Live attack detection method, apparatus, storage medium, and terminal
Patent Information
- Application Number
- CN202211708379.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2042-12-28
Smart Images

Figure CN116189314B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present specification relate to the technical field of artificial intelligence, and in particular to a live body attack detection method and device, a storage medium, and a terminal. BACKGROUND
[0002] With the continuous development of face recognition systems in recent years, misrecognition of non-live images in the recognition process can easily threaten the security of user information, so live body attack detection in the face recognition process has become an important step. Due to the complexity of the scene using the face recognition function, the face region of the recognition object can be partially occluded. In order to reduce the negative impact of face occlusion on the accuracy of the live body attack detection result, a method is needed that can accurately complete the live body attack detection task with occlusion properties. SUMMARY
[0003] Embodiments of the present specification provide a live body attack detection method, device, storage medium, and terminal, which can solve the technical problem of inaccurate live body attack detection results in related technologies.
[0004] In a first aspect, embodiments of the present specification provide a live body attack detection method, which includes:
[0005] determining a first feature image of the to-be-detected image based on image features extracted from the to-be-detected image;
[0006] performing a weakening operation on a target image feature in the first feature image to obtain a second feature image, the target image feature having a target feature contribution degree to a live body attack detection result of the to-be-detected image greater than a preset feature contribution degree;
[0007] determining the live body attack detection result of the to-be-detected image according to the second feature image.
[0008] In a second aspect, embodiments of the present specification provide a live body attack detection device, which includes:
[0009] a feature extraction module configured to determine a first feature image of the to-be-detected image based on image features extracted from the to-be-detected image;
[0010] a feature weakening module configured to perform a weakening operation on a target image feature in the first feature image to obtain a second feature image, the target image feature having a target feature contribution degree to a live body attack detection result of the to-be-detected image greater than a preset feature contribution degree;
[0011] a live body attack detection module configured to determine the live body attack detection result of the to-be-detected image according to the second feature image.
[0012] In a third aspect, an embodiment of the present specification provides a computer program product containing instructions, which, when executed on a computer or processor, cause the computer or the processor to perform the steps of the method described above.
[0013] In a fourth aspect, an embodiment of the present specification provides a computer storage medium storing a plurality of instructions, which are suitable for being loaded by a processor and performing the steps of the method described above.
[0014] In a fifth aspect, an embodiment of the present specification provides a terminal, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being suitable for being loaded by the processor and performing the steps of the method described above.
[0015] The technical solutions provided by some embodiments of the present specification have at least the following beneficial effects:
[0016] An embodiment of the present specification provides a method, based on image features extracted from a to-be-detected image, determining a first feature image of the to-be-detected image; performing a weakening operation on a target image feature in the first feature image to obtain a second feature image, the target image feature having a target feature contribution degree to a living body attack detection result of the to-be-detected image greater than a preset feature contribution degree; and determining a living body attack detection result of the to-be-detected image according to the second feature image. Since some obvious features such as facial features and joint features are more obvious when extracting features, they will have a greater impact on the detection result. Therefore, in the embodiment of the present specification, the image features with a large contribution degree are weakened, so that the living body attack detection is finally completed by the image features with a relatively weak contribution degree, the living body attack detection accuracy when the high-contribution-degree features are covered is improved, and the applicability in diversified complex scenes is improved. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments of the present specification, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.
[0018] Figure 1 An exemplary system architecture diagram of a living body attack detection method provided by an embodiment of the present specification is shown in the following figure:
[0019] Figure 2 A system interaction diagram of a living body attack detection method provided by an embodiment of the present specification is shown in the following figure:
[0020] Figure 3A flowchart of a living body attack detection method provided by an embodiment of the present specification is shown in FIG. 1.
[0021] Figure 4 A flowchart of a living body attack detection method provided by an embodiment of the present specification is shown in FIG. 1.
[0022] Figure 5 A logic flowchart of a living body attack detection method provided by an embodiment of the present specification is shown in FIG. 2.
[0023] Figure 6 A structural block diagram of a living body attack detection device provided by an embodiment of the present specification is shown in FIG. 3.
[0024] Figure 7 A structural diagram of a terminal provided by an embodiment of the present specification is shown in FIG. 4. DETAILED DESCRIPTION
[0025] In order to make the features and advantages of the embodiments of the present specification more obvious and easy to understand, the technical solutions in the embodiments of the present specification will be described clearly and completely below in conjunction with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only some of the embodiments of the present specification, but not all the embodiments. Based on the embodiments in the present specification, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the embodiments of the present specification.
