Face Image Detection Method, Device, Readable Medium and Electronic Device
By extracting and analyzing pixel-side channel information in the high-frequency feature image of the face image, and using an image classifier to identify the tampered image, the problem of low recognition accuracy caused by tampering with the injected image in the face recognition system is solved, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202110578770.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-26
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-05-26
AI Technical Summary
Existing facial recognition systems are vulnerable to attacks from tampering with images, resulting in low recognition accuracy, and attackers can crack signatures or anti-counterfeiting watermarks through reverse engineering, resulting in an increased risk of misjudgment.
By extracting the high-frequency information of the image to be identified, the pixel side channel information in the high-frequency characteristic image is obtained, and the trained image classifier is used for analysis to determine whether the image is a normal real-face image collected by the authentication device in real time.
It improves the recognition accuracy of injected attack images during the face recognition process, ensures that the authenticated device can still be accurately recognized when it is invaded or cloned, enhances the security and reliability of the system, and does not require the hardware device to be modified, and the deployment cost is low.
Smart Images

Figure CN113762060B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of computers and image processing, and particularly relates to a face image detection method, device, readable medium, and electronic device. Background Art
[0002] Face recognition is a biometric identification technology that performs identity recognition based on a person's facial feature information. It requires relevant devices to collect face images in real time for analysis and processing to determine whether the user for face recognition is a legitimate user. However, there are attackers who tamper with and inject face images during the processes of face image acquisition, storage, processing, transmission, etc., in order to deceive the relevant detections of the face recognition system and achieve the purpose of disguising the identity of others for biometric authentication. Therefore, in order to improve the accuracy of the face recognition system, it is necessary to detect whether a face image is a tampered and injected image. Currently, there is a method of adding signatures or anti-counterfeiting watermarks to face images to prevent image tampering and injection. However, attackers can reverse the signatures or anti-counterfeiting watermarks based on software and hardware vulnerabilities, still making the face recognition system at risk of misjudgment.
[0003] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of this application. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0004] The purpose of this application is to provide a face image detection method, device, readable medium, and electronic device to solve the problem of low recognition accuracy of the face recognition system due to tampered and injected images.
[0005] Other features and advantages of this application will become apparent through the following detailed description, or be learned in part through the practice of this application.
[0006] According to one aspect of the embodiments of this application, a face image detection method is provided, including:
[0007] Obtain a to-be-recognized image for face authentication;
[0008] Extract the high-frequency information of the to-be-recognized image to obtain a high-frequency feature image of the to-be-recognized image. The high-frequency feature image carries pixel side-channel information, and the pixel side-channel information is the side-channel information retained at the pixel level after the to-be-recognized image undergoes image processing;
[0009] Extract and analyze the pixel side-channel information of the high-frequency feature image, and map the high-frequency feature image to a corresponding classification result based on the analysis result;
[0010] Determine whether the image to be recognized is a normal real face image for face authentication collected by an authentication device according to the classification result.
[0011] According to one aspect of the embodiments of the present application, a face image detection device is provided, including:
[0012] An image to be recognized acquisition module, configured to acquire an image to be recognized for face authentication;
[0013] A feature image extraction module, configured to extract high-frequency information of the image to be recognized to obtain a high-frequency feature image of the image to be recognized, where the high-frequency feature image carries pixel side-channel information, and the pixel side-channel information is side-channel information retained at the pixel level after the image to be recognized undergoes image processing;
[0014] An image classification module, configured to extract and analyze the pixel side-channel information of the high-frequency feature image, and map the high-frequency feature image to a corresponding classification result based on the analysis result;
[0015] An image detection module, configured to determine whether the image to be recognized is a normal real face image for face authentication collected by an authentication device according to the classification result.
[0016] In an embodiment of the present application, the high-frequency feature image includes a plurality of image block high-frequency feature maps; the feature image extraction module includes:
[0017] An image division unit, configured to divide the image to be recognized into a plurality of image blocks;
[0018] A high-frequency feature map extraction unit, configured to extract high-frequency information of the image blocks to obtain image block high-frequency feature maps.
[0019] In an embodiment of the present application, the classification result includes a normal real face image and an injected fake face image, and the image detection module is specifically configured to:
[0020] Determine a first quantity of image block high-frequency feature maps with a classification result of a normal real face image and a second quantity of image block high-frequency feature maps with a classification result of an injected fake face image;
[0021] If the first quantity is greater than the second quantity, determine that the image to be recognized is a normal real face image;
[0022] If the second quantity is greater than or equal to the first quantity, determine that the image to be recognized is an injected fake face image.
[0023] In an embodiment of the present application, the high-frequency feature map extraction unit is specifically configured to:
[0024] Perform low-pass filtering on the image block to obtain a low-frequency feature map of the image block;
[0025] Subtract the low-frequency feature map of the image block from the image block to obtain a high-frequency feature map of the image block carrying the high-frequency information of the image block.
[0026] In an embodiment of the present application, the high-frequency feature map extraction unit is specifically configured to:
[0027] Perform high-pass filtering on the image block to extract the high-frequency information of the image block and obtain a high-frequency feature map of the image block.
[0028] In an embodiment of the present application, the image classification module includes:
[0029] An image block classification unit, configured to analyze by extracting the pixel side-channel information of the high-frequency feature map of the image block through a trained image classifier, and map the high-frequency feature map of the image block to a corresponding classification result based on the analysis result, where the classification result includes a normal real face image and an injected fake face image.
[0030] In an embodiment of the present application, the image block classification unit is specifically configured to:
[0031] Analyze by extracting the pixel side-channel information of the high-frequency feature map of the image block through a trained image classifier to obtain the probability that the high-frequency feature map of the image block is a normal real face image;
[0032] If the probability is greater than or equal to a preset threshold, determine that the classification result of the high-frequency feature map of the image block is a normal real face image;
[0033] If the probability is less than the preset threshold, determine that the classification result of the high-frequency feature map of the image block is an injected fake face image.
[0034] In an embodiment of the present application, the device further includes:
[0035] An attack sample dataset acquisition module, configured to acquire an attack sample dataset, where the sample images in the attack sample dataset include injected attack images and face authentication images, the injected attack images are images obtained through an injection attack method, and the face authentication images are images collected by an authentication device;
[0036] A model training module, configured to build a classifier model and train the classifier model based on the attack sample dataset to obtain a trained image classifier.
[0037] In an embodiment of the present application, the attack sample dataset acquisition module includes:
[0038] An original face image acquisition unit, configured to acquire a plurality of original face images collected by one or more image acquisition devices;
[0039] A preprocessing unit, configured to preprocess the original face images to obtain a plurality of preprocessed images corresponding to the original face images, where the preprocessing is used to change the image parameters of the original face images;
[0040] An attack injection unit, configured to inject the preprocessed images according to an injection attack method to obtain a plurality of injection attack images;
[0041] A face authentication image acquisition unit, configured to acquire a plurality of face authentication images collected by an authentication device, and use the plurality of injection attack images and the plurality of face authentication images as an attack sample data set.
