that show that this theoretical upper bound can be approximated if the FR system is known. The resulting morphs can also succesfully fool unseen FR systems and are useful for exploring and understanding the weaknesses of FR systems. Our method contributes to gaining more insight into the vulnerability of FR systems.
翻译:脸部识别( FR) 系统被证明很容易受到变形攻击。 我们仔细研究进化变形究竟会如何。 通过显示FR系统嵌入空间中最糟糕的构造, 并使用从嵌入空间到图像空间的映射, 我们产生的图像显示,如果FR系统为人所知, 理论上的上层界限是可以接近的。 由此形成的变形也可以巧妙地愚弄不为人知的FR系统, 有助于探索和理解FR系统的弱点。 我们的方法有助于更深入地了解FR系统的脆弱性。