[0026] The following description relates to the drawings, and the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the embodiments of the present specification. Instead, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of the present specification as detailed in the appended claims.
[0027] With the increasing amount of face recognition tasks, the number of users using face recognition functions and the face recognition scenarios they are in is increasing. The user's living body data is highly related to their personal information, and during the information collection process, living body attacks against the living body attack detection model may be collected, such as face images, photos, videos, and other information. If the detection is incorrect when a living body attack of non-real living body data is collected, it may lead to the leakage of user information and cause losses, and thus the interception of non-living body type attacks through living body attack detection becomes an indispensable part of the face recognition system. Living body attack detection needs to effectively intercept non-living body type attack samples, including, for example, mobile phone attacks, paper attacks, head models, and the like.
[0028] In the live body attack detection process, it is usually judged whether it is a live body attack through image features in the image to be detected. It is easy to understand that compared with a flat face, obvious facial features of the object to be detected have stronger feature representation, and correct live body attack detection results can be obtained according to the obvious features. Therefore, in the existing live body attack detection process, the exposure degree of important facial features depends greatly. This also makes some obvious facial features of the object to be detected, such as facial features, ears, and facial contours, have a great influence on the detection results. However, in daily life, the user's face often appears to be covered, for example, the user may wear sunglasses, masks, hats and other common objects that cover the face, so that some important facial features of the object to be detected are covered during live body attack detection. At this time, the existing live body attack detection may not be able to obtain accurate detection results according to weak feature representation, and is very easy to be disturbed by the features of the covering object.
[0029] Therefore, the existing live body attack detection scheme suitable for the covering scene is mostly based on the mask covering attribute. For example, a score fusion scheme based on the mask attribute fuses the score of the mask attribute and the score of the live body attack detection to obtain the overall score of the input image, so as to integrate the mask attribute into the live body attack detection task. However, the accuracy of the mask covering object recognition of this scheme is required to be high, and the global robustness cannot be guaranteed. For example, another mask live body attack detection method based on face component detection detects fixed components in the face, and if the mouth and nose are found to be covered, it is considered that the face is covered by a mask, thereby constraining the final live body attack detection score. However, this method does not have the ability to judge the non-mask face component covering, and a large amount of misidentification will be caused.
[0030] Therefore, the embodiment of the present specification provides a live body attack detection method, which determines a first feature image of the image to be detected based on image features extracted from the image to be detected; performs a weakening operation on a target image feature in the first feature image to obtain a second feature image, the target image feature having a target feature contribution degree to the live body attack detection result of the image to be detected greater than a preset feature contribution degree; and determines the live body attack detection result of the image to be detected according to the second feature image, so as to solve the technical problem of inaccurate live body attack detection result in the covering scene.
[0031] Please refer to Figure 1 , Figure 1 An exemplary system architecture diagram of a live body attack detection method provided by the embodiment of the present specification is provided.
[0032] As Figure 1As shown, the system architecture can include a terminal 101, a network 102 and a server 103. The network 102 is used as a medium for providing a communication link between the terminal 101 and the server 103. The network 102 can include various types of wired communication links or wireless communication links, for example, the wired communication links include optical fiber, twisted pair or coaxial cable, and the wireless communication links include Bluetooth communication link, Wireless-Fidelity (Wi-Fi) communication link or microwave communication link, etc.
[0033] The terminal 101 can interact with the server 103 through the network 102 to receive a message from the server 103 or send a message to the server 103, or the terminal 101 can interact with the server 103 through the network 102 to receive a message or data sent by other users to the server 103. The terminal 101 can be hardware or software. When the terminal 101 is hardware, it can be various electronic devices, including but not limited to smart watches, smart phones, tablet computers, laptop computers and desktop computers, etc. When the terminal 101 is software, it can be installed in the above-mentioned electronic devices, which can be implemented as multiple software or software modules (for example, to provide distributed services) or a single software or software module, which is not specifically limited here.
[0034] In the embodiments of the present specification, the terminal 101 first determines a first feature image of the to-be-detected image based on the image features extracted from the to-be-detected image; then, the terminal 101 performs a weakening operation on the target image features in the first feature image to obtain a second feature image, wherein the target image features have a target feature contribution degree greater than a preset feature contribution degree to the living body attack detection result of the to-be-detected image; finally, the terminal 101 determines the living body attack detection result of the to-be-detected image according to the second feature image
[0035] The server 103 can be a central integrated server providing various services. It should be noted that the server 103 can be hardware or software. When the server 103 is hardware, it can be implemented as a distributed server cluster composed of multiple servers, or as a single server. When the server 103 is software, it can be implemented as multiple software or software modules (for example, to provide distributed services), or as a single software or software module, which is not specifically limited here.
