User authentication method and system
By combining a comprehensive evaluation of face similarity, background similarity, and Morpheus patterns, and using a trained image deception model and CNN to generate multiple scores, this approach addresses the shortcomings of existing face anti-spoofing methods in identifying similar image attacks, thereby improving the security and accuracy of identity authentication in eKYC processing.
Patent Information
- Application Number
- CN202011383526.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-18
- Filing Date
- 2020-12-01
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2040-12-01
AI Technical Summary
In existing eKYC processing, facial anti-spoofing methods have difficulty effectively identifying attack images that are similar to the facial images used in the initial registration process, resulting in insufficient security for identity authentication.
By combining facial similarity, background similarity, and Morpheus patterns, multiple scores are generated through a trained image deception model and CNN to comprehensively evaluate user identity authentication.
It improves the ability to identify attacks in eKYC processing, reduces the success rate of attacks using similar facial images, and enhances the accuracy and security of identity authentication.
Smart Images

Figure CN112613345B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] This document relates generally to, but not exclusively to, a user authentication method and a user authentication system. BACKGROUND
[0002] “Electronic Know Your Customer (eKYC)” is a digital due diligence process performed by a business entity or service provider to verify the identity of its customers to prevent identity fraud. Many eKYC processes involve a potential customer submitting a photo of themselves (particularly their face) and their official identity proof document (e.g. identity card, passport, etc.). The photos can then be compared for consistency to verify the identity of the customer.
[0003] In a typical eKYC process, the customer is asked to first take a photo of their identity proof document. Then a photo of their face is taken (i.e. a “selfie”). A face anti-spoofing method is then implemented to prevent an attacker from using a photo, video or other substitute to fool the face verification of the person.
[0004] Current face anti-spoofing techniques can effectively detect screen captures, paper prints and video replays. However, certain attacks will use a face image that is very similar to the face image in the initial registration process to attack the subsequent verification process. It is relatively easy for an attacker to obtain the face image from the registration process. For example, if a user uses the face image in their identity card to register their face image, an attacker can print the face image of the identity card at high resolution to attack the verification process.
[0005] Therefore, there is a need to improve the way a user can be authenticated. SUMMARY
[0006] Embodiments seek to provide a user authentication method that involves a combination of different authentication methods such as computing face similarity, background similarity and Moire ripple.
[0007] According to an embodiment, there is provided a user authentication method comprising: extracting a first face image and a first background image from a user registration image comprising the first face image and the first background image; extracting a second face image and a second background image from a user authentication image comprising the second face image and the second background image; generating a first score (SI) associated with the user authentication image using a trained image spoofing model; generating a second score (S2) corresponding to a similarity between the first background image and the second background image; generating a third score (S3) corresponding to a similarity between the first face image and the second face image; and authenticating the user based on the first score (SI), the second score (S2) and the third score (S3).
[0008] According to another embodiment, there is provided a user authentication system comprising: an extraction device configured to extract a first face image and a first background image from a user registration image comprising the first face image and the first background image, and to extract a second face image and a second background image from a user authentication image comprising the second face image and the second background image; a first score generation device configured to generate a first score (S1) associated with the user authentication image using a trained image spoofing model; a second score generation device for generating a second score (S2) corresponding to a similarity between the first background image and the second background image; a third score generation device for generating a third score (S3) corresponding to a similarity between the first face image and the second face image; and an authentication device configured to authenticate the user based on the first score (S1), the second score (S2), and the third score (S3). BRIEF DESCRIPTION OF DRAWINGS
[0009] The embodiments are provided by way of example only, and those skilled in the art will readily recognize variations and modifications to the embodiments as they will be better understood from the following written description together with the accompanying drawings, in which:
[0010] Figure 1 is a flowchart illustrating an example of a user authentication method according to an embodiment.
[0011] Figure 2 An example of a face photo submitted by a user is shown.
[0012] Figure 3 A schematic diagram of a computer system suitable for performing at least some steps of a user authentication method is shown.