[0042] In an embodiment of the present application, the preprocessing unit is specifically configured to:
[0043] Perform an image modification operation on the original face images to obtain a plurality of modified images corresponding to the original face images, where the image modification operation includes one or more of compression, scaling, rotation, retouching, and beautification;
[0044] Upload the plurality of modified images to an information sharing platform;
[0045] Download a plurality of images from the information sharing platform to obtain a plurality of preprocessed images.
[0046] In an embodiment of the present application, the injection attack method includes one or more of APP layer injection, system layer injection, camera firmware injection, camera bus injection, memory injection, and image buffer injection.
[0047] In an embodiment of the present application, the model training module includes:
[0048] A sample high-frequency feature map extraction unit, configured to cut the sample images in the attack sample data set into a plurality of sample image blocks, and extract the high-frequency information of the sample image blocks to obtain a sample high-frequency feature map;
[0049] A model training unit, configured to build a classifier model and train the classifier model based on the plurality of sample high-frequency feature maps to obtain a trained image classifier.
[0050] The specific details of the face image detection device provided in each embodiment of the present application have been described in detail in the corresponding method embodiments, and will not be repeated here.
[0051] According to one aspect of the embodiments of the present application, there is provided a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processor, it implements the face image detection method in the above technical solution.
[0052] According to one aspect of the embodiments of the present application, there is provided an electronic device, which includes: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the face image detection method in the above technical solution by executing the executable instructions.
[0053] According to one aspect of the embodiments of the present application, there is provided a computer program product or a computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the face image detection method in the above technical solution.
[0054] In the technical solution provided by the embodiments of the present application, by extracting and analyzing the pixel-level side-channel information of the image to be recognized, it is determined whether the image to be recognized is a normal real face image collected by an authentication device for face authentication, effectively improving the recognition accuracy of injected attack images in the face recognition process, and being able to accurately recognize the authentication image even when the software and hardware of the authentication device are invaded or cloned, improving the security and reliability of face recognition; and applying the technical solution provided by the embodiments of the present application does not require modification of the hardware devices of the face recognition system, and has a low deployment cost.
[0055] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0057] Figure 1 Schematically shown is an exemplary system architecture block diagram applying the technical solution of the present application.
[0058] Figure 2 Schematically shown is an online face recognition system architecture diagram applying the technical solution of the present application.
[0059] Figure 3The flowchart of the face image detection method provided by an embodiment of the present application is schematically shown.
[0060] Figure 4 The flowchart of the extraction process of the high-frequency information of the image to be recognized is schematically shown.
[0061] Figure 5 The structural diagram of the image classifier is schematically shown.
[0062] Figure 6 The flowchart of obtaining the attack sample dataset is schematically shown.
[0063] Figure 7 The flowchart of the face image detection method provided by another embodiment of the present application is schematically shown.
[0064] Figure 8 The structural block diagram of the face image detection device provided by an embodiment of the present application is schematically shown.
[0065] Figure 9 The computer system structural block diagram of the electronic device suitable for implementing the embodiments of the present application is schematically shown. Detailed implementation manners
[0066] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0067] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.
[0068] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0069] The flowcharts shown in the accompanying drawings are merely illustrative and not necessarily inclusive of all content and operations / steps, nor are they necessarily to be executed in the order described. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0070] The technical solution of the embodiment of the present application applies a machine learning model to perform face image detection. Machine Learning (ML) is an interdisciplinary field that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent, and its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning. The machine learning model applied in the technical solution of the embodiment of the present application can be deployed in Figure 1 or Figure 2 the system architecture shown.
[0071] Figure 1 Schematically shows an exemplary system architecture block diagram applying the technical solution of the present application.
[0072] As Figure 1 shown, the system architecture 100 may include a terminal device 110, a network 120, and a server 130. The terminal device 110 may include various electronic devices such as smartphones, tablets, laptops, and desktop computers. The server 130 may be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The network 120 may be a communication medium of various connection types capable of providing a communication link between the terminal device 110 and the server 130. For example, it may be a wired communication link or a wireless communication link, and the wireless communication link includes but is not limited to: Bluetooth, WI-FI, Near Field Communication (NFC), and cellular mobile communication networks. Users can use the terminal device 110 to interact with the server 130 through the network 120 to receive or send messages, etc.
[0073] According to implementation requirements, the system architecture in the embodiments of the present application may have any number of terminal devices, networks, and servers. For example, the server 130 may be a server group composed of multiple server devices. Additionally, the technical solutions provided in the embodiments of the present application may be applied to the terminal device 110, may also be applied to the server 130, or may be jointly implemented by the terminal device 110 and the server 130. The present application does not make any special limitations in this regard.
[0074] For example, the terminal device 110 may serve as an authentication device, obtain an image to be recognized for face authentication, and then send the image to be recognized to the server 130 through the network 120. After receiving the image to be recognized, the server 130 extracts the high-frequency information of the image to be recognized to obtain a high-frequency feature image of the image to be recognized. The high-frequency feature image carries pixel side-channel information, which is the side-channel information retained at the pixel level after the image to be recognized undergoes image processing. Then, feature extraction and mapping processing are performed on the high-frequency feature image to obtain a classification result of the high-frequency feature image. Finally, it is determined whether the image to be recognized is a normal real face image collected by the authentication device for face authentication according to the classification result.
[0075] In an embodiment of the present application, after the server 130 determines whether the image to be recognized is a normal real face image collected by the authentication device for face authentication, it may return the recognition result to the terminal device 110 through the network 120. Furthermore, the terminal device 110 may display the detection result of the image to be recognized to the user.
[0076] In an embodiment of the present application, the face image detection method provided in the embodiments of the present application is executed by the server 130. The server 130 is used to receive the image to be recognized uploaded by the terminal device 110 and detect whether the image to be recognized is a normal real face image collected in real time by the terminal device 110. Correspondingly, the face image detection device is generally arranged in the server 130. However, those skilled in the art can easily understand that the face image detection method provided in the embodiments of the present application may also be executed by the terminal device 110. Correspondingly, the face image detection device may also be arranged in the terminal device 110. No special limitations are made in this exemplary embodiment. For example, in an exemplary embodiment, the terminal device 110 is used to obtain the image to be recognized and detect whether the image to be recognized is a normal real face image collected in real time.
[0077] In an embodiment of the present application, the face image detection method provided in the embodiments of the present application is executed by the server 130, and the server 130 is a node on the blockchain. Optionally, the face image detection device provided in the embodiments of the present application is a node on the blockchain. The user obtains the detection result of the image to be recognized by accessing the blockchain node through the terminal device 110.
[0078] Blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain, in essence, is a decentralized database, a series of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer.