[0036] Alternatively, the system architecture can also not include the server 103, in other words, the server 103 can be an optional device in the embodiments of the present specification, that is, the method provided by the embodiments of the present specification can be applied to a system structure including only the terminal 101, and the embodiments of the present specification do not limit this.
[0037] It should be understood that Figure 1The number of terminals, networks and servers in the system is only illustrative, and can be any number of terminals, networks and servers according to implementation needs.
[0038] Please refer to Figure 2 , Figure 2 A flowchart of a living body attack detection method provided by an embodiment of the present specification is shown. The execution subject of the embodiment of the present specification can be a terminal that performs living body attack detection, can also be a processor in the terminal that performs the living body attack detection method, and can also be a living body attack detection service in the terminal that performs the living body attack detection method. For the convenience of description, the specific execution process of the living body attack detection method is introduced below by taking the execution subject as the processor in the terminal.
[0039] As Figure 2 indicated, the living body attack detection method can at least include:
[0040] S202, determining a first feature image of the to-be-detected image based on image features extracted from the to-be-detected image.
[0041] Optionally, when performing living body attack detection, the to-be-detected image needs to be analyzed to obtain image features such as key point information and line contour information, and the living body attack can be judged based on the image features. That is, for the to-be-detected image input by the user, the image features of each unit pixel need to be extracted from the to-be-detected image first, and the first feature image of the to-be-detected image can be determined based on the image features.
[0042] Specifically, the feature extraction task of the image can be completed through a deep learning neural network to extract the deep features of the to-be-detected image, so as to facilitate the subsequent living body attack detection based on the feature image. And before performing the feature extraction on the to-be-detected model, a certain preprocessing step such as sharpening and target face region cropping can be performed, wherein the step and the corresponding method of performing the preprocessing are not specifically limited by the embodiment of the present specification.
[0043] S204, performing a weakening operation on a target image feature in the first feature image to obtain a second feature image, and the target image feature has a target feature contribution degree to the living body attack detection result of the to-be-detected image greater than a preset feature contribution degree.
[0044] Optionally, since in the human face features, the features with obvious changes are more informative, such as facial features, facial contours, etc. Such information is usually more helpful for judging the current target to be tested. Therefore, in the detection task of living body attacks, attention will be paid to such features, and these strong feature representations will have a strong contribution and a greater impact on the detection result. However, in a large number of actual scenes, the face features may be covered. When this part of the features is covered, the conventional living body attack detection method will still have a greater dependence on high-contribution feature representations, which will interfere with the final living body attack detection, cause misrecognition, and thus obtain inaccurate detection results. Therefore, in order to cope with the living body attack detection task with the covered attribute, it is possible to try to reduce the dependence on high-contribution features, extract information for English detection and judgment from weak-contribution features, and thus improve the living body attack detection capability in the covered scene.
[0045] Optionally, in order to reduce the influence of high-contribution feature representations on the final result, a weakening operation can be performed on the target image features with high contribution in the first feature image to obtain a second feature image, wherein the target image features are target features with a contribution to the living body attack detection result of the to-be-detected image greater than a preset feature contribution. The preset feature contribution can be set according to actual conditions, and the embodiments of the present specification are not limited in this regard.
[0046] Optionally, in a feasible embodiment, a neural network model can be used to complete the above task. Therefore, in the model training process, the model will perform a weakening operation on the target image features with high contribution, and then perform living body attack detection based on the weaker features, forcing the model to learn classification information from weaker features, which directly trains the model to use weak feature representations to judge living body attacks, thereby breaking the model's lazy training process and increasing the model's overall generalization.
[0047] S206, determining the living body attack detection result of the to-be-detected image according to the second feature image.
[0048] Optionally, after the target image features with strong contribution in the first feature image are weakened, the living body attack detection result of the to-be-detected image can be determined according to the obtained second feature image. At this time, the living body attack detection is based on weak-contribution representations for judgment, reducing the dependence on high-contribution features in the detection process, improving the living body attack detection accuracy when high-contribution features are covered, and enhancing the generalization of the living body attack detection method in various complex scenes.
