Method and device for intercepting face recognition attack, equipment and storage medium
By acquiring and analyzing transaction data and biopsy face images in the face recognition system, dividing image clusters and identifying risk users, the problem of low accuracy of face recognition attack interception in the prior art is solved, and more efficient attack recognition and interception is achieved.
Patent Information
- Application Number
- CN202510114354.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art has low accuracy when intercepting face recognition attacks, especially in scenarios with high timeliness requirements. In order to ensure user experience, it is easy to reduce the accuracy of attack interception.
By acquiring transaction data of N users in the first time window and biopsy face images, dividing image clusters based on transaction data, identifying user image clusters with similar background areas, and determining interception data of risk users corresponding to biopsy face images in the image cluster to instruct intercept face recognition attacks related to risk users in the second time window.
It realizes the rapid and accurate discovery and identification of potential attack images in a large amount of daily transaction data, improves the interception accuracy of face recognition attacks, avoids potential or missing attacks, and flexibly controls the risks of face services.
Smart Images

Figure CN120014719A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of information security technology, and in particular, relates to a method, device, equipment and storage medium for intercepting face recognition attacks. Background Art
[0002] With the application of identity authentication in various fields, face recognition has become the main means of identity authentication. In the process of collecting face data, there are criminals who use synthetic attacks, injection attacks and other means to attack face recognition to affect face recognition results. For example, using artificial intelligence synthesis technology, the user's facial features are fitted into a realistic background image, and the corresponding actions are activated to generate a false biopsy action video, attacking the face recognition process and disrupting the face recognition results.
[0003] In related technologies, for facial recognition scenarios with high timeliness requirements, such as order transaction scenarios and account login scenarios, in order not to affect the normal user experience, a higher pass rate is usually prioritized. This can easily reduce the accuracy of intercepting facial recognition attacks. Summary of the invention
[0004] The embodiments of the present application provide a method, device, equipment and storage medium for intercepting face recognition attacks, which can solve the problem of low accuracy in intercepting face recognition attacks in related technologies.
[0005] In a first aspect, an embodiment of the present application provides a method for intercepting a face recognition attack, which may include:
[0006] Acquire transaction data and biopsy face images of N users in a first time window, where the transaction data includes at least one of the following: transaction time and transaction location, where N is an integer greater than 1;
[0007] Based on the transaction data, the biopsy face images of N users are divided to obtain at least one image cluster, where the image cluster includes the biopsy face images of at least two users with similar background areas, where the background area is a non-face area in the biopsy face images;
[0008] Determine interception data of a risky user corresponding to the biopsy face image in the image cluster, where the interception data is used to indicate interception of a face recognition attack associated with the risky user within a second time window.
[0009] In a second aspect, an embodiment of the present application provides a device for intercepting face recognition attacks, which may include:
[0010] An acquisition module is used to acquire transaction data and biopsy face images of N users in a first time window, where the transaction data includes at least one of the following: transaction time and transaction location, and N is an integer greater than 1;
[0011] a segmentation module, configured to segment the biopsy face images of N users based on the transaction data to obtain at least one image cluster, wherein the image cluster includes the biopsy face images of at least two users having similar background areas, where the background area is a non-face area in the biopsy face images;
[0012] A determination module is used to determine interception data of a risky user corresponding to a biopsy face image in an image cluster, wherein the interception data is used to indicate interception of a face recognition attack associated with the risky user within a second time window.
[0013] In a third aspect, an embodiment of the present application provides a computer device, the computer device comprising: a processor and a memory storing computer program instructions;
[0014] When the processor executes the computer program instructions, it implements the method for intercepting face recognition attacks as shown in the first aspect.
[0015] In a fourth aspect, an embodiment of the present application provides a computer storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the method for intercepting face recognition attacks as shown in the first aspect is implemented.
[0016] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the method for intercepting face recognition attacks as shown in the first aspect.
[0017] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method for intercepting face recognition attacks as shown in the first aspect.
[0018] The method, apparatus, device and storage medium for intercepting facial recognition attacks of the embodiments of the present application can obtain transaction data and biopsy facial images of N users within a first time window, where the transaction data includes at least one of the following: transaction time and transaction location; and based on the transaction data, the biopsy facial images of N users are divided to obtain at least one image cluster, where the image cluster includes biopsy facial images of at least two users with similar background areas, where the background area is a non-face area in the biopsy facial image; then, the interception data of the risky user corresponding to the biopsy facial image in the image cluster is determined, and the interception data is used to indicate the interception of facial recognition attacks related to the risky user within a second time window. In this way, with respect to the time and / or space dimensions, potential attack images can be quickly and accurately discovered and identified in a large amount of daily transaction data. From the perspective of post-transaction handling, the background homogeneity characteristics of illegal facial recognition attacks can be fully utilized. Combined with the fact that the attack image features are naturally different from the discrete features of the biopsy facial images of normal users and clustered, the biopsy facial images are clustered, thereby determining the biopsy facial images of users with higher risks and the corresponding interception data, thereby intercepting facial recognition attacks related to risky users, flexibly controlling the risks of facial services, and, on the premise of ensuring the identity authentication pass rate of normal users, intercepting facial recognition attacks of risky users as much as possible after the transaction occurs, avoiding potential or missed facial recognition attacks, and improving the accuracy of intercepting facial recognition attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solution of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0020] Figure 1 A flowchart of a method for intercepting face recognition attacks provided in an embodiment of the present application;
[0021] Figure 2 A schematic diagram of reference geographic attribute data in a method for intercepting face recognition attacks provided in an embodiment of the present application;
[0022] Figure 3 A flowchart of a method for intercepting face recognition attacks provided in an embodiment of the present application;
[0023] Figure 4 It is a structural schematic diagram of a device for intercepting face recognition attacks provided by an embodiment of the present application;
[0024] Figure 5 It is a schematic diagram of the structure of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0025] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is only to provide a better understanding of the present application by illustrating the examples of the present application.