[0013] Figure 4 is a schematic diagram illustrating an example of a user authentication system according to an embodiment. DETAILED DESCRIPTION
[0014] The embodiments will be described with reference to the drawings in which like elements are referred to by the same reference numeral or character. As such, each embodiment described below will not be described in every possible combination or sub-combination. Only the essential operational features of the embodiments will be described, and other features will be apparent to the skilled person.
[0015] Some portions of the description which follow are explicitly or implicitly presented in terms of algorithms and functional or symbolic representations of operations on data within a computer memory. These algorithmic descriptions and functional or symbolic representations are the means used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. Here, a algorithm is generally considered to be a self-consistent sequence of steps leading to a desired result. The steps are those requiring physical manipulations of physical quantities, such as electrical, magnetic or optical signals capable of storing, transferring, combining, comparing, and otherwise manipulating such signals.
[0016] Unless specifically stated otherwise, and as can be apparent from the following, methodologies described herein can be implemented by using computer- readable instructions, such as program code, executed on computers in networked environments. A computer-readable medium can include one or more of many physical media, such as optical, magnetic or semiconductor storage medium. More specific examples of a computer-readable medium can include: hard disks, floppy disks, magnetic tape, optical data storage like CD-ROM or DVD, magneto-optical storage like floptical disks, ROM, RAM, EPROM, EEPROM, DRAM, SRAM, SDRAM, or any other storage device(s) which are suitable to the technical task of the present application.
[0017] There is also disclosed herein a device for performing the operations of the methods described. Such a device can be specially constructed for the required purposes, or it can comprise a computer or other apparatus selectively activated or reconfigured by a computer program stored in the computer. The algorithms and displays presented herein are not inherently related to any particular computer or other apparatus. Various machines can be used with programs in accordance with the teachings herein. Alternatively, the construction of more specialized apparatus to perform the required method steps can be appropriate. The structure of a computer for executing the various methods described herein will appear from the description below.
[0018] In addition, a computer program is implicitly disclosed herein, since any computer program that enables a computer to operate as described herein is implicitly disclosed herein. A computer program in which such a computer program is embodied can optionally be encoded on a computer- readable medium. The computer-readable medium can include storage devices such as magnetic or optical disks, memory chips, or other storage devices suitable for the technical task of the present application. The computer-readable medium can also include hard-wired elements or other storage devices transitory or otherwise, such as in the Internet system, or wireless elements such as in the GSM mobile telephone system, and other wireless systems such as Bluetooth, ZigBee, Wi-Fi. When this computer program is loaded into the computer and executed, it effectively results in an apparatus, being the computer, which carries out the steps of the preferred methods.
[0019] Furthermore, one or more steps of the computer program can be performed in parallel rather than sequentially. Such a computer program can be stored on any computer readable medium. The computer readable medium can include storage devices such as magnetic or optical disks, memory chips, or other storage devices suitable for the technical task of the present application. The computer readable medium can also include hard-wired elements or other storage devices transitory or otherwise, such as in the Internet system, or wireless elements such as in the GSM mobile telephone system, and other wireless systems such as Bluetooth, ZigBee, Wi-Fi. When this computer program is loaded into the computer and executed, it effectively results in an apparatus, being the computer, which carries out the steps of the preferred methods.
[0020] “eKYC” is a digital due diligence process performed by a business entity or service provider to verify the identity of its customers to prevent identity fraud. Authentication can be considered a form of fraud detection in which the legitimacy of a user is verified and potential fraudsters can be detected before fraudulent acts are carried out. Effective authentication can enhance the data security of a system, thereby protecting digital data from unauthorized users.
[0021] In a typical eKYC process, a customer is asked to first take a photo of their identity document. Then, a photo of their face (i.e., a “selfie”) is taken. A face anti-spoofing method is then implemented to prevent false face verification by an attacker using a photo, video, or other substitute in place of the person’s face.
[0022] Current face anti-spoofing techniques can effectively detect screen captures, paper prints, and video replays. However, certain attacks can use a face image that is very similar to the face image of the initial registration process to attack the subsequent verification process. Current face anti-spoofing methods typically focus on identifying moire patterns or face similarity, and can not fully exploit available information such as background similarity. Verifying the background similarity of an image can help detect attacks using a face image that is similar to the face image of the initial registration process.