[0079] The blockchain underlying platform can include processing modules such as user management, basic services, smart contracts, and operation monitoring. Among them, the user management module is responsible for the identity information management of all blockchain participants, including maintaining the generation of public and private keys (account management), key management, and the maintenance of the correspondence between the real identity of the user and the blockchain address (permission management). And under the authorization, it supervises and audits the transaction situations of certain real identities, and provides the rule configuration for risk control (risk control audit); the basic service module is deployed on all blockchain node devices, used to verify the validity of business requests, and after reaching a consensus on valid requests, record them on the storage. For a new business request, the basic service first performs interface adaptation parsing and authentication processing (interface adaptation), then encrypts the business information through a consensus algorithm (consensus management), after encryption, transmits it to the shared ledger completely and consistently (network communication), and records and stores it; the smart contract module is responsible for the registration and issuance of contracts, contract triggering, and contract execution. Developers can define contract logic through a certain programming language, publish it to the blockchain (contract registration), trigger the execution according to the logic of the contract terms, call keys or other events, complete the contract logic, and at the same time provide functions for contract upgrade and cancellation; the operation monitoring module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation during the product release process, and the visual output of the real-time state during product operation, such as: alarming, monitoring network conditions, monitoring the health status of node devices, etc.
[0080] Exemplarily, Figure 2 shows the architecture diagram of an online face recognition system applying the technical solution of the present application. As Figure 2 shown, the online face recognition system includes a face acquisition terminal 210, a network 220, and a face authentication cloud 230.
[0081] The face collection terminal 210 includes a camera module, a CPU (Central Processing Unit), a memory, a network card, and other peripherals. The camera module is used to collect images, which can be an RGB camera, an infrared camera, a depth camera, or other types of cameras. The camera module can also be a combination of multiple types of cameras. The output of the camera module can be multi-channel or single-channel. The CPU is the operation and control center of the face collection terminal 210, the memory is used for data storage of the face collection terminal 210, the network card enables the face collection terminal 210 to transmit data with the face authentication cloud 230 through the network 220, and other peripherals are devices corresponding to other functions of the face collection terminal 210, such as microphones, etc. The face collection terminal 210 can be a face payment machine deployed in a large supermarket or a portable device such as a mobile phone.
[0082] The face authentication cloud 230 includes an injected fake face detection module 231 and a face database 232. The injected fake face detection module 231 is used to implement the face image detection method provided in the embodiments of the present application. The face database 232 is used to store data required by the face recognition system, such as user face data for face comparison. In an embodiment of the present application, the face authentication cloud 230 can be a node on the blockchain, and the face database 232 is stored on the blockchain.
[0083] The face collection terminal 210 collects a user image for face authentication through the camera module, and transmits the user image to the injected fake face detection module 231 of the face authentication cloud 230 through the network 220. The user image may be attacked or tampered with during the transmission from the face collection terminal 210 to the injected fake face detection module 231. Therefore, the image obtained by the injected fake face detection module 231 is an image to be recognized. After obtaining the image to be recognized, the injected fake face detection module 231 processes it to obtain a high-frequency feature image carrying pixel side-channel information, where the pixel side-channel information is the side-channel information retained at the pixel level after the image to be recognized undergoes image processing; finally, the high-frequency feature image is classified, and finally, according to the classification result, it is determined whether the image to be recognized is a normal real face image collected in real time by the face collection terminal 210.
[0084] The following makes a detailed description of the face image detection method provided in the present application in combination with specific embodiments.
[0085] Figure 3 Schematically shows a flowchart of a face image detection method provided in an embodiment of the present application. This face image detection method can be executed by a server, and the server can be Figure 1 the server 130 shown in Figure 2The face authentication cloud 230 shown; this face image detection method can also be executed by a terminal device, which can be the terminal device 110 shown in Figure 1 or the face acquisition terminal 210 shown in Figure 2 .
[0086] As shown in Figure 3 , the face image detection method provided by an embodiment of the present application at least includes steps 310 to 340, specifically:
[0087] Step 310, obtain an image to be recognized for face authentication.
[0088] Specifically, the image to be recognized refers to the image obtained by the face recognition system during face authentication. Under normal circumstances, the image to be recognized is a face image of the authenticated user collected in real time by the authentication device, such as the user's mobile phone, the face payment machine in the supermarket, etc. However, in abnormal circumstances, the image to be recognized may be a face image after the real-time collected image by the authentication device is attacked or tampered with.
[0089] In an embodiment of the present application, the face image detection method provided by the embodiment of the present application can be combined with the live detection of the face recognition system. After the live detection is completed, a frame of image is extracted from the video stream of the live detection as the image to be recognized, and the face image detection is continued, so as to improve the accuracy and reliability of identity authentication.
[0090] Continue to refer to Figure 3 , step 320, extract the high-frequency information of the image to be recognized to obtain a high-frequency feature image of the image to be recognized. The high-frequency feature image carries pixel side-channel information, and the pixel side-channel information is the side-channel information retained at the pixel level after the image to be recognized undergoes image processing.
[0091] Specifically, the image will form pixel-level side-channel information after image processing, which is the pixel side-channel information. Image processing methods include image compression, rotation, scaling, demosaicing, interpolation, post-processing filters, injection attacks, etc. Image interpolation refers to given a pixel point, predicting the value of the pixel point according to the information of its surrounding pixel points. Image interpolation is commonly used in operations such as image scaling, rotation, and demosaicing. Injection attack refers to tampering with the face image during the processes of face image acquisition, storage, processing, and transmission, and injecting the tampered image into the face recognition system. The pixel side-channel information usually appears as high-frequency information. Therefore, by extracting the high-frequency information of the image to be recognized, a high-frequency feature image carrying pixel side-channel information can be obtained.
[0092] In an embodiment of the present application, an attacker breaks through the detection of a face recognition system through a face injection attack, and a face injection attack generally includes two steps: face image acquisition and face image injection. Face image acquisition refers to the attacker collecting photos containing the user's face from social media (such as Weibo, WeChat, etc.). The photos collected in this way usually go through relevant image processing by image processing software and social media clients or the cloud, such as compression, rotation, scaling, filtering, etc. Face image injection refers to the attacker injecting the collected face photos into the face recognition system through software and hardware methods, mainly including means such as software HOOK injection and bus injection. It can be seen that the face images injected into the face recognition system through the face injection attack method will have pixel-level side-channel information, while the images collected in real time by the authentication device for face authentication do not go through the numerous image processing operations of the face injection attack process, so they have no or very little pixel-level side-channel information. Therefore, by extracting the high-frequency information of the image to be recognized to analyze whether it contains these pixel-level side-channel information, it can be determined whether the image to be recognized is a face image injected by the attacker into the face recognition system or an image collected in real time by the authentication device for face authentication.