[0026] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "include..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0027] The acquisition, storage, use, and processing of data (including but not limited to the features and information in the text) in the technical solution of this application comply with the relevant provisions of national laws and regulations.
[0028] Liveness detection is a method used to determine the real physiological characteristics of an object in an identity authentication scenario. In face recognition applications, liveness detection can verify whether the user is a real living person through a combination of actions such as blinking, opening the mouth, shaking the head, and nodding, using technologies such as facial key point positioning and face tracking. It can effectively resist common attack methods such as photos, videos, face swapping, masks, occlusions, and screen reshoots, and determine the authenticity of the face, thereby helping users identify fraud and ensure user information security.
[0029] Face recognition has been the main means of identity verification for many years. With the upgrading of artificial intelligence and the use of Internet technology to carry out cyber attacks, steal information, extortion and fraud, attacks in the face collection process have gradually changed from low-tech means such as reshoots and masks to more complex and realistic means such as synthesis and injection. In the face detection process, criminals use synthetic attacks, injection attacks and other means to attack face recognition in order to affect the face recognition results. For example, in the liveness detection stage of the face detection process, the collected image including the face is fitted to the realistic background image provided by the criminals, and the corresponding actions are activated to generate a false liveness action video to attack the face recognition process.
[0030] Since these background images have the same background characteristics, that is, multiple attacked user videos are fitted with the same background image, so that the fitted images show the same background characteristics, which is particularly evident in the attacks of preset synthesis and real-time synthesis injection. Therefore, in order to effectively identify attacks with these background images with homologous characteristics, potential homologous background images can usually be detected during the transaction process. However. For face recognition scenarios with high timeliness requirements such as order transaction scenarios and account login scenarios, in order not to affect the normal user experience, it is usually prioritized to ensure a higher pass rate, which is easy to reduce the accuracy of intercepting face recognition attacks.
[0031] In order to solve the problems arising in the related technology, the embodiment of the present application proposes a method of analyzing facial recognition attacks after a transaction occurs, intercepting facial recognition attacks of users with higher risks, avoiding potential or missed facial recognition attacks, and improving the accuracy of intercepting facial recognition attacks, in order to improve the systematic capabilities of facial prevention and control.
[0032] Based on this, the following will combine the attached Figures 1 to 5 , the methods, devices, computer equipment and storage media of the embodiments of the present application are described in detail. It should be noted that these embodiments are not intended to limit the scope of the disclosure of the present application.
[0033] Figure 1 A flowchart of a method for intercepting face recognition attacks provided in an embodiment of the present application.
[0034] like Figure 1 As shown, the method for intercepting face recognition attacks can be applied to computer devices, and the interception method can specifically include the following steps:
[0035] Step 110, obtaining transaction data and biopsy face images of N users within a first time window, where the transaction data includes at least one of the following: transaction time, transaction location, and N is an integer greater than 1; Step 120, dividing the biopsy face images of N users based on the transaction data to obtain at least one image cluster, where the image cluster includes biopsy face images of at least two users with similar background areas, and the background area is a non-face area in the biopsy face image; Step 130, determining interception data of risky users corresponding to the biopsy face images in the image cluster, where the interception data is used to indicate interception of face recognition attacks related to risky users within a second time window.
[0036] In this way, with respect to the time and / or space dimensions, potential attack images can be quickly and accurately discovered and identified in a large amount of daily transaction data. From the perspective of post-transaction handling, the background homogeneity characteristics of illegal facial recognition attacks can be fully utilized. Combined with the fact that the attack image features are naturally different from the discrete features of the biopsy facial images of normal users and clustered, the biopsy facial images are clustered, thereby determining the biopsy facial images of users with higher risks and the corresponding interception data, thereby intercepting facial recognition attacks related to risky users, flexibly controlling the risks of facial services, and, on the premise of ensuring the identity authentication pass rate of normal users, intercepting facial recognition attacks of risky users as much as possible after the transaction occurs, avoiding potential or missed facial recognition attacks, and improving the accuracy of intercepting facial recognition attacks.
[0037] The above steps are described in detail below, as shown below.
[0038] First, step 110 is involved. In some embodiments of the present application, in the actual service process, the service end can obtain the service transaction data sent by the user end. The service transaction data includes the transaction data of N users and the biopsy face image of the identity verification involved in the transaction process. Among them, the transaction data includes at least one of the following: transaction time and transaction location. The service transaction data can be service transaction data in face recognition scenarios with high timeliness requirements, such as transfer, binding payment card, account login, and face payment order transaction scenarios.
[0039] Next, step 120 is referred to. In some embodiments of the present application, step 120 may specifically include step 1201 and step 1202.
[0040] Step 1201 , based on the transaction data, feature extraction is performed on the background area in the biopsy face images of N users to obtain background feature data of the biopsy face image of each user.