[0049] In the embodiments of the present specification, a live body attack detection method is provided. Based on image features extracted from a to-be-detected image, a first feature image of the to-be-detected image is determined. A target image feature in the first feature image is subjected to a weakening operation to obtain a second feature image, and a target feature contribution degree of the target image feature to a live body attack detection result of the to-be-detected image is greater than a preset feature contribution degree. The live body attack detection result of the to-be-detected image is determined according to the second feature image. Since some obvious features such as facial features and joint features are more obvious when the features are extracted, the obvious features will have a greater impact on the detection result. Therefore, in the embodiments of the present specification, the image features with a large contribution degree are weakened, so that the live body attack detection is finally completed by the image features with a relatively weak contribution degree, the live body attack detection accuracy when the high-contribution-degree features are covered is improved, and the applicability in diversified complex scenes is improved.
[0050] Please refer to Figure 3 , Figure 3 A flowchart of a live body attack detection method provided in the embodiments of the present specification is shown.
[0051] As Figure 3 shown, the live body attack detection method can at least include:
[0052] S302, based on image features extracted from a to-be-detected image, a first feature image of the to-be-detected image is determined.
[0053] For step S302, please refer to the detailed description in step S202, which will not be repeated here.
[0054] S304, based on feature gradients of each image feature in the first feature image, a target image feature in the first feature image is determined.
[0055] Optionally, as can be known from the introduction of the above embodiments, in order to reduce the influence of obvious features on the final live body attack detection result, after obtaining the first feature image of the to-be-detected image, the target image feature in the first feature image can be subjected to a weakening operation. Therefore, before the weakening operation is performed, the target image feature in the first feature image needs to be determined first. For image features in units of pixels, each pixel has its corresponding feature gradient. The higher the gradient, the stronger the feature representation of the pixel, and the greater the influence on the output result. The lower the gradient, the weaker the feature representation of the pixel, and the smaller the influence on the output result. Based on this, in a feasible embodiment, the feature gradient of each image feature in the first feature image can be calculated, and the target image feature in the first feature image is determined according to the feature gradient, that is, the feature self-challenge of each image feature in the first feature image is performed, the feature gradient is obtained through the self-challenge, and the target image feature to be weakened is further determined.
[0056] Specifically, when the feature self-challenge is performed, in order to screen out the target image features according to the feature gradients of the image features, a preset feature gradient threshold can be set first, a boundary between strong features and weak features of the preset feature gradient threshold is determined, the feature gradients are compared with the preset feature gradient threshold respectively, and the image features corresponding to the feature gradients higher than the preset feature gradient threshold are taken as the target image features which can strongly contribute to the output result. The preset feature gradient threshold can be set according to actual needs, and can be obtained in various ways such as experimental statistics and calculation, which are not limited in the embodiments of the present application.
[0057] S306, performing a weakening operation on each target image feature.
[0058] Optionally, after the target image features are determined, a weakening operation needs to be performed on each target image feature. Each target image feature influences the final output result through its feature value, so the feature value of the target image feature is mainly weakened during the weakening, and the feature values of the remaining weakly represented image features need to be retained for the final live body attack detection.
[0059] Specifically, selective and targeted weakening needs to be performed during the weakening process, so a corresponding filter is needed, and in a feasible embodiment, a mask operation can be used as the weakening operation. The mask operation, also known as the mask film operation, is equivalent to covering a mask on the original tensor, thereby shielding or selecting some specific elements. Based on the mask operation, the feature value of the target image feature can be weakened to a preset feature value, and the original feature values of the non-target image features in the first feature image except the target image features are retained. The preset feature value represents the weakening effect of the target image feature, which can be zero or other arbitrary standard feature value, and is mainly dynamically set according to actual needs, which is not limited in the embodiments of the present application.
[0060] S308, determining a live body attack detection result of the to-be-detected image according to the second feature image.
[0061] For step S308, please refer to the detailed description in step S206, which will not be repeated here.
[0062] In the embodiment of the present specification, a living body attack detection method is provided, the target image feature is determined through the feature gradient of the image feature, so that the feature strength of the image feature can be accurately quantified, and then an accurate living body attack detection result can be obtained subsequently; the image feature with a feature gradient exceeding a preset feature gradient threshold is determined as a target image feature having a greater influence on the output result, and a mask operation is used to weaken the feature value of the target image feature, the mask operation can weaken the feature value of the target image feature to a preset feature value, and retain the original feature value of the non-target image feature in the first feature image except the target image feature, so as to weaken the strong feature and retain the weak feature.
[0063] Referring to Figure 4 , Figure 4 A flowchart of a living body attack detection method provided by the embodiment of the present specification is shown.