[0023] According to one embodiment, to reduce the success rate of attacks using a face image that is very similar to the face image of the initial registration process, a user authentication method can be implemented that involves authenticating the identity of a user through a combination of different authentication methods. The different authentication methods can include computing face similarity, background similarity, and moire patterns.
[0024] Embodiments described herein can involve an eKYC process that includes two general processes: a user registration process and a user authentication process. In the user registration process, a user can submit a photo of their identity document or a selfie photo as a user registration image. In the user authentication process, if a user has submitted a photo of their identity document as a user registration image, the user can submit a selfie photo as a user authentication image. In some implementations, if a user has submitted a selfie photo as a user registration image, the user can submit another selfie photo as a user authentication image.
[0025] As mentioned above, current face anti-spoofing methods can not fully exploit available information, such as background similarity. The techniques described herein produce one or more technical effects. In particular, by computing a similarity between a background image of a user enrollment image and a background image of a user authentication image, the user authentication method and system can reduce the success rate of attacks on eKYC processes, and can be particularly effective in identifying attacks that use a face image that is very similar to the face image in the enrollment process. If the background image of the user enrollment image and the background image of the user authentication image are determined to be similar, the user authentication image can be identified as an attack.
[0026] Furthermore, the user authentication method and system can authenticate a user by using, for example, comparing face similarity, comparing background similarity, and detecting various patterns of moire in the submitted photo for eKYC process, thereby providing higher accuracy in detecting attacks.
[0027] Figure 1 is a flowchart 100 illustrating an example of a user authentication method according to an embodiment. At step 102, a first face image and a first background image are extracted from a user enrollment image including the first face image and the first background image. At step 104, a second face image and a second background image are extracted from a user authentication image including the second face image and the second background image. At step 106, a first score (S1) associated with the user authentication image is generated using a trained image spoofing model. At step 108, a second score (S2) corresponding to a similarity between the first background image and the second background image is generated. At step 110, a third score (S3) corresponding to a similarity between the first face image and the second face image is generated. At step 112, the user is authenticated based on the first score (S1), the second score (S2), and the third score (S3).
[0028] According to an embodiment, the user can be authenticated in a case where S1 is lower than a first threshold, S2 is lower than a second threshold, and S3 is greater than a third threshold. The generated scores S1, S2, and S3 can be computed with a mathematical function. If the above conditions are satisfied, the user authentication image can be determined as a real image. Otherwise, the user authentication image can be determined as an attack image.
[0029] The first threshold, the second threshold, and the third threshold can be determined based on a receiver operating characteristic (ROC) curve, respectively. As a non-limiting example, the third threshold is set to 68. At this point of the ROC curve, the false acceptance rate is 1E-4, while the true acceptance rate is 99%.
[0030] The user registration image can be obtained in an initial user registration process, and the user authentication image can be obtained in a subsequent user authentication process. The user registration image can include a photo of the user's face or a photo of the user's identity-verification document taken in the initial user registration process. The user authentication image can include another photo of the user's face or another photo of the user's identity-verification document taken in the subsequent user authentication process.
[0031] Figure 2 An example of a user-submitted photo of a face 200 is shown. The photo of a face 200 can be a selfie photo taken by the user to submit in a user registration process or a user authentication process.
[0032] The step of extracting the first face image 202 and the first background image 204 from the user registration image can include applying a face detection method to the user registration image to generate a face detection box 206 that bounds the first face image 202, such that the area of the user registration image within the face detection box 206 corresponds to the first face image 202, and the area of the user registration image outside the face detection box 206 corresponds to the first background image 204. In other words, the first face image 202 can be obtained by cropping the area bounded by the face detection box 206. To obtain the first background image 204, the first face image 202 can then be removed, such that only the first background image 204 remains.