[0041] Exemplarily, if the transaction data is the transaction location, feature extraction can be performed on the background area of the biopsy face image in the same transaction location; if the transaction data is the transaction time, feature extraction can be performed on the background area of the biopsy face image in the same transaction time interval; if the transaction data includes the transaction location and transaction time, feature extraction can be performed on the background area of the biopsy face image in the same transaction time interval and in the same transaction location. For example, according to the transaction time interval of 5 minutes, the transaction location can be represented by longitude and latitude information, that is, the geographical location of the transaction location is a rectangular area with a side length of 100m, and the biopsy face images of users in the same time interval and transaction location are clustered.
[0042] In some embodiments, the feature extraction method can be performed using a pre-trained convolutional network with a classical structure. In other embodiments, in order to save computing costs, the Histogram of Oriented Gradients (HOG) feature can be used instead.
[0043] It should be noted here that in addition to executing the above-mentioned background separation process after obtaining the transaction data and the biopsy face image, the above-mentioned background separation process can also be introduced in the hack detection stage before executing the specific portrait or identity authentication service. The background image in the biopsy face image can be synchronously separated and retained during the hack detection process. In this way, the background feature data of the user's biopsy face image can be obtained while obtaining the transaction data and the biopsy face image, so as to improve the clustering efficiency, and then improve the efficiency of intercepting face recognition attacks.
[0044] In addition, in the face recognition of the embodiments of the present application, hacking refers to the use of technical means to bypass the security verification of the face recognition system to achieve illegal access or impersonation of others. This behavior may involve the use of photos, videos or other forms of disguise to deceive the face recognition system to obtain improper access rights. The process of detecting hacking is called hack detection.
[0045] Step 1202 : clustering the biopsy face images of N users based on the background feature data of the biopsy face image of each user to obtain at least one image cluster.
[0046] For example, in view of the background homogeneity of illegal face recognition attacks, combined with the fact that the attack image features are naturally different from the discrete features of normal user biopsy face images and thus clustered, unsupervised clustering such as DBSCAN, OPTICS, and BIRCH can be used to cluster the background feature data.
[0047] In this way, the image clusters that can be significantly clustered have the characteristic of smaller average distance of centroids within the class, and the corresponding biopsy face images have a higher risk level, which can improve the recognition effect of biopsy face images as much as possible, avoid potential or missed face recognition attacks, and improve the accuracy of intercepting face recognition attacks.
[0048] Furthermore, in some embodiments, the above-mentioned step 1202 may specifically include:
[0049] Clustering the biopsy face images of N users based on the similarity between the background feature data of the biopsy face images of at least two users by an unsupervised clustering algorithm to obtain at least one initial image cluster;
[0050] At least one image cluster is determined from at least one initial image cluster; wherein the image cluster satisfies at least one of the following conditions: the number of biopsy face images in the image cluster is greater than or equal to the number of reference images, and the range of the average centroid distance interval of the image cluster belongs to the range of the reference average centroid distance interval.
[0051] Here, the similarity of the background areas of at least two frames of biopsy face images in the initial image cluster described in the embodiment of the present application is greater than or equal to a preset similarity.
[0052] Exemplarily, BIRCH clustering is performed on all background feature data in the group, the number of reference images in the image cluster and the reference average centroid distance interval are set, the initial image cluster falling within the range is marked, and the background area of the biopsy face image in the image cluster is obtained.
[0053] The pixel consistency comparison is performed on the background area of the biopsy face image within the image cluster, and the normalized difference square sum algorithm is used to evaluate the pixel consistency between at least two background areas. Specifically, it can be calculated by the following formula (1):
[0054]
[0055] Among them, I(x,y) is used to represent the horizontal and vertical coordinates of pixel point i in a background area. ′ (x, y) is used to represent the horizontal and vertical coordinates of pixel point i in another background area.
[0056] In this way, the sum of squares of differences between corresponding pixels of at least two background areas is calculated. For images using the same background template, the difference should be close to 0. A relevant threshold is set, and images below the threshold are considered to have pixel-level consistency. The matched background images are added to the attack background library, and the associated users involved are marked as risky. It is worth noting that such associations are often many-to-many clustered, so error fluctuations can be further eliminated by the cluster number.
[0057] Then, in step 130, the time in the second time window in the embodiment of the present application is later than the time in the first time window.
[0058] In this way, potential attack images can be quickly and accurately discovered and identified in a large amount of daily transaction data in terms of time and / or space dimensions, so as to make full use of the background homogeneity characteristics of illegal facial recognition attacks from the perspective of post-transaction handling, and cluster the biopsy facial images by combining the attack image features that are naturally different from the discrete features of normal user biopsy facial images, thereby determining the biopsy facial images of users with higher risks and the corresponding interception data.
[0059] In some embodiments of the present application, the transaction data includes the transaction time. Based on this, before step 130, the method for intercepting face recognition attacks may also include steps 2101 and 2102.
[0060] Step 2101 , performing pixel consistency comparison on background areas of biopsy facial images of at least two users in an image cluster to obtain pixel comparison data of at least two background areas.
[0061] Step 2102: when the data value of the pixel comparison data is greater than or equal to a first preset threshold, determine that at least two users corresponding to the pixel comparison data are risky users.