[0064] As Figure 4 shown, the living body attack detection method can at least include:
[0065] S402, a target region of interest in the to-be-detected image is determined, and a first feature image of the to-be-detected image is determined based on the image features extracted from the target region of interest.
[0066] Optionally, since the living body attack detection mainly judges the face information of the to-be-detected target, and the to-be-detected image usually includes the upper limb information of the to-be-detected target and a large amount of image background information, in order to accurately analyze the face information, the face region in the to-be-detected image can be taken as a region of interest (ROI), the target region of interest is obtained from the to-be-detected image first, and then the image features of the user's face are extracted based on the target region of interest.
[0067] Referring to Figure 5 , Figure 5 A logic flowchart of a living body attack detection method provided by the embodiment of the present specification is shown. As Figure 5 shown, after obtaining the input to-be-detected image, first, a target region of interest in the to-be-detected image is determined, and a first feature image of the to-be-detected image is determined based on the image features extracted from the target region of interest.
[0068] S404, a covered image region and a non-covered image region in the first feature image are determined.
[0069] Optionally, for different covering scenarios, the covering area can be further weakened in targeted features to enhance the applicability in specific scenarios. Since the mask attribute covering scenario is the most common in various covering scenarios, the embodiments of the present specification take the mask scenario as an example to perform targeted processing for the specific scenario of the mask attribute, that is, to weaken the features of the mask covering area in a targeted manner, so that the mask area is not sensitive to the live attack detection, thereby enhancing the contribution of other areas to the final classification.
[0070] Optionally, as shown in Figure 5 , first, the mask region in the first feature image, that is, the covering coordinates of the covering image region, is determined by target detection of the mask. Based on the covering coordinates, projection is performed in the first feature image to determine the projection region as the covering image region and the remaining non-projection region as the non-covering image region. At this time, for the covering image region, targeted feature weakening can be performed to make the live attack detection focus more on the non-covering image region. The weakening of the non-covering image region makes the live attack detection focus more on the weak features that are not covered, and finally realizes the enhancement of the non-covering image region to the weak feature representation, thereby realizing the generalization of the overall live attack detection model.
[0071] S406, performing a first weakening operation on the first target image feature in the covering image region and a second weakening operation on the second target image feature in the non-covering image region to obtain a second feature image.
[0072] Optionally, the first target image feature in the covering image region is subjected to a first weakening operation, and the second target image feature in the non-covering image region is subjected to a second weakening operation. Specifically, in order to retain some covering features in the covering image region to enable the model to learn the feature representation of the covering region, it is not necessary to weaken the features of all covering image regions, but as shown in Figure 5 , a random weakening operation can be used as the first weakening operation to randomly challenge the image features of the covering image region, so that for a part of the input image, the model is not sensitive to the covering image region, and the contribution of other non-covering image regions to the final classification is enhanced.
[0073] Further, as shown in Figure 5As shown, for the non-occluded image region, high-response self-challenge can be performed, that is, the second weakening operation can be a high-response weakening operation. For the non-occluded image region, grid division can be performed, the non-occluded image region is divided into a grid with 8 pixels as a unit for weakening operation, the feature value of the maximum image feature in each grid region is calculated as the feature value of the unit grid, and the feature self-challenge is performed according to the feature gradient of each divided grid, so as to improve the weakening operation efficiency of the non-occluded image region and improve the final generalization of the scheme. The number of pixel grids of grid division can be set according to specific needs. The smaller the number of pixel grids, the more detailed the weakening operation. The number of pixel grids of grid division is not limited in the embodiments of the present application.
[0074] Optionally, please continue to refer to Figure 5 After the targeted weakening operation is performed on each of the occluded image region and the non-occluded image region, the second feature image corresponding to the original first feature image after weakening can be obtained, and finally the live body attack detection can be performed according to the second feature image and the detection classification result can be obtained. Specifically, the feature mapping method can be used to map the occluded image region on the last feature, or a distributed convolution framework similar to the convolutional neural network (Region Proposal Network, RPN) can be used to achieve better feature region mapping effect, thereby producing additional positive benefits on the final result.
[0075] Further, it can be noted that, based on the targeted weakening of the occluded image region in the present scheme, other attributes of the face can be introduced by similar methods, for example, the eye region is an occluded region in the case of a pair of sunglasses, so as to obtain a more robust live body attack detection model and a live body attack detection method applicable in multiple scenarios.
[0076] S408, determining the live body attack detection result of the to-be-detected image according to the second feature image.
[0077] For step S408, please refer to the detailed description in step S206, which will not be repeated here.