[0093] In an embodiment of the present application, the pixel side-channel information includes one or more of the following features: the blocking artifact introduced by image compression coding, the high-frequency loss caused by image compression coding, the pixel interpolation feature introduced by image rotation or scaling, and the secondary ISP and bus quantization noise caused by image injection attack. The blocking artifact is a phenomenon that discontinuities occur at the boundaries of blocks based on block-based transform coding algorithms (such as JPEG compression), resulting in defects in the reconstructed image at the block edges. High-frequency loss refers to the loss of high-frequency information of an image due to compression coding based on DCT (Discrete Cosine Transform). ISP (Image Signal Processing) is mainly used to process the output signal of the front-end image sensor to match image sensors of different manufacturers.
[0094] In an embodiment of the present application, the high-frequency information of the image to be recognized can be extracted through high-pass filtering to obtain a high-frequency feature image. High-pass filtering can be implemented through a high-pass filter or a neural network filter. Optionally, the image to be recognized can be first subjected to low-pass filtering to obtain the low-frequency feature image of the image to be recognized, and then the image to be recognized is subtracted from its low-frequency feature image, and the high-frequency information of the image to be recognized can be extracted to obtain a high-frequency feature image.
[0095] In an embodiment of the present application, when extracting the high-frequency information of the image to be recognized, the image to be recognized can also be block-processed, that is, the image to be recognized is divided into multiple image blocks, and then the high-frequency information of each image block is extracted. The high-frequency information of the image blocks forms an image block high-frequency feature map, and multiple image block high-frequency feature maps form the high-frequency feature image of the image to be recognized. The method of extracting the high-frequency information of the image blocks can be to directly perform high-pass filtering on the image blocks to obtain the image block high-frequency feature map, or to first perform low-pass filtering on the image blocks to obtain the image block low-frequency feature map, and then subtract the image block low-frequency feature map from the image blocks to obtain the image block high-frequency feature map.
[0096] In an embodiment of the present application, as Figure 4 shown, the extraction process of the high-frequency information of the image to be recognized is schematically shown. First, the image to be recognized 410 (i.e., the authentication image) is cut without coverage so that it is divided into multiple rectangular image blocks 420 with a width of W and a height of H. Then, low-pass filtering is performed on each image block 420 to obtain the image block low-frequency feature map 430. The image block low-frequency feature map 430 mainly includes the low-frequency information and content information of the image block 420. Then, the image block 420 is subtracted from the image block low-frequency feature map 430 to obtain the image block high-frequency feature map 440. The image block high-frequency feature map 440 carries the pixel-level side-channel information of the image block 420. This method of first performing low-pass filtering and then subtracting the image block low-frequency feature map from the image block to obtain the image block high-frequency feature map can make the pixel-level side-channel information carried by the image block high-frequency feature map more complete, and avoid the situation that some pixel-level side-channel information is directly filtered out by direct high-pass filtering.
[0097] Continue to refer to Figure 3 , step 330: Extract and analyze the pixel side-channel information of the high-frequency feature image, and map the high-frequency feature image to the corresponding classification result based on the analysis result.
[0098] Specifically, extract the pixel-level side-channel information carried in the high-frequency feature image, and map the high-frequency feature image to the corresponding image category based on the calculation and analysis of the pixel-level side-channel information to obtain the classification result of the high-frequency feature image. The analysis and processing of the pixel side-channel information of the high-frequency feature image and the mapping processing of the analysis result can be implemented by a trained image classifier.
[0099] In an embodiment of the present application, the classification results include two categories: normal real face images and injected fake face images. A normal real face image refers to an image used for face authentication collected in real time by an authentication device, and an injected fake face image refers to a tampered image injected by an attacker into a face recognition system.
[0100] In one embodiment of the present application, when the high-frequency feature image is a high-frequency feature map of multiple image patches, extracting and analyzing the pixel side-channel information of the high-frequency feature image means extracting and analyzing the pixel side-channel information of each high-frequency feature map of the image patch. Correspondingly, the classification result of each high-frequency feature map of the image patch is mapped based on the analysis result of each high-frequency feature map of the image patch.
[0101] In one embodiment of the present application, the pixel side-channel information of the high-frequency feature image or the high-frequency feature map of the image patch can be extracted and analyzed by a trained image classifier, and the high-frequency feature image or the high-frequency feature map of the image patch is mapped to the corresponding classification result based on the analysis result. The image classifier can be an image classifier based on deep learning methods, such as a convolutional neural network classifier; or an image classifier based on non-deep learning methods, such as a KNN (K-Nearest Neighbors) classifier, an SVM (Support Vector Machine) classifier, a Bayesian classifier, etc.
[0102] In one embodiment of the present application, when obtaining the classification result of the high-frequency feature map of the image patch, first, the pixel side-channel information of the high-frequency feature map of the image patch is extracted and analyzed by a trained image classifier to obtain the probability that the high-frequency feature map of the image patch is a normal real face image; then, the classification result of the high-frequency feature map of the image patch is determined according to the relationship between the probability and a preset threshold. Generally, the preset threshold is the minimum probability that the high-frequency feature map of the image patch needs to meet to be a normal real face image. Then, if the obtained probability is greater than or equal to the preset threshold, the classification result of the high-frequency feature map of the image patch is determined to be a normal real face image; if the obtained probability is less than the preset threshold, the classification result of the high-frequency feature map of the image patch is determined to be an injected fake face image.
[0103] In one embodiment of the present application, the method such as Figure 5 is used to extract and analyze the pixel side-channel information of the high-frequency feature map of the image patch, and the high-frequency feature map of the image patch is mapped to the corresponding classification result based on the analysis result. Figure 5 The image classifier shown is a convolutional neural network classifier, which includes 4 convolutional layers (Conv 2D), 2 pooling layers (Max Pooling), and 1 fully connected layer (Full Connected). The size of the convolutional kernel of each convolutional layer is 3×3. The first 2 convolutional layers have 32 nodes, and the last 2 convolutional layers have 64 nodes. The filter size of each pooling layer is 2×2. The fully connected layer has 256 nodes. The output of each convolutional layer uses the RELU function, the output of each pooling layer uses the DROPOUT function, and the SIGMOID activation function is used after the fully connected layer. The high-frequency feature map of the image patch is input to Figure 5In the convolutional neural network classifier shown, features are extracted through the calculations of several convolutional layers and pooling layers. This feature contains pixel-level side-channel information. Then, the fully connected layer uses the SIGMOID activation function on the extracted features to obtain a probability, which is the probability that the high-frequency feature map of the image patch is a normal real face image. Finally, based on the comparison between this probability and a preset threshold, it is mapped to two classification results, namely class 1 (the injected fake face, i.e., the injected fake face image) and class 2 (the normal real face, i.e., the normal real face image). For example, if the preset threshold is set to 0.5 and the probability output by the SIGMOID activation function is 0.4, it is mapped to class 1, indicating that the high-frequency feature map of the image patch is an injected fake face image.