[0062] For example, in order to further reduce errors, it is necessary to perform pixel consistency judgment on the background areas of the biopsied facial images within these image clusters, and issue a unified risk warning to associated users that exceed the consistency threshold, so that corresponding strategy adjustments can be made to the biopsy process of at least two users in the image cluster.
[0063] Furthermore, the pixel consistency judgment involved above can determine the consistency between the background areas of the biopsy face images of at least two users through a normalized difference square algorithm and a normalized correlation coefficient evaluation algorithm. Based on this, in some embodiments, the above step 2101 can specifically include:
[0064] Through a comparison algorithm, pixel consistency comparison is performed on the background areas of the biopsy facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas; wherein the comparison algorithm includes at least one of the following: a normalized difference square algorithm and a normalized correlation coefficient evaluation algorithm.
[0065] In some embodiments of the present application, the transaction data includes the transaction location. Based on this, before step 130, the method for intercepting facial recognition attacks may also include steps 2103 and 2104.
[0066] Step 2103, based on the reference geographic attribute data of the transaction location, correlation matching is performed on the background areas of the biopsy face images of at least two users in the image cluster to obtain content matching data.
[0067] It should be noted that the reference geographic attribute data in the embodiments of the present application includes at least one of the following: weather condition attribute data, indoor and outdoor environment attribute data, background complexity attribute data, scene function attribute data, and administrative division attribute data.
[0068] Step 2104: when the data value of the content matching data is less than or equal to the second preset threshold, determine that at least two users corresponding to the content matching data are risky users.
[0069] For example, the spatiotemporal domain, i.e., the geographic location factor, can be introduced, that is, the transaction data of N users in the same spatiotemporal range and the background area of the biopsy face image can be verified to clarify the risk range. Since the attribute data reflected by the background area of normal users in the same geographic location tends to be consistent, the background area of risky users using the same set of attack images often cannot be adjusted with the change of geographic location, resulting in conflicts. Therefore, the risk range can be determined by Figure 2 The reference geographic attribute data shown performs correlation matching on the background areas of the biopsy face images of at least two users in the image cluster. If the data value of the content matching data is less than or equal to the second preset threshold, at least two users corresponding to the content matching data are determined to be risky users.
[0070] In some embodiments of the present application, the transaction data includes the transaction location and transaction time. Based on this, before step 130, the method for intercepting facial recognition attacks may also include steps 2105 to 2107.
[0071] Step 2105, performing pixel consistency comparison on the background areas of the biopsied facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas; and, based on the reference geographic attribute data of the transaction location, performing correlation matching on the background areas of the biopsied facial images of at least two users in the image cluster to obtain content matching data.
[0072] Step 2106, determining risk score data for each of the at least two users based on the pixel comparison data, the first risk confidence level corresponding to the pixel comparison data, the content matching data, and the second risk confidence level corresponding to the content matching data.
[0073] Step 2107: When the risk score data is greater than or equal to the third preset threshold, determine that the user corresponding to the risk score data is a risky user.
[0074] For example, on the basis of a fixed time zone, the geographical location factor is introduced, the background features of the business flow images in the same time interval and in the same time and space range are extracted, and the data with feature conflicts are analyzed to clarify the risk range. Because the background attribute characteristics of normal users in a fixed geographical location within the same period tend to be consistent, the background of risky users using the same set of attack templates often cannot be adjusted with the change of geographical location, resulting in conflicts. For two sets of conflicting data, risk confirmation can be carried out based on adjacent location references, historical transaction data comparisons, and manual screening.
[0075] It should be noted that in order to improve the accuracy of identifying risky users, the sharing users determined by any of the above methods can be re-checked through the following steps. For example, for two sets of conflicting data, risk re-check can be performed based on reference geographic attribute data of adjacent transaction locations of transaction locations, biopsy facial images of adjacent transaction times of transaction times, or manual screening. Based on this, before step 130, the method for intercepting facial recognition attacks can also include steps 2108 and 2109.
[0076] Step 2108, based on the risk verification data, re-inspect the background area of the biopsy face images of at least two users in the image cluster to obtain re-inspection result data; wherein the risk verification data includes at least one of the following data: reference geographic attribute data of adjacent transaction locations of the transaction location, biopsy face images of adjacent transaction times of the transaction time.
[0077] Step 2109: When the data value of the re-inspection result data is higher than or equal to the fourth preset threshold, determine that the user corresponding to the content matching data is a risky user.
[0078] For example, in order to improve the accuracy of determining risky users, the reference geographic attribute data of the adjacent transaction locations of the transaction location and the biopsy face images of the adjacent transaction times of the transaction time can be further referenced to further clarify the real attributes, and then the abnormal value users in the problem group are marked as risky, and manual review can be performed if the cost is controllable. In the embodiment of the present application, it is more suitable to use adjacent locations for judgment for large-scale attribute features such as weather, time, etc., while it is more suitable to use similar time for small-scale attribute features.
[0079] In addition, after step 130, a step of using the intercepted data is also included. In the embodiment of the present application, the intercepted data can be used to intercept at least one of the following face recognition attacks: a face recognition attack related to the risky user, and a face recognition attack related to the electronic device of the risky user. Based on this, the method for intercepting face recognition attacks in the embodiment of the present application may also include:
[0080] Step 140, based on the interception data, sending an interception instruction to the detection terminal corresponding to the risky user;
[0081] The detection end includes at least one of the following: an electronic device of the risk user, a face detection system for checking a biopsy face image of the risk user;
[0082] The interception instruction includes at least one of the following: a first interception instruction and a second interception instruction; the first interception instruction is used to instruct the electronic device of the risky user to increase the difficulty level of the biopsy for the risky user; the second interception instruction is used to instruct the face detection system to increase the hack detection interception gear for the biopsy face image of the risky user.