[0078] In the embodiments of the present application, a live body attack detection method is provided, which randomly weakens the features in the special occluded region, improves the processing capability of the present scheme for specific occlusion, and enhances the applicability in specific occlusion scenarios; the target image features in the non-special occluded region are weakened, so that the live body attack detection result can be obtained by analyzing the weak features in the non-occluded region during live body attack detection, the live body attack detection is finally completed by relatively weaker image features, the live body attack detection accuracy is improved when the high-contribution features are occluded, and the applicability in diversified complex scenarios is improved.
[0079] Please refer toFigure 6 , Figure 6 A structural block diagram of a living body attack detection device is provided for an embodiment of the present specification. As shown in the figure, the living body attack detection device 600 comprises: Figure 6
[0080] A feature extraction module 610 is configured to determine a first feature image of a to-be-detected image based on image features extracted from the to-be-detected image.
[0081] A feature weakening module 620 is configured to perform a weakening operation on target image features in the first feature image to obtain a second feature image, the target image features having a target feature contribution degree to a living body attack detection result of the to-be-detected image greater than a preset feature contribution degree.
[0082] A living body attack detection module 630 is configured to determine the living body attack detection result of the to-be-detected image according to the second feature image.
[0083] Optionally, the feature weakening module 620 is further configured to determine the target image features in the first feature image based on feature gradients of the image features in the first feature image; and perform the weakening operation on the target image features.
[0084] Optionally, the feature weakening module 620 is further configured to compare each feature gradient with a preset feature gradient threshold value, and determine the image features corresponding to the feature gradients higher than the preset feature gradient threshold value as the target image features.
[0085] Optionally, the feature weakening module 620 is further configured to set a feature value of the target image features to a preset feature value, and retain feature values of non-target image features in the first feature image except the target image features.
[0086] Optionally, the feature weakening module 620 is further configured to determine a covered image region and a non-covered image region in the first feature image; perform a first weakening operation on first target image features in the covered image region and a second weakening operation on second target image features in the non-covered image region to obtain the second feature image.
[0087] Optionally, the feature weakening module 620 is further configured to determine a covering coordinate of a covering region in the to-be-detected image, project the covering coordinate in the first feature image based on the covering coordinate, determine a projection region as the covered image region, and determine a remaining non-projection region as the non-covered image region.
[0088] Optionally, the first weakening operation is a random weakening operation, and the second weakening operation is a high-response weakening operation.
[0089] Optionally, the feature extraction module 610 is further configured to determine a target region of interest in the image to be detected, and determine the first feature image of the image to be detected based on image features extracted from the target region of interest.
[0090] Optionally, the weakening operation is a masking operation.
[0091] In the embodiments of the present specification, a living body attack detection apparatus is provided, wherein a feature extraction module is configured to determine a first feature image of an image to be detected based on image features extracted from the image to be detected; a feature weakening module is configured to perform a weakening operation on a target image feature in the first feature image to obtain a second feature image, the target image feature having a target feature contribution to a living body attack detection result of the image to be detected greater than a preset feature contribution; and a living body attack detection module is configured to determine the living body attack detection result of the image to be detected according to the second feature image. Since some obvious features such as facial features and joint features are more obvious when the features are extracted, and have a greater impact on the detection result, the image features with a large contribution are weakened in the embodiments of the present specification, so that the living body attack detection is finally completed by the image features with a relatively weak contribution, the living body attack detection accuracy when the high-contribution features are covered is improved, and the applicability in diversified complex scenes is improved.
[0092] The embodiments of the present specification provide a computer program product containing instructions, which, when the computer program product is run on a computer or a processor, cause the computer or the processor to execute the steps of the method of any one of the above embodiments.
[0093] The embodiments of the present specification also provide a computer storage medium, which can store a plurality of instructions, and the instructions are suitable for being loaded and executed by a processor to perform the steps of the method of any one of the above embodiments.
[0094] Please refer to Figure 7 , Figure 7 A structural schematic diagram of a terminal is provided for the embodiments of the present specification. As shown in Figure 7 , the terminal 700 can include at least one terminal processor 701, at least one network interface 704, a user interface 703, a memory 705, and at least one communication bus 702.
[0095] The communication bus 702 is configured to realize the connection communication between the components.
[0096] The user interface 703 can include a display screen (Display) and a camera (Camera), and the optional user interface 703 can further include a standard wired interface and a wireless interface.
[0097] The network interface 704 can optionally include a standard wired interface, a wireless interface (e.g., a WI-FI interface).