[0104] In one embodiment of the present application, before analyzing the pixel side-channel information of the high-frequency feature map of the image patch through the trained image classifier and mapping the high-frequency feature map of the image patch to the corresponding classification result based on the analysis result, it further includes building a classifier model and training it to obtain a trained image classifier, specifically including: obtaining an attack sample dataset, where the attack sample dataset includes injected attack images and face authentication images. The injected attack image is an image obtained through an injection attack method, and the face authentication image is an image collected by an authentication device; building a classifier model and training the classifier model based on the attack sample dataset to obtain a trained image classifier.
[0105] Specifically, the images in the attack sample dataset are sample images, which consist of injected attack images and face authentication images. Among them, the injected attack image is a positive sample of the dataset, and the face authentication image is a negative sample of the dataset. The injected attack image is an image obtained through an injection attack method and is an image that an attacker may use. The injected attack image can be obtained by simulating the attacker's attack path on a normal image, or it can be an injected attack image obtained in actual business, or an injected attack image in a public dataset (such as the Deep Fake dataset). The face authentication image can be obtained by an authentication device, such as a face image directly obtained through the camera module of the authentication device. After obtaining the attack sample dataset, build a classifier model and train the classifier model with this attack sample dataset to obtain a trained image classifier.
[0106] In one embodiment of the present application, training the classifier model with the attack sample dataset to obtain an image classifier specifically includes: cutting the sample images in the attack sample dataset into multiple sample image patches, and extracting the high-frequency information of the sample image patches to obtain sample high-frequency feature maps; building a classifier model and training the classifier model based on the multiple sample high-frequency feature maps to obtain a trained image classifier.
[0107] Specifically, each sample image is cut into multiple sample image patches, and then the high-frequency information of each sample image patch is extracted to form a sample high-frequency feature map. The extraction of the high-frequency information of the sample image patch can refer to Figure 4 the high-frequency information extraction process shown in. First, the sample image patch is low-pass filtered to obtain a sample low-frequency feature map, and then the sample image patch is subtracted from the sample low-frequency feature map to obtain a sample high-frequency feature map. After obtaining the sample high-frequency feature map, it is labeled according to the sample image category of the sample high-frequency feature map. The sample image category of the sample high-frequency feature map refers to whether the sample high-frequency feature map is extracted from an injection attack image or a face authentication image. If the sample high-frequency feature map is extracted from an injection attack image, it is labeled with an injection attack image label; if the sample high-frequency feature map is extracted from a face authentication image, it is labeled with a face authentication image label.
[0108] The constructed classifier model can refer to Figure 5 the model structure shown in. The sample high-frequency feature map is input into the classifier model, and the classifier model will output the predicted image category of the sample high-frequency feature map, that is, predict whether the sample high-frequency feature map is an injection attack image or a face authentication image. During the model training process, the difference between the predicted image category output by the classifier model and the label of the sample high-frequency feature map is used as the loss function, and the model parameters are updated through gradient backpropagation until the loss function meets the requirements, and a trained image classifier is obtained.
[0109] In an embodiment of the present application, as Figure 6 shown, the acquisition method of the attack sample data set at least includes steps 610 to 640, specifically:
[0110] Step 610: Obtain a plurality of original face images collected by one or more image acquisition devices.
[0111] Specifically, the image acquisition device can be any device capable of acquiring images, such as a mobile phone, a camera, etc. It should be noted that the image acquisition device is not necessarily an authentication device. The original face image is an image containing a face collected by one or more image acquisition devices, such as a user's self-taken image. Preferably, the original face image is preferably a frontal face image of a person taken by the image acquisition device in a well-lit environment.
[0112] Step 620: Preprocess the original face images to obtain a plurality of preprocessed images corresponding to the original face images. The preprocessing is used to change the image parameters of the original face images.
[0113] Specifically, preprocessing the original face image means performing some image processing operations on the original face image, mainly used to modify image parameters such as image compression ratio, scaling scale, rotation angle, etc. Multiple preprocessed images are formed after preprocessing the original face image.
[0114] In an embodiment of the present application, preprocessing the original face image specifically includes: performing an image modification operation on the original face image to obtain multiple modified images corresponding to the original face image, and the image modification operation includes one or more of compression, scaling, rotation, image retouching, and beautification; uploading the multiple modified images to an information sharing platform; and downloading multiple images from the information sharing platform to obtain multiple preprocessed images.
[0115] Specifically, first perform an image modification operation on the original face image to obtain a modified image, and the image modification operation such as compression, scaling, rotation, image retouching, beautification, etc. Each type of image modification operation can take multiple image parameters. For example, when performing compression processing on the original face image, it can be compressed according to JEPG compression ratios of 100, 95, 90, 85, 80, 75, 70, 65, 60, 55, etc.; when performing scaling processing on the original face image, it can be scaled according to scaling scales of 50%, 60%, 70%, 80%, 90%, 100%, 110%, 120%, 130%, 140%, 150%, etc.; when performing rotation processing on the original face image, it can be rotated according to rotation angles of ±5°, ±10°, ±15°, ±20°, ±25°, ±30°, ±35°, ±40°, ±45°, ±50°, etc.; when performing beautification processing on the original face image, it can be beautified by adding different types of beauty filters to the original face image. The modified image can be formed by the original face image through one image modification operation or through multiple image modification operations. For example, scale the original face image according to a scaling scale of 50% to obtain a modified image, or scale the original face image according to a scaling scale of 50% and then compress it according to a JEPG compression ratio of 95 to obtain a modified image.
[0116] After uploading the modified image obtained through the image modification operation to the information sharing platform, download the image from the information sharing platform to obtain the required preprocessed image. The information sharing platform can be one or more of platforms such as WeChat, Weibo, Douyin, Zhihu, Facebook, Twitter, Instagram, Flickr, etc. When uploading the modified image to the information sharing platform, you can choose to upload the original image or upload it after compression. In this way, the face image acquisition step in the face injection attack can be simulated.
[0117] Step 630: Inject the preprocessed image according to the injection attack method to obtain multiple injected attack images.
[0118] Specifically, injecting the preprocessed image according to the injection attack method is equivalent to imitating the face image injection step in the face injection attack. Inject the preprocessed image into the face recognition system through the injection attack method to obtain the injected attack image. The injection attack method includes one or more of APP layer injection, system layer injection, camera firmware injection, camera bus injection, memory injection, and image buffer injection.
[0119] Step 640: Obtain multiple face authentication images collected by the authentication device, and use the multiple injected attack images and the multiple face authentication images as an attack sample data set.
[0120] Specifically, the face authentication image is an image collected by the authentication device for face authentication. Use the multiple injected attack images as positive samples and the multiple face authentication images as negative samples, and combine the two to form an attack sample data set.
[0121] Continue to refer to Figure 3 , step 340: Determine whether the image to be recognized is a normal real face image collected by the authentication device for face authentication according to the classification result.
[0122] Specifically, the category of the image to be recognized is consistent with the category of its high-frequency feature image. According to the classification result of the high-frequency feature image, it can be directly determined whether the image to be recognized is a normal real face image collected by the authentication device for face authentication. For example, if the high-frequency feature image is a normal real face image, it means that the image to be recognized is a normal real face image collected by the authentication device for face authentication; if the high-frequency feature image is an injected fake face image, it means that the image to be recognized is an injected fake face image injected by the attacker.