[0083] For example, risk tagging requires tagging two dimensions: user and device. Through the two-way association between device and user, more potential or missed attack behaviors can be discovered. For risk-tagged users or devices, the relevant risk strategies can be adjusted according to the specific business scenarios. The risk strategies can affect the biopsy difficulty in the front-end collection process and the response level of the back-end hack detection service.
[0084] Therefore, the embodiment of the present application can be based on two detection methods, pixel-level consistency analysis and background attribute conflict, to target the time and space characteristics of illegal attacks on face recognition, quickly and accurately discover and identify potential attack targets in a large number of daily transaction flows, and mark target risk users and devices from the perspective of post-processing. Different from traditional methods, it fully utilizes the attack characteristics of face scenes, focuses on local abnormal data, reduces the cost of attack screening, cooperates with the issuance of multi-stage risk control parameters, flexibly controls the risks of face services, and implements interception as efficiently as possible while ensuring the pass rate of normal users.
[0085] It should be noted that in the embodiment of the present application, the biopsy face image is obtained through a liveness detection process. Specifically, when the electronic device is performing the liveness detection stage, it will prompt the user to adjust the position of the electronic device so that the face is moved to the coverage range of the face collection preview control displayed by the electronic device. The user holding the electronic device will cause the electronic device to undergo obvious deflection or acceleration changes, so that the electronic device collects the transformation information of the electronic device. When the user adjusts the position of the electronic device so that it can collect the user's complete face image, at least one frame of the biopsy face image in the face collection preview control can be collected.
[0086] It should be noted that the method for intercepting facial recognition attacks provided in the embodiments of the present application can be applied to scenarios where biopsy facial images are required for identity verification, such as financial payment, access control, account login authentication, and other scenarios that require verification of the user's true identity.
[0087] To facilitate understanding, the following describes the process of a method for intercepting face recognition attacks applied to a computer device in an embodiment of the present application.
[0088] Figure 3 A flowchart of a method for intercepting face recognition attacks provided in an embodiment of the present application.
[0089] like Figure 3 As shown, flow images can be obtained from all business scenarios, and the background of the flow images can be separated. The background area can be divided according to the transaction time and transaction location, so that the users and devices associated with the image can be marked as risks through evaluation, which can be used to guide flexible face risk strategy configuration.
[0090] Based on this, the interception method may include steps f1 to f10.
[0091] In step f1, the transaction data and biopsy face images of N users are obtained. In the actual production business process, the transaction data and biopsy face images sent by the user end can be obtained. For details, please refer to the relevant description of step 110 in the above embodiment, which will not be repeated here.
[0092] In step f2, background feature data is extracted, wherein feature extraction is performed on the background areas in the biopsy face images of N users to obtain background feature data of the biopsy face image of each user.
[0093] Here, the transaction data may include the transaction time and transaction location. Therefore, they can be processed separately, that is, pixel consistency analysis is performed through steps f3 to f4, and multi-factor evaluation of reference geographic attribute data is performed through steps f5 to f7. Based on this, the specific steps are as follows.
[0094] Step f3, clustering the biopsy face images of N users according to the transaction time and based on the background feature data of the biopsy face image of each user to obtain at least one image cluster.
[0095] Step f4, performing pixel consistency comparison on the background areas of the biopsied facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas.
[0096] Step f5, clustering the biopsy face images of N users according to the transaction locations and based on the background feature data of the biopsy face image of each user to obtain at least one image cluster.
[0097] Step f6, for the transaction location, correlation matching may be performed on the background areas of the biopsied face images of at least two users in the image cluster based on the reference geographic attribute data of the transaction location to obtain content matching data.
[0098] Step f7, determining first risk score data based on the pixel comparison data and the first risk confidence level corresponding to the pixel comparison data, and determining second risk score data based on the content matching data and the second risk confidence level corresponding to the content matching data.
[0099] Step f8: Summarize the risk score data of each user based on the first risk score data and the second risk score data.
[0100] In this way, before the risk user is clearly identified and marked as risky, the qualitative extremes can also be verified by cross-evaluation of the two methods. For users who hit both questions, there is a higher risk confidence level, which can appropriately reduce the subsequent manual verification process or further increase the risk level rating, providing more reference information for risk decision-making.
[0101] Step f9: when the risk score data is greater than or equal to the third preset threshold, determining the user corresponding to the risk score data as a risky user.
[0102] Step f10: Based on the interception data, an interception instruction is sent to the detection terminal corresponding to the risky user. For details, please refer to the relevant description of step 130 in the above embodiment, which will not be repeated here.