[0033] The step of extracting the second face image 202 and the second background image 204 from the user authentication image can include applying a face detection method to the user authentication image to generate another face detection box 206 that bounds the second face image 202, such that the area of the user authentication image within the other face detection box 206 corresponds to the second face image 202, and the area of the user authentication image outside the other face detection box 206 corresponds to the second background image 204. In other embodiments, a different face detection method can be used than the face detection method used in the step of extracting the first face image 202 and the first background image 204 from the user registration image. The second face image 202 can be obtained by cropping the area bounded by the face detection box 206. To obtain the second background image 204, the second face image 202 can then be removed, such that only the second background image 204 remains.
[0034] According to embodiments, the step of generating the second score (S2) can include performing a pixel-by-pixel comparison between the first background image and the second background image to determine a similarity between the first background image and the second background image. An image subtraction or pixel subtraction process can be used to subtract the digital values of the second background image from the digital values of the first background image to determine the similarity between the two images. Since each background image is an integer in the interval of 0 to 255, the absolute value can be obtained by subtraction. The similarity between the first background image and the second background image can be determined by comparing the absolute value obtained from the image subtraction with a predetermined threshold.
[0035] As mentioned above, and with reference to Figure 1 At step 106, a first score (S1) associated with the user authentication image is generated using the trained image spoofing model. The user authentication method can further include training the image spoofing model using a CNN with a normalized exponential function. For face anti-spoofing, the user authentication image can be sent to the trained image spoofing model to generate the first score (S1). The first score (S1) can then be compared to a predetermined first threshold. If the first score (S1) is greater than the predetermined first threshold, the user authentication image can be determined to be an attack image. The trained image spoofing model can be a binary classifier based on a convolutional neural network (CNN) that can be trained using a large dataset of live face images and spoof images to determine whether an image sent to it is a live image or a spoof image. In other implementations, a multi-class classifier based on a CNN can be used to generate the first score (S1).
[0036] The step of generating the third score (S3) can include extracting a first feature (F1) corresponding to the first face image using a trained CNN; extracting a second feature (F2) corresponding to the second face image using the trained CNN; and generating the third score (S3) according to a cosine similarity between the first feature (F1) and the second feature (F2). The trained CNN can be a trained image similarity model that has been trained with historical images to perform a face verification task. The similarity between the first feature (F1) and the second feature (F2) can be extracted and compared, respectively, to generate the third score (S3) based on the similarity between the first feature (F1) and the second feature (F2). In some implementations, the first feature (F1) and the second feature (F2) can be 256-dimensional feature vectors, and the cosine similarity can be used to measure the similarity between the first feature (F1) and the second feature (F2) to generate a value in the interval of -1 and 1.
[0037] Other embodiments of the user authentication method can include identifying a face image from the user enrollment image and the user authentication image using a face analysis method and obtaining the face image with a high degree of accuracy as possible. The face image can then be removed from the user enrollment image and the user authentication image to obtain respective background images. Embodiments can further include generating a face detection box for each of the user enrollment image and the user authentication image to extract the respective background images.
[0038] Figure 3 A schematic diagram of a computer system suitable for performing at least some steps of the user authentication method is shown.
[0039] The description of the computing system / computing device 300 is provided below by way of example only, and is not intended to be limiting.
[0040] As Figure 3 shown, the example computing device 300 includes a processor 304 for executing software routines. Although a single processor is shown for purposes of clarity, multiple processors can be included in the computing device 300. The processor 304 is connected to a communication infrastructure 306 to enable communications with other components of the computing device 300. The communication infrastructure 306 can include, for example, a communications bus, cross-over switch, or network.
[0041] The computing device 300 also includes a main memory 308, such as random access memory (RAM), and a secondary memory 310. The secondary memory 310 can include, for example, a hard disk drive 312 and / or a removable storage drive 314, which can include a magnetic tape drive, an optical disk drive, etc. The removable storage drive 314 reads from and / or writes to a removable storage unit 318 in a well-known manner. The removable storage unit 318 can include a magnetic tape, optical disk, etc. which is read by and written to by removable storage drive 314. As will be appreciated by persons skilled in the relevant art, the removable storage unit 318 includes computer readable storage media that stores computer executable program code instructions and / or data.