[0123] In an embodiment of the present application, when the image to be recognized is divided into multiple image blocks, it is determined whether the image to be recognized is a normal real face image collected by the authentication device for face authentication through the voting result of the classification results of the high-frequency feature maps of the multiple image blocks, and the classification result with the most high-frequency feature maps of the image blocks is used as the classification result of the image to be recognized. Specifically, count the first number of high-frequency feature maps of the image blocks with the classification result of normal real face images and the second number of high-frequency feature maps of the image blocks with the classification result of injected fake face images; if the first number is greater than the second number, determine that the image to be recognized is a normal real face image; if the second number is greater than or equal to the first number, determine that the image to be recognized is an injected fake face image.
[0124] In the technical solution provided by the embodiment of the present application, by extracting and analyzing the pixel-level side-channel information of the image to be recognized, it is determined whether the image to be recognized is a normal real face image for face authentication collected by an authentication device, effectively improving the recognition accuracy of injected attack images during the face recognition process, and accurately recognizing the authentication image even when the software and hardware of the authentication device are invaded or cloned, improving the security and reliability of face recognition; and applying the technical solution provided by the embodiment of the present application does not require modification of the hardware device of the face recognition system, and the deployment cost is low.
[0125] Reference Figure 7 , schematically shows a flowchart of a face image detection method provided by another embodiment of the present application. As Figure 7 shown, the face image detection method provided by the embodiment of the present application includes steps S1 to S8, specifically:
[0126] S1. Obtain a plurality of original face images collected by one or more image acquisition devices.
[0127] Specifically, the image acquisition device can be any device capable of acquiring images, such as a mobile phone, a camera, etc. It should be noted that the image acquisition device is not necessarily the authentication device. For example, the authentication device is the user's mobile phone, and the image acquisition device can be one or more of the user's mobile phone, camera, other people's mobile phones, and other image acquisition devices. Preferably, the original face image is preferably a frontal face image of a person taken by the image acquisition device in an environment with good lighting. The specific details of this step can refer to the relevant description of the foregoing step 610, and will not be elaborated here.
[0128] S2. Perform an image modification operation on the original face image to change the image parameters of the original face image, and obtain a modified image.
[0129] Specifically, in this step, an image modification operation is performed on the original face image obtained in step S1 to change the image parameters of the original face image and obtain a modified image. The image modification operations include compression, scaling, rotation, image retouching, beauty enhancement, etc. The image modification operation can be one operation or a combination of multiple operations. For example, the original face image can be compressed according to JEPG compression ratios of 100, 95, 90, 85, 80, 75, 70, 65, 60, 55, etc.; the original face image can be scaled according to scaling scales of 50%, 60%, 70%, 80%, 90%, 100%, 110%, 120%, 130%, 140%, 150%, etc.; the original face image can be rotated according to rotation angles of ±5°, ±10°, ±15°, ±20°, ±25°, ±30°, ±35°, ±40°, ±45°, ±50°, etc.; various types of beauty filters can be added to the original face image that has undergone the foregoing image modification operations. For the specific details of this step, reference can be made to the relevant description of the foregoing step 620, and no further elaboration will be provided here.
[0130] S3. Share the modified image through an information sharing platform, and then download the shared image from the information sharing platform to obtain a preprocessed image.
[0131] Specifically, the information sharing platform can be a social network or instant messaging software, such as platforms like WeChat, Weibo, Douyin, Zhihu, Facebook, Twitter, Instagram, Flickr, etc. The information sharing platform for sharing can be one or more of them. Upload the modified image obtained in step S2 to the information sharing platform and then download it. The obtained image is the preprocessed image, which is equivalent to the picture obtained in the face image acquisition step in the simulated face injection attack. For the specific details of this step, reference can be made to the relevant description of the foregoing step 620, and no further elaboration will be provided here.
[0132] S4. Inject the modified image according to different injection attack methods to obtain an injection attack image.
[0133] Specifically, this step simulates the face image injection step in the face injection attack. Inject the preprocessed image into the face recognition system through the injection attack method to obtain the injected photo, that is, the injection attack image. The injection attack methods include one or more of APP layer injection, system layer injection, camera firmware injection, camera bus injection, memory injection, and image buffer injection. For the specific details of this step, reference can be made to the relevant description of the foregoing step 630, and no further elaboration will be provided here.
[0134] S5. Use the injection attack image as the positive sample of the dataset and the face authentication image collected by the authentication device as the negative sample of the dataset to construct an attack sample dataset.
[0135] Specifically, the sample images in the attack sample dataset include two categories: face authentication images and injection attack images. The face authentication images are the normal face-swiping authentication images collected by the authentication device, which are the negative samples of the dataset. The injection attack images are the images obtained by simulating face injection attacks in the previous steps, which are the positive samples of the dataset. For the specific details of this step, reference can be made to the relevant description of the previous step 640, and no more elaboration will be made here.
[0136] S6. Cut the sample images in the attack sample dataset into multiple sample image blocks, and extract the high-frequency information of the sample image blocks to obtain a sample high-frequency feature map.
[0137] Specifically, divide the sample images in the attack sample dataset into multiple image blocks, extract the high-frequency information for each image block to obtain a sample high-frequency feature map. For the extraction of the high-frequency information of the image block, first perform low-pass filtering on the image block to obtain the sample low-frequency feature map of the image block, and then subtract the sample low-frequency feature map of the image block from the image block to obtain the sample high-frequency feature map. It is also possible to directly perform high-pass filtering on the image block to obtain the sample high-frequency feature map. After obtaining the sample high-frequency feature map, label it according to whether the sample high-frequency feature map is a face authentication image or an injection attack image. For the specific details of this step, reference can be made to the relevant description of the previous step 330, and no more elaboration will be made here.
[0138] S7. Train a convolutional neural network model based on the sample high-frequency feature map to obtain a trained convolutional neural network classifier.
[0139] Specifically, first build a convolutional neural network classifier model, and then train the convolutional neural network classifier model through the sample high-frequency feature map to obtain a trained convolutional neural network classifier. Reference can be made to Figure 5 the model structure shown to build a convolutional neural network classifier model and train the convolutional neural network classifier model through the sample high-frequency feature map. During the training process, use the difference between the predicted category of the model and the label of the sample high-frequency feature map as the loss function for gradient backpropagation to update the model parameters. When the loss function meets the conditions, obtain a trained convolutional neural network classifier. For the specific details of this step, reference can be made to the relevant description of the previous step 330, and no more elaboration will be made here.
[0140] S8. Obtain the image to be recognized for face authentication, divide the image to be recognized into multiple image blocks, and extract the high-frequency feature map of the image block carrying pixel side-channel information; obtain the classification result of the high-frequency feature map of the image block through the trained convolutional neural network classifier, and vote and summarize the classification results of all the high-frequency feature maps of the image blocks to determine the detection result of the image to be recognized.