[0103] Therefore, in terms of time and / or space dimensions, potential attack images can be quickly and accurately discovered and identified in a large amount of daily transaction data. From the perspective of post-transaction handling, the background homogeneity characteristics of illegal facial recognition attacks can be fully utilized. Combined with the fact that the attack image features are naturally different from the discrete features of normal user biopsy facial images and clustered, the biopsy facial images are clustered, thereby determining the biopsy facial images of users with higher risks and the corresponding interception data, thereby intercepting facial recognition attacks related to risky users, flexibly controlling the risks of facial services, and, on the premise of ensuring the identity authentication pass rate of normal users, intercepting facial recognition attacks of risky users as much as possible after the transaction occurs, avoiding potential or missed facial recognition attacks, and improving the accuracy of intercepting facial recognition attacks.
[0104] The present application also provides a device for intercepting face recognition attacks, specifically combining Figure 4 Provide detailed explanation.
[0105] Figure 4 It is a structural diagram of an interception device for face recognition attacks provided by an embodiment of the present application.
[0106] In some embodiments of the present application, Figure 4 The device for intercepting facial recognition attacks shown can be set in the computer device provided in the embodiment of the present application.
[0107] like Figure 4 As shown, the interception device 40 for face recognition attacks may specifically include:
[0108] The acquisition module 401 is used to acquire transaction data and biopsy face images of N users in a first time window, where the transaction data includes at least one of the following: transaction time and transaction location, and N is an integer greater than 1;
[0109] A division module 402 is used to divide the biopsy face images of N users based on the transaction data to obtain at least one image cluster, where the image cluster includes the biopsy face images of at least two users with similar background areas, where the background area is a non-face area in the biopsy face images;
[0110] The determination module 403 is used to determine the interception data of the risky user corresponding to the biopsy face image in the image cluster, where the interception data is used to indicate the interception of the face recognition attack related to the risky user within the second time window.
[0111] In this way, the interception device for facial recognition attacks in the embodiment of the present application can obtain transaction data and biopsy facial images of N users within a first time window, and the transaction data includes at least one of the following: transaction time and transaction location; and based on the transaction data, the biopsy facial images of N users are divided to obtain at least one image cluster, and the image cluster includes biopsy facial images of at least two users with similar background areas, and the background area is the non-face area in the biopsy facial image; then, the interception data of the risky user corresponding to the biopsy facial image in the image cluster is determined, and the interception data is used to indicate the interception of facial recognition attacks related to the risky user in the second time window. In this way, with respect to the time and / or space dimensions, potential attack images can be quickly and accurately discovered and identified in a large amount of daily transaction data. From the perspective of post-transaction handling, the background homogeneity characteristics of illegal facial recognition attacks can be fully utilized. Combined with the fact that the attack image features are naturally different from the discrete features of the biopsy facial images of normal users and clustered, the biopsy facial images are clustered, thereby determining the biopsy facial images of users with higher risks and the corresponding interception data, thereby intercepting facial recognition attacks related to risky users, flexibly controlling the risks of facial services, and, on the premise of ensuring the identity authentication pass rate of normal users, intercepting facial recognition attacks of risky users as much as possible after the transaction occurs, avoiding potential or missed facial recognition attacks, and improving the accuracy of intercepting facial recognition attacks.
[0112] The following is a detailed description of the interception device 40 for face recognition attacks in the embodiments of the present application.
[0113] In some embodiments of the present application, the segmentation module 402 may be specifically used to extract features of background areas in the biopsied face images of N users based on the transaction data to obtain background feature data of the biopsied face image of each user;
[0114] Based on the background feature data of the biopsy face image of each user, the biopsy face images of N users are clustered to obtain at least one image cluster.
[0115] In some embodiments of the present application, the partitioning module 402 may be specifically configured to cluster the biopsy face images of N users based on the similarity between the background feature data of the biopsy face images of at least two users through an unsupervised clustering algorithm to obtain at least one initial image cluster;
[0116] At least one image cluster is determined from at least one initial image cluster; wherein the image cluster satisfies at least one of the following conditions: the number of biopsy face images in the image cluster is greater than or equal to the number of reference images, and the range of the average centroid distance interval of the image cluster belongs to the range of the reference average centroid distance interval.
[0117] In some embodiments of the present application, the face recognition attack interception device 40 in the embodiment of the present application may further include a comparison module, which is used to perform pixel consistency comparison on background areas of biopsy face images of at least two users in the image cluster when the transaction data includes the transaction time, to obtain pixel comparison data of at least two background areas;
[0118] The determination module 403 may also be configured to, when a data value of the pixel comparison data is greater than or equal to a first preset threshold, determine that at least two users corresponding to the pixel comparison data are risky users.
[0119] In some embodiments of the present application, the comparison module in the embodiments of the present application can be specifically used to perform pixel consistency comparison on the background areas of the biopsy facial images of at least two users in the image cluster through a comparison algorithm to obtain pixel comparison data of at least two background areas; wherein the comparison algorithm includes at least one of the following: a normalized difference square algorithm and a normalized correlation coefficient evaluation algorithm.
[0120] In some embodiments of the present application, the face recognition attack interception device 40 in the embodiment of the present application may further include a matching module, which is used to perform correlation matching on background areas of biopsy face images of at least two users in the image cluster based on reference geographic attribute data of the transaction location when the transaction data includes the transaction location, to obtain content matching data;
[0121] The determination module 403 may also be configured to, when the data value of the content matching data is less than or equal to a second preset threshold, determine that at least two users corresponding to the content matching data are risky users.
[0122] In some embodiments of the present application, the reference geographic attribute data includes at least one of the following: weather condition attribute data, indoor and outdoor environment attribute data, background complexity attribute data, scene function attribute data, and administrative division attribute data.