[0042] In alternative embodiments, the secondary memory 310 can additionally or alternatively include other similar devices for allowing computer programs or other instructions to be loaded into the computing device 300. Such devices can include, for example, a removable storage unit 322 and an interface 320. Examples of the removable storage unit 322 and the interface 320 include a program cartridge and cartridge interface, a removable memory chip (e.g., EPROM or PROM) and associated socket, and other removable storage units 322 and interfaces 320 which allow software and data to be transferred from the removable storage unit 322 to the computing device 300.
[0043] The computing device 300 also includes at least one communication interface 324. The communication interface 324 allows software and data to be transferred between computing device 300 and external devices via a communication path 326. In various embodiments, the communication interface 324 allows data to be transferred between computing device 300 and a data communication network, such as a public data or private data communication network. The communication interface 324 can be used to exchange data with other computing devices 300 that form a part of an interconnected computer network, such as the Internet. Examples of communication interfaces 324 can include a modem, a network interface card (such as an Ethernet card), a communications port, an antenna, etc. with associated circuitry, etc. The communication interface 324 can be wired or wireless. Software and data transferred via the communication interface 326 are in the form of signals, which can be electronic, electromagnetic, optical or other signals capable of being received by the communication interface 324. These signals are provided to the communication interface via the communication path 326.
[0044] Optionally, the computing device 300 also includes a display interface 302 that forwards graphics, text, and other data from the communication interface 324 (or from a frame buffer not shown) for display on the associated display 330 and an audio interface 432 that forwards audio data to the associated speaker 334 for playback.
[0045] As used herein, the term "computer program product" can refer, in part, to the removable storage unit 318, the removable storage unit 322, the hard disk installed in the hard disk drive 312, or a carrier wave carrying software embodied in the communication path 326 (wireless link or cable) to the communication interface 324. A computer readable storage medium refers to any non-transitory tangible storage medium that provides recorded instructions and / or data to a computing device 300 for execution and / or processing. Examples of such storage mediums include floppy disks, magnetic tape, CD-ROM, DVD, Blu-ray Disc™, hard disk drive, ROM, or integrated circuits, USB memory, magneto-optical disks, or computer readable cards such as PCMCIA cards, and the term should not be construed as being limited to just those TM ) examples of transitory or non-tangible computer readable transmission mediums that can also participate in the provision of software, application programs, instructions and / or data to the computing device 300 include radio or infra-red transmission channels as well as a network connection to another computer or networking device, and the Internet or Intranet communications using, e.g., E-mail transmission or FTP.
[0046] Computer programs (also referred to as computer program code) are stored in main memory 308 and / or secondary memory 310. Computer programs can also be received via communications interface 324. Such computer programs, when executed, enable the computing device 300 to perform one or more features of the embodiments discussed herein. In various embodiments, the computer programs, when executed, enable the processor 304 to perform the features of the embodiments described above. Accordingly, such computer programs represent controllers of the computer system 300.
[0047] The software can be stored in a computer program product and loaded into the computing device 300 using removable storage drive 314, hard disk drive 312 or interface 320. Alternatively, the computer program product can be downloaded to the computer system 300 over the communications path 326. The software, when executed, enables the computing device 300 to perform the functions as described herein of the embodiments.
[0048] It should be understood that Figure 3 The embodiments of the application are given by way of example only. Thus, in some embodiments, one or more features of the computing device 300 can be omitted. Also, in some embodiments, one or more features of the computing device 300 can be combined together. Additionally, in some embodiments, one or more features of the computing device 300 can be split into one or more constituent parts.
[0049] The term "configured to" is used herein with respect to systems, devices, and computer program components. With respect to a system of one or more computers configured to perform particular operations or actions, that the system has installed on it the software, firmware, hardware, or a combination thereof that in operation causes the system to perform the operations or actions. With respect to one or more computer programs configured to perform particular operations or actions, that the one or more programs include instructions that when executed by data processing apparatus cause the apparatus to perform the operations or actions. With respect to a special purpose logic circuit configured to perform particular operations or actions, that the circuit has electronic logic that performs the operations or actions.