[0141] Specifically, when a user is authenticated, the face image used for authentication is divided into multiple image blocks, and the high-frequency information of each image block is extracted to form an image block high-frequency feature map, which carries pixel-level side-channel information. The convolutional neural network classifier obtained through step S7 extracts and analyzes the pixel-level side-channel information in the image block high-frequency feature map and outputs the classification result of the image block high-frequency feature map. Finally, according to the classification results of all the image block high-frequency feature maps, the classification result with the most image block high-frequency feature maps is used as the classification result of the image to be recognized, so as to determine whether the face image used for authentication is a normal real face image collected by the authentication device for face authentication. The specific details of this step can refer to the relevant descriptions in the foregoing steps 310 to 340, and will not be elaborated here.
[0142] It should be noted that although the steps of the method in this application are described in a specific order in the drawings, this does not require or imply that these steps must be executed in that specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.
[0143] The following introduces the device embodiments of this application, which can be used to execute the face image detection method in the above embodiments of this application. Figure 8 Schematically shows the structural block diagram of the face image detection device provided by the embodiments of this application. As Figure 8 shown, the face image detection device provided by the embodiments of this application includes:
[0144] An image to be recognized acquisition module 810, configured to acquire an image to be recognized for face authentication;
[0145] A feature image extraction module 820, configured to extract the high-frequency information of the image to be recognized to obtain a high-frequency feature image of the image to be recognized, where the high-frequency feature image carries pixel side-channel information, and the pixel side-channel information is side-channel information retained at the pixel level after the image to be recognized undergoes image processing;
[0146] An image classification module 830, configured to extract and analyze the pixel side-channel information of the high-frequency feature image, and map the high-frequency feature image to a corresponding classification result based on the analysis result;
[0147] An image detection module 840, configured to determine whether the image to be recognized is a normal real face image collected by the authentication device for face authentication according to the classification result.
[0148] In an embodiment of this application, the high-frequency feature image includes multiple image block high-frequency feature maps; the feature image extraction module 820 includes:
[0149] An image partitioning unit for partitioning the image to be recognized into a plurality of image blocks;
[0150] A high-frequency feature map extraction unit for extracting the high-frequency information of the image block to obtain a high-frequency feature map of the image block.
[0151] In an embodiment of the present application, the classification result includes a normal genuine face image and an injected fake face image, and the image detection module 840 is specifically configured to:
[0152] Determine a first quantity of high-frequency feature maps of image blocks with a classification result of a normal genuine face image and a second quantity of high-frequency feature maps of image blocks with a classification result of an injected fake face image;
[0153] If the first quantity is greater than the second quantity, determine that the image to be recognized is a normal genuine face image;
[0154] If the second quantity is greater than or equal to the first quantity, determine that the image to be recognized is an injected fake face image.
[0155] In an embodiment of the present application, the high-frequency feature map extraction unit is specifically configured to:
[0156] Perform low-pass filtering on the image block to obtain a low-frequency feature map of the image block;
[0157] Subtract the low-frequency feature map of the image block from the image block to obtain a high-frequency feature map of the image block carrying the high-frequency information of the image block.
[0158] In an embodiment of the present application, the high-frequency feature map extraction unit is specifically configured to:
[0159] Perform high-pass filtering on the image block to extract the high-frequency information of the image block and obtain a high-frequency feature map of the image block.
[0160] In an embodiment of the present application, the image classification module 830 includes:
[0161] An image block classification unit for analyzing by extracting the pixel side-channel information of the high-frequency feature map of the image block through a trained image classifier, and mapping the high-frequency feature map of the image block to a corresponding classification result based on the analysis result, where the classification result includes a normal genuine face image and an injected fake face image.
[0162] In an embodiment of the present application, the image block classification unit is specifically configured to:
[0163] Analyze by extracting the pixel side-channel information of the high-frequency feature map of the image block through a trained image classifier to obtain the probability that the high-frequency feature map of the image block is a normal genuine face image;
[0164] If the probability is greater than or equal to a preset threshold, determine that the classification result of the high-frequency feature map of the image block is a normal genuine face image;
[0165] If the probability is less than the preset threshold, determine that the classification result of the high-frequency feature map of the image block is an injected fake face image.
[0166] In an embodiment of the present application, the apparatus further includes:
[0167] An attack sample dataset acquisition module, configured to acquire an attack sample dataset, where the sample images in the attack sample dataset include injected attack images and face authentication images, the injected attack images are images obtained through an injection attack method, and the face authentication images are images collected by an authentication device;
[0168] A model training module, configured to build a classifier model and train the classifier model based on the attack sample dataset to obtain a trained image classifier.
[0169] In an embodiment of the present application, the attack sample dataset acquisition module includes:
[0170] An original face image acquisition unit, configured to acquire a plurality of original face images collected by one or more image acquisition devices;
[0171] A preprocessing unit, configured to preprocess the original face images to obtain a plurality of preprocessed images corresponding to the original face images, where the preprocessing is used to change the image parameters of the original face images;
[0172] An attack injection unit, configured to inject the preprocessed images in an injection attack manner to obtain a plurality of injected attack images;
[0173] A face authentication image acquisition unit, configured to acquire a plurality of face authentication images collected by an authentication device, and use the plurality of injected attack images and the plurality of face authentication images as an attack sample dataset.
[0174] In an embodiment of the present application, the preprocessing unit is specifically configured to:
[0175] Perform an image modification operation on the original face images to obtain a plurality of modified images corresponding to the original face images, where the image modification operation includes one or more of compression, scaling, rotation, retouching, and beautification;
[0176] Upload the plurality of modified images to an information sharing platform;
[0177] Download a plurality of images from the information sharing platform to obtain a plurality of preprocessed images.
[0178] In one embodiment of the present application, the injection attack methods include one or more of APP layer injection, system layer injection, camera firmware injection, camera bus injection, memory injection, and image buffer injection.
[0179] In one embodiment of the present application, the model training module includes:
[0180] A sample high-frequency feature map extraction unit, configured to cut the sample images in the attack sample dataset into multiple sample image blocks, and extract the high-frequency information of the sample image blocks to obtain a sample high-frequency feature map;
[0181] A model training unit, configured to build a classifier model and train the classifier model based on multiple sample high-frequency feature maps to obtain a trained image classifier.
[0182] The specific details of the face image detection device provided in each embodiment of the present application have been described in detail in the corresponding method embodiments, and will not be repeated here.
[0183] Figure 9 Schematically shown is a computer system block diagram of an electronic device for implementing the embodiments of the present application.
[0184] It should be noted that Figure 9 The computer system 900 of the shown electronic device is only an example, and should not bring any limitations to the functions and usage scope of the embodiments of the present application.