[0098] The terminal processor 701 can include one or more processing cores. The terminal processor 701 connects various parts within the terminal 700 via various interfaces and lines, executes various functions of the terminal 700 and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 705, and calling data stored in the memory 705. The terminal processor 701 can be implemented in at least one of a hardware form of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The terminal processor 701 can be integrated with a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU is mainly responsible for processing an operating system, a user interface, and an application program. The GPU is responsible for rendering and drawing content to be displayed on a display screen. The modem is responsible for processing wireless communication. It can be understood that the modem can also not be integrated into the terminal processor 701, but can be implemented by a separate chip.
[0099] The memory 705 can include a random access memory (RAM) and a read-only memory (ROM). The memory 705 can include a non-transitory computer-readable storage medium. The memory 705 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 705 can include a program storage area and a data storage area. The program storage area can store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playing function, an image playing function, etc.), instructions for implementing the above-mentioned various method embodiments, etc. The data storage area can store data involved in the above-mentioned various method embodiments, etc. The memory 705 can optionally be at least one storage device located away from the terminal processor 701. As shown, the memory 705 as a computer storage medium can include an operating system, a network communication module, a user interface module, and a live attack detection program. Figure 7 As shown, the memory 705 as a computer storage medium can include an operating system, a network communication module, a user interface module, and a live attack detection program.
[0100] In Figure 7 In the terminal 700 shown, the user interface 703 is mainly used to provide an interface for the user to input, and obtain data input by the user; and the terminal processor 701 can be used to call a living body attack detection program stored in the storage 705, and specifically perform the following operations:
[0101] Based on the image features extracted from the to-be-detected image, a first feature image of the to-be-detected image is determined;
[0102] Target image features in the first feature image are subjected to a weakening operation to obtain a second feature image, and a target feature contribution degree of the target image features to a living body attack detection result of the to-be-detected image is greater than a preset feature contribution degree;
[0103] The living body attack detection result of the to-be-detected image is determined according to the second feature image.
[0104] In some embodiments, when the terminal processor 701 performs the weakening operation on the target image features in the first feature image, the following steps are specifically performed: based on feature gradients of the image features in the first feature image, target image features in the first feature image are determined; and the target image features are subjected to the weakening operation.
[0105] In some embodiments, when the terminal processor 701 performs the determination of the target image features in the first feature image based on the feature gradients of the image features in the first feature image, the following steps are specifically performed: each feature gradient is compared with a preset feature gradient threshold value, and the image features corresponding to the feature gradients higher than the preset feature gradient threshold value are the target image features.
[0106] In some embodiments, when the terminal processor 701 performs the weakening operation on the target image features, the following steps are specifically performed: a feature value of the target image features is set to a preset feature value, and feature values of non-target image features in the first feature image except the target image features are retained.
[0107] In some embodiments, when the terminal processor 701 performs the weakening operation on the target image features in the first feature image to obtain the second feature image, the following steps are specifically performed: a covered image region and a non-covered image region in the first feature image are determined; a first target image feature in the covered image region is subjected to a first weakening operation, and a second target image feature in the non-covered image region is subjected to a second weakening operation to obtain the second feature image.
[0108] In some embodiments, the terminal processor 701, when performing the determining of the covered image region and the non-covered image region in the first feature image, specifically performs the following steps: determining the covering coordinates of the covered region in the image to be detected, projecting in the first feature image based on the covering coordinates, determining the projected region as the covered image region and the remaining non-projected region as the non-covered image region.
[0109] In some embodiments, the first weakening operation is a random weakening operation, and the second weakening operation is a high-response weakening operation.
[0110] In some embodiments, the terminal processor 701, when performing the determining of the first feature image of the image to be detected based on the image features extracted from the image to be detected, specifically performs the following steps: determining a target region of interest in the image to be detected, and determining the first feature image of the image to be detected based on the image features extracted from the target region of interest.
[0111] In some embodiments, the weakening operation is a mask operation.
[0112] In several embodiments provided in the specification, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are only schematic, for example, the division of the modules is only a logical function division, and actual implementation can have another division manner, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed modules can be indirect coupling or communication connection through some interface, device or module, and can be electrical, mechanical or other forms.