[0050] Figure 4is a schematic diagram 400 illustrating an example of a user authentication system according to an embodiment. The user authentication system comprises an extraction device 402 configured to extract a first face image and a first background image from a user enrollment image comprising the first face image and the first background image. The extraction device 402 is further configured to extract a second face image and a second background image from a user authentication image comprising the second face image and the second background image. The user authentication system further comprises a first score generation device 404 configured to generate a first score (SI) associated with the user authentication image using a trained image spoofing model. The user authentication system further comprises a second score generation device 406 configured to generate a second score (S2) corresponding to a similarity between the first background image and the second background image. The user authentication system further comprises a third score generation device 408 configured to generate a third score (S3) corresponding to a similarity between the first face image and the second face image. In addition, the user authentication system comprises an authentication device 410 configured to authenticate the user based on the first score (SI), the second score (S2), and the third score (S3).
[0051] The authentication device 410 can be further configured to authenticate the user as passing in case that SI is below a first threshold, S2 is below a second threshold, and S3 is greater than a third threshold.
[0052] The first threshold, the second threshold, and the third threshold can be determined based on a receiver operating characteristic (ROC) curve, respectively.
[0053] The extraction device 402 can be further configured to apply a face detection method to the user enrollment image to generate a face detection box bounding the first face image, such that a region of the user enrollment image within the face detection box corresponds to the first face image and a region of the user enrollment image outside the face detection box corresponds to the first background image.
[0054] The extraction device 402 can be further configured to apply a face detection method to the user authentication image to generate another face detection box bounding the second face image, such that a region of the user authentication image within the other face detection box corresponds to the second face image and a region of the user authentication image outside the other face detection box corresponds to the second background image.
[0055] The second score generation device 406 can be further configured to perform a pixel- wise comparison between the first background image and the second background image to determine the similarity between the first background image and the second background image.
[0056] The image spoofing model can be trained using a CNN with a normalized exponential function.
[0057] The third score generating device 408 can also be configured to extract a first feature (F1) corresponding to the first face image using the trained CNN. The third score generating device 408 can also be configured to extract a second feature (F2) corresponding to the second face image using the trained CNN. Further, the third score generating device 408 can be configured to generate a third score (S3) based on a cosine similarity between the first feature (F1) and the second feature (F2).
[0058] Those skilled in the art will appreciate that numerous variations and / or modifications can be made to the present application as shown in the specific embodiments without departing from the spirit or scope of the application as broadly described. The present application, therefore, is not to be restricted except in the scope of the appended claims.
Claims
1. A user authentication method, comprising: extracting a first face image and a first background image from a user registration image comprising the first face image and the first background image; the user registration image being an image containing a user face captured at an initial user registration; extracting a second face image and a second background image from a user authentication image comprising the second face image and the second background image; the user authentication image being an image containing a user face captured in real time at a user authentication; generating a first score S1 associated with the user authentication image using a trained image spoofing model; generating a second score S2 corresponding to a similarity between the first background image and the second background image; generating a third score S3 corresponding to a similarity between the first face image and the second face image; and authenticating the user in real time based on the first score S1, the second score S2 and the third score S3; wherein S2 not lower than a second threshold value indicates that the first background image and the second background image are similar, and the user authentication fails if S2 is not lower than the second threshold value; the generating the second score S2 comprises: performing a pixel-by-pixel comparison between the first background image and the second background image, obtaining absolute values of each pixel difference value, and generating the S2 based on the absolute values of each pixel difference value to determine the similarity between the first background image and the second background image.
2. The method of claim 1, wherein, the user passes the authentication if S1 is lower than a first threshold value, S2 is lower than a second threshold value and S3 is greater than a third threshold value.
3. The method of claim 2, wherein, the first threshold value, the second threshold value and the third threshold value are determined based on a receiver operating characteristic curve, respectively. 4.The method of any one of the preceding claims 1-3, wherein the user registration image is obtained in an initial user registration process, and the user authentication image is obtained in a subsequent user authentication process; the user registration image comprises a photo of the user’s face or a photo of the user’s identity document taken in the initial user registration process; and the user authentication image comprises another photo of the user’s face or another photo of the user’s identity document taken in the subsequent user authentication process.