[0185] As Figure 9 shown, the computer system 900 includes a central processing unit 901 (Central Processing Unit, CPU), which can perform various appropriate actions and processes according to the program stored in the read-only memory 902 (Read-Only Memory, ROM) or the program loaded from the storage section 908 into the random access memory 903 (Random Access Memory, RAM). In the random access memory 903, various programs and data required for system operation are also stored. The central processing unit 901, the read-only memory 902, and the random access memory 903 are connected to each other through a bus 904. The input / output interface 905 (Input / Output interface, that is, I / O interface) is also connected to the bus 904.
[0186] The following components are connected to the input / output interface 905: an input section 906 including a keyboard, a mouse, etc.; an output section 907 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a local area network card, a modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read from the same can be installed into the storage section 908 as needed.
[0187] Specifically, according to an embodiment of the present application, the processes described in each of the method flowcharts can be implemented as computer software programs. For example, an embodiment of the present application includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the central processing unit 901, various functions defined in the system of the present application are executed.
[0188] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0189] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0190] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more of the above-described modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0191] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0192] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application.
[0193] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A face image detection method, characterized in that, Including: Obtain an image to be recognized for face authentication; Divide the image to be recognized into multiple image patches; Extract the high-frequency information of each of the image patches to obtain an image patch high-frequency feature map corresponding to each of the image patches. The image patch high-frequency feature image carries pixel side-channel information, and the pixel side-channel information is the side-channel information retained at the pixel level after the image to be recognized undergoes image processing; Analyze the pixel side-channel information of each of the image patch high-frequency feature images through a trained image classifier, and map each of the image patch high-frequency feature images to a corresponding classification result based on the analysis result; the classification result includes a normal genuine face image and an injected fake face image; Determine whether the image to be recognized is a normal genuine face image collected by the authentication device for face authentication according to the multiple classification results.
2. The face image detection method according to claim 1, wherein The determining whether the image to be recognized is a normal genuine face image collected by the authentication device for face authentication according to the multiple classification results includes: Determine a first quantity of the image patch high-frequency feature maps with the classification result of a normal genuine face image and a second quantity of the image patch high-frequency feature maps with the classification result of an injected fake face image; If the first quantity is greater than the second quantity, determine that the image to be recognized is a normal genuine face image; If the second quantity is greater than or equal to the first quantity, determine that the image to be recognized is an injected fake face image.
3. The face image detection method according to claim 1, wherein, The extracting the high-frequency information of each of the image patches to obtain an image patch high-frequency feature map corresponding to each of the image patches includes: Perform low-pass filtering on the image patch to obtain an image patch low-frequency feature map; Subtract the image patch low-frequency feature map from the image patch to obtain an image patch high-frequency feature map carrying the high-frequency information of the image patch.
4. The face image detection method according to claim 1, wherein The extracting the high-frequency information of each of the image patches to obtain an image patch high-frequency feature map corresponding to each of the image patches includes: Perform high-pass filtering on the image patch to extract the high-frequency information of the image patch and obtain an image patch high-frequency feature map.
5. The face image detection method according to claim 1, characterized in that, The analyzing the pixel side-channel information of each of the image patch high-frequency feature images through a trained image classifier and mapping each of the image patch high-frequency feature images to a corresponding classification result based on the analysis result includes: Analyze the pixel side-channel information of the image patch high-frequency feature map through a trained image classifier to obtain the probability that the image patch high-frequency feature map is a normal genuine face image; If the probability is greater than or equal to a preset threshold, determine that the classification result of the image patch high-frequency feature map is a normal genuine face image; If the probability is less than the preset threshold, determine that the classification result of the image patch high-frequency feature map is an injected fake face image.
6. The face image detection method according to claim 5, wherein Before analyzing the pixel side-channel information of each of the image patch high-frequency feature images through a trained image classifier and mapping each of the image patch high-frequency feature images to a corresponding classification result based on the analysis result, the method further includes: Obtain an attack sample dataset, where the sample images in the attack sample dataset include injection attack images and face authentication images. The injection attack images are images obtained through injection attack methods, and the face authentication images are images collected by authentication devices. Build a classifier model and train the classifier model based on the attack sample dataset to obtain a trained image classifier.
7. The face image detection method according to claim 6, wherein The obtaining of the attack sample dataset includes: Obtain multiple original face images collected by one or more image acquisition devices. Preprocess the original face images to obtain multiple preprocessed images corresponding to the original face images. The preprocessing is used to change the image parameters of the original face images. Inject the preprocessed images according to the injection attack method to obtain multiple injection attack images. Obtain multiple face authentication images collected by authentication devices, and use the multiple injection attack images and the multiple face authentication images as the attack sample dataset.
8. The face image detection method according to claim 7, characterized in that, The preprocessing of the original face images to obtain multiple preprocessed images corresponding to the original face images includes: Perform image modification operations on the original face images to obtain multiple modified images corresponding to the original face images. The image modification operations include one or more of compression, scaling, rotation, retouching, and beautification. Upload the multiple modified images to an information sharing platform. Download multiple images from the information sharing platform to obtain multiple preprocessed images.
9. The face image detection method according to claim 7, wherein, The injection attack methods include one or more of APP layer injection, system layer injection, camera firmware injection, camera bus injection, memory injection, and image buffer injection.
10. The face image detection method according to claim 6, characterized in that The building of the classifier model and training the classifier model based on the attack sample dataset to obtain a trained image classifier includes: Cut the sample images in the attack sample dataset into multiple sample image blocks, and extract the high-frequency information of the sample image blocks to obtain a sample high-frequency feature map. Build a classifier model and train the classifier model based on the multiple sample high-frequency feature maps to obtain a trained image classifier.
11. A face image detection device, characterized in that, It includes: A to-be-recognized image acquisition module, which is used to acquire a to-be-recognized image for face authentication. A feature image extraction module, which is used to divide the to-be-recognized image into multiple image blocks; extract the high-frequency information of each image block to obtain an image block high-frequency feature map corresponding to each image block. The image block high-frequency feature image carries pixel side-channel information, and the pixel side-channel information is the side-channel information retained at the pixel level after the to-be-recognized image undergoes image processing. An image classification module, which is used to analyze the pixel side-channel information of each image block high-frequency feature image through the trained image classifier, and map each image block high-frequency feature image to the corresponding classification result based on the analysis result; the classification results include normal genuine face images and injected fake face images. An image detection module, which is used to determine whether the to-be-recognized image is a normal genuine face image collected by an authentication device for face authentication according to the multiple classification results.
12. A computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the face image detection method according to any one of claims 1 to 10.
13. An electronic device, characterized in that, Comprising: A processor; And A memory for storing executable instructions of the processor; Wherein the processor is configured to execute the face image detection method according to any one of claims 1 to 10 by executing the executable instructions.
14. A computer program product, characterized in that, The computer program product includes computer instructions, and the computer instructions are stored in a computer-readable storage medium; The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the face image detection method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Face image processing method and device, electronic equipment and computer readable storage medium
CN108830892A
Image recognition method and training method of image recognition model
CN111178340A