[0113] The modules illustrated as separate components can or can not be physically separate, and the components illustrated as modules can or can not be physical modules, i.e. can be located in one place, or can be distributed to a plurality of network modules. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0114] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The above computer program product includes one or more computer instructions. When the above computer program instructions are loaded and executed on a computer, all or part of the processes or functions described above according to the embodiments of the present specification are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted by the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center through a wired (such as a coaxial cable, an optical fiber, a digital subscriber line (DSL)) or a wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital versatile disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
[0115] It should be noted that, for the foregoing method embodiments, in order to facilitate description, they are all described as a combination of a series of actions, but those skilled in the art should know that the embodiments of the present specification are not limited by the order of the described actions, because according to the embodiments of the present specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of the present specification.
[0116] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0117] The above is the description of the living body attack detection method, device, storage medium, and terminal provided by the embodiments of the present specification. For those skilled in the art, according to the idea of the embodiments of the present specification, there will be changes in specific implementation and application range. In summary, the content of the present specification should not be understood as a limitation of the embodiments of the present specification.
Claims
1. A live attack detection method, the method comprising: determining a first feature image of a to-be-detected image based on image features extracted from the to-be-detected image; performing a weakening operation on target image features in the first feature image to obtain a second feature image, the target image features having a target feature contribution to a live attack detection result of the to-be-detected image greater than a preset feature contribution; determining a live attack detection result of the to-be-detected image according to the second feature image; the weakening operation on the target image features in the first feature image comprises: calculating feature gradients of each image feature in the first feature image by a feature self-challenge algorithm, determining the target image features in the first feature image based on the feature gradients of each image feature, and performing the weakening operation on each target image feature; the feature gradient is used to represent an influence degree of an image feature on a live attack detection result; the weakening operation on the target image features in the first feature image to obtain the second feature image comprises: determining a covered image region and a non-covered image region in the first feature image; performing a first weakening operation on first target image features in the covered image region and a second weakening operation on second target image features in the non-covered image region to obtain the second feature image; the first weakening operation is a random weakening operation, and the second weakening operation is a high-response weakening operation.
2. The method of claim 1, wherein the determination of the target image features in the first feature image based on the feature gradients of each image feature in the first feature image comprises: comparing each feature gradient with a preset feature gradient threshold, and regarding an image feature corresponding to a feature gradient higher than the preset feature gradient threshold as a target image feature.
3. The method of claim 2, wherein the weakening operation on each target image feature comprises: setting a feature value of the target image feature to a preset feature value, and retaining feature values of non-target image features in the first feature image except the target image features.
4. The method of claim 1, wherein the determination of the covered image region and the non-covered image region in the first feature image comprises: determining covered coordinates of a covered region in the to-be-detected image, projecting the covered coordinates in the first feature image to determine a projection region as the covered image region and a remaining non-projection region as the non-covered image region.
5. The method of claim 1, wherein the determination of the first feature image of the to-be-detected image based on the image features extracted from the to-be-detected image comprises: determining a target region of interest in the to-be-detected image, and determining the first feature image of the to-be-detected image based on image features extracted from the target region of interest.
6. The method of claim 1, wherein the weakening operation is a mask operation.
7. A live attack detection device, the device comprising: a feature extraction module configured to determine a first feature image of a to-be-detected image based on image features extracted from the to-be-detected image. The feature weakening module is configured to perform a weakening operation on target image features in the first feature image to obtain a second feature image, the target image features having a target feature contribution degree to the living body attack detection result of the to-be-detected image greater than a preset feature contribution degree; The living body detection module is configured to determine the living body attack detection result of the to-be-detected image according to the second feature image; The feature weakening module is further configured to calculate a feature gradient of each image feature in the first feature image by using a feature self-challenge algorithm, determine the target image features in the first feature image based on the feature gradient of each image feature, perform a weakening operation on each target image feature, and use the feature gradient to represent the influence degree of the image feature on the living body attack detection result. The feature weakening module is further configured to determine a covered image region and a non-covered image region in the first feature image, perform a first weakening operation on a first target image feature in the covered image region, perform a second weakening operation on a second target image feature in the non-covered image region, and obtain a second feature image, the first weakening operation being a random weakening operation, and the second weakening operation being a high-response weakening operation.
8. A computer program product comprising instructions which, when executed on a computer or processor, cause the computer or processor to carry out the steps of the method of any one of claims 1 to 6.
9. A computer storage medium having stored thereon a plurality of instructions adapted to be loaded and executed by a processor to perform the steps of the method of any one of claims 1 to 6.
10. A terminal comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, the processor implementing the steps of the method of any one of claims 1 to 6 when executing the program.
Citation Information
Patent Citations
Face recognition model attack defense method and device, equipment and storage medium
CN114332982A
Living body detection method, device and equipment
CN114973347A