[0123] In some embodiments of the present application, the face recognition attack interception device 40 in the embodiment of the present application may further include a comparison module for performing pixel consistency comparison on background areas of biopsy face images of at least two users in the image cluster when the transaction data includes transaction time and transaction location, so as to obtain pixel comparison data of at least two background areas;
[0124] Furthermore, the face recognition attack interception device 40 in the embodiment of the present application may further include a matching module for performing correlation matching on background areas of biopsy face images of at least two users in the image cluster based on reference geographic attribute data of the transaction location to obtain content matching data;
[0125] The determination module 403 may also be used to determine risk score data for each of the at least two users based on the pixel comparison data, the first risk confidence level corresponding to the pixel comparison data, the content matching data, and the second risk confidence level corresponding to the content matching data;
[0126] The determination module 403 may also be configured to, when the risk score data is greater than or equal to a third preset threshold, determine that the user corresponding to the risk score data is a risky user.
[0127] In some embodiments of the present application, the face recognition attack interception device 40 in the embodiment of the present application may further include a re-inspection module, which is used to re-inspect the background area of the biopsy face images of at least two users in the image cluster according to the risk verification data to obtain re-inspection result data; wherein the risk verification data includes at least one of the following data: reference geographical attribute data of adjacent transaction locations of the transaction location, and biopsy face images of adjacent transaction times of the transaction time;
[0128] The determination module 403 may also be configured to, when a data value of the re-inspection result data is higher than or equal to a fourth preset threshold, determine that the user corresponding to the content matching data is a risky user.
[0129] In some embodiments of the present application, the face recognition attack interception device 40 in the embodiment of the present application may further include a sending module for sending an interception instruction to a detection terminal corresponding to a risky user based on the interception data;
[0130] The detection end includes at least one of the following: an electronic device of the risk user, a face detection system for checking a biopsy face image of the risk user;
[0131] The interception instruction includes at least one of the following: a first interception instruction and a second interception instruction; the first interception instruction is used to instruct the electronic device of the risky user to increase the difficulty level of the biopsy for the risky user; the second interception instruction is used to instruct the face detection system to increase the hack detection interception gear for the biopsy face image of the risky user.
[0132] The present application also provides a computer device. Figure 5 Provide detailed explanation.
[0133] Figure 5 It is a schematic diagram of the structure of a computer device provided by an embodiment of the present application.
[0134] like Figure 5 As shown, the computer device may include at least one of the following involved in the embodiments of the present application: an electronic device, a server. The computer device may include a processor 501 and a memory 502 storing computer program instructions.
[0135] Specifically, the processor 501 may include a central processing unit (CPU), or an application specific integrated circuit (Application Specific Integrated Circuit (ASTC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0136] The memory 502 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 502 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In appropriate cases, the memory 502 may include a removable or non-removable (or fixed) medium. In appropriate cases, the memory 502 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 502 is a non-volatile solid-state memory. In a specific embodiment, the memory 502 includes a solid-state storage (ROM). In appropriate cases, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM) or a flash memory or a combination of two or more of these.
[0137] The processor 501 reads and executes computer program instructions stored in the memory 502 to implement any one of the methods for intercepting face recognition attacks in the above embodiments.
[0138] In one example, the computer device may further include a communication interface 503 and a bus 510. Figure 5 As shown, the processor 501, the memory 502, and the communication interface 503 are connected via a bus 510 and communicate with each other.
[0139] The communication interface 503 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0140] Bus 510 includes hardware, software or both, and the parts of flow control device are coupled to each other.For example, but not limitation, bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industry standard system (ETSA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard system (TSA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel system (MCA) bus, peripheral component interconnection (PCT) bus, PCT-Express (PCT-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 510 may include one or more buses. Although the present application embodiment describes and shows a specific bus, the application considers any suitable bus or interconnection.
[0141] The face recognition attack detection device can execute the face recognition attack interception method in the embodiment of the present application, thereby realizing the combination of Figures 1 to 4 A method and device for intercepting face recognition attacks are described.
[0142] In addition, in combination with the method for intercepting face recognition attacks in the above embodiments, the embodiment of the present application can provide a computer-readable storage medium for implementation. The computer-readable storage medium stores computer program instructions; when the computer program instructions are executed by the processor, any method for intercepting face recognition attacks in the above embodiments is implemented.
[0143] It should be clear that the present application is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present application.
[0144] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0145] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be performed simultaneously.
[0146] The above are only specific implementation methods of the present application. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the protection scope of the present application is not limited to this. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included in the protection scope of this application.
Claims
1. A method for intercepting face recognition attacks, comprising: Acquire transaction data and biopsy face images of N users within a first time window, wherein the transaction data includes at least one of the following: transaction time and transaction location, where N is an integer greater than 1; Based on the transaction data, the biopsied face images of the N users are divided to obtain at least one image cluster, wherein the image cluster includes the biopsied face images of at least two users having similar background areas, where the background area is a non-face area in the biopsied face images; Determine interception data of a risky user corresponding to the biopsy face image in the image cluster, where the interception data is used to indicate interception of a face recognition attack associated with the risky user within a second time window.