5. The method according to any of the preceding claims 1-3, wherein, extracting the first face image and the first background image from the user registration image comprises: applying a face detection method to the user registration image to generate a face detection box bounding the first face image, such that a region of the user registration image within the face detection box corresponds to the first face image, and a region of the user registration image outside the face detection box corresponds to the first background image.
6. The method of claim 5, wherein, extracting the second face image and the second background image from the user authentication image comprises: applying the face detection method to the user authentication image to generate another face detection box bounding the second face image, such that a region of the user authentication image within the another face detection box corresponds to the second face image, and a region of the user authentication image outside the another face detection box corresponds to the second background image.
7. The method of any of the preceding claims 1-3, further comprising: training the image spoofing model using a convolutional neural network with a normalized exponential function.
8. The method according to any of the preceding claims 1 - 3, wherein, generating the third score S3 comprises: extracting, using a trained convolutional neural network, first features F1 corresponding to the first face image; extracting, using the trained convolutional neural network, second features F2 corresponding to the second face image; and generating the third score S3 based on a cosine similarity between the first features F1 and the second features F2.
9. A user authentication system, comprising: an extracting device configured to: extract, from a user registration image comprising a first face image and a first background image, the first face image and the first background image; the user registration image being an image containing a user face captured at an initial user registration; and extract, from a user authentication image comprising a second face image and a second background image, the second face image and the second background image; the user authentication image being an image containing a user face captured in real time at a user authentication; a first score generating device configured to generate a first score S1 associated with the user authentication image using a trained image spoofing model; a second score generating device for generating a second score S2 corresponding to a similarity between the first background image and the second background image; a third score generating device for generating a third score S3 corresponding to a similarity between the first face image and the second face image; and an authentication device configured to authenticate the user in real time based on the first score S1, the second score S2 and the third score S3; wherein S2 not lower than a second threshold value indicates that the first background image and the second background image are similar, and in the case that S2 is not lower than the second threshold value, the user authentication fails; the generating the second score S2 comprises: performing a pixel-by-pixel comparison between the first background image and the second background image, obtaining absolute values of each pixel difference value, and generating the S2 based on the absolute values of each pixel difference value to determine the similarity between the first background image and the second background image.
10. The system of claim 9, wherein, the authentication device is further configured to: in the case that S1 is lower than a first threshold value, S2 is lower than a second threshold value and S3 is greater than a third threshold value, the user passes the authentication.
11. The system of claim 10, wherein, the first threshold value, the second threshold value and the third threshold value are determined based on a receiver operating characteristic curve, respectively.
12. The system of any one of claims 9 to 11, wherein, the extracting device is further configured to: applying a face detection method to the user enrollment image to generate a face detection box bounding the first face image, such that a region of the user enrollment image within the face detection box corresponds to the first face image and a region of the user enrollment image outside the face detection box corresponds to the first background image.
13. The system of claim 12, wherein, The extraction device is further configured to: apply the face detection method to the user authentication image to generate another face detection box bounding the second face image, such that a region of the user authentication image within the another face detection box corresponds to the second face image and a region of the user authentication image outside the another face detection box corresponds to the second background image.
14. The system of any one of claims 9 to 11, wherein, The image spoofing model is trained using a convolutional neural network that utilizes a normalized exponential function.
15. The system of any one of claims 9 to 11, wherein, The third score generation device is further configured to: extract, using a trained convolutional neural network, a first feature F1 corresponding to the first face image; extract, using the trained convolutional neural network, a second feature F2 corresponding to the second face image; and generate the third score S3 based on a cosine similarity between the first feature F1 and the second feature F2.
Citation Information
Patent Citations
Face recognition method, device and terminal
CN109325413A
Face recognition method and a recognition device,
CN109508694A
Photo background similarity clustering method based on convolutional neural network and computer
CN110569878A