2. The interception method according to claim 1, wherein: The step of dividing the biopsy face images of the N users based on the transaction data to obtain at least one image cluster includes: Based on the transaction data, feature extraction is performed on the background area in the biopsied face images of the N users to obtain background feature data of the biopsied face image of each of the users; Based on the background feature data of the biopsied facial image of each of the users, the biopsied facial images of the N users are clustered to obtain the at least one image cluster.
3. The interception method according to claim 2, wherein: The clustering of the biopsy face images of the N users based on the background feature data of the biopsy face image of each user to obtain the at least one image cluster includes: Clustering the biopsied facial images of the N users based on the similarity between background feature data of at least two of the biopsied facial images of the users using an unsupervised clustering algorithm to obtain at least one initial image cluster; Determine the at least one image cluster from the at least one initial image cluster; wherein the image cluster satisfies at least one of the following conditions: the number of biopsy face images in the image cluster is greater than or equal to the number of reference images, and the range of the average centroid distance interval of the image cluster belongs to the range of the reference average centroid distance interval.
4. The interception method according to any one of claims 1 to 3, wherein: The transaction data includes the transaction time; before determining the interception data of the risk user corresponding to the biopsy face image in the image cluster, the method further includes: Performing pixel consistency comparison on background areas of biopsy facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas; When the data value of the pixel comparison data is greater than or equal to a first preset threshold, at least two users corresponding to the pixel comparison data are determined to be risky users.
5. The interception method according to claim 4, wherein: The step of performing pixel consistency comparison on the background areas of the biopsied facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas includes: Through a comparison algorithm, pixel consistency comparison is performed on the background areas of the biopsy facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas; wherein the comparison algorithm includes at least one of the following: a normalized difference square algorithm and a normalized correlation coefficient evaluation algorithm.
6. The interception method according to any one of claims 1 to 3, wherein: The transaction data includes the transaction location; before determining the interception data of the risk user corresponding to the biopsy face image in the image cluster, the method further includes: Based on the reference geographic attribute data of the transaction location, correlation matching is performed on background areas of the biopsied face images of at least two users in the image cluster to obtain content matching data; When the data value of the content matching data is less than or equal to a second preset threshold, at least two users corresponding to the content matching data are determined to be risky users.
7. The interception method according to claim 6, wherein: The reference geographic attribute data includes at least one of the following: weather condition attribute data, indoor and outdoor environment attribute data, background complexity attribute data, scene function attribute data, and administrative division attribute data.
8. The interception method according to any one of claims 1 to 3, wherein: The transaction data includes the transaction time and the transaction location; before determining that the user corresponding to the content matching data is the risky user, the method further includes: Performing pixel consistency comparison on background areas of biopsied facial images of at least two users in the image cluster to obtain pixel comparison data of at least two background areas; and performing correlation matching on background areas of biopsied facial images of at least two users in the image cluster based on reference geographic attribute data of the transaction location to obtain content matching data; Determining risk score data for each of the at least two users according to the pixel comparison data, the first risk confidence level corresponding to the pixel comparison data, the content matching data, and the second risk confidence level corresponding to the content matching data; When the risk score data is greater than or equal to a third preset threshold, it is determined that the user corresponding to the risk score data is the risky user.
9. The interception method according to claim 4, 6 or 8, wherein: Before determining the interception data of the risky user corresponding to the biopsy face image in the image cluster, the method further includes: According to the risk verification data, the background area of the biopsy face images of at least two users in the image cluster is re-inspected to obtain re-inspection result data; wherein the risk verification data includes at least one of the following data: reference geographical attribute data of adjacent transaction locations of the transaction location, and biopsy face images of adjacent transaction times of the transaction time; When the data value of the re-inspection result data is higher than or equal to a fourth preset threshold, it is determined that the user corresponding to the content matching data is the risky user.
10. The interception method according to claim 1, wherein: The method further comprises: Based on the interception data, sending an interception instruction to a detection terminal corresponding to the risky user; Wherein, the detection end includes at least one of the following: an electronic device of the risk user, a face detection system for checking a biopsy face image of the risk user; The interception instruction includes at least one of the following: a first interception instruction and a second interception instruction; the first interception instruction is used to instruct the electronic device of the risky user to increase the difficulty level of the biopsy for the risky user; the second interception instruction is used to instruct the face detection system to increase the hack detection interception gear of the biopsy face image of the risky user.
11. A device for intercepting face recognition attacks, comprising: An acquisition module, used to acquire transaction data and biopsy face images of N users within a first time window, wherein the transaction data includes at least one of the following: transaction time and transaction location, and N is an integer greater than 1; a segmentation module, configured to segment the biopsied face images of the N users based on the transaction data to obtain at least one image cluster, wherein the image cluster includes biopsied face images of at least two users having similar background areas, wherein the background area is a non-face area in the biopsied face images; A determination module is used to determine interception data of a risky user corresponding to the biopsy face image in the image cluster, wherein the interception data is used to indicate interception of a face recognition attack related to the risky user within a second time window.
12. An electronic device, comprising: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the steps of the method for intercepting face recognition attacks as described in any one of claims 1-10 are implemented.
13. A storage medium storing computer program instructions, wherein the computer program instructions, when executed by a processor, implement the steps of the method for intercepting facial recognition attacks as described in any one of claims 1 to 10.
14. A computer program product, characterized in that The program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the method for intercepting face recognition attacks as described in any one of claims 1-10.
Citation Information
Cited By
Method and apparatus for intercepting face recognition attack, and device and storage medium
WO2026157289A1