A centralized dynamic verification and risk defense method based on face data
By collecting multidimensional dynamic biological indicators and environmental risk factors, and combining them with an adversarial generative verification model for comprehensive evaluation, the problem of high false recognition and false recognition rates in existing face recognition technologies has been solved, achieving more comprehensive risk defense and model optimization.
Patent Information
- Application Number
- CN202510642666.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-05-19
AI Technical Summary
Existing facial recognition technologies have high false recognition and false negative rates when faced with sophisticated forgery and risk assessment. They lack centralized integration and assessment of biometric dynamic characteristics, environment and history, and cannot form a complete closed-loop security system.
By collecting multidimensional dynamic biological indicators, such as micro-expression changes, iris dynamic response and facial blood flow waveform characteristics, combined with environmental risk factors and historical behavioral patterns, an adversarial generative validation model is used for comprehensive evaluation, and an adaptive defense mechanism and model update are triggered when the risk exceeds the threshold.
It significantly improves the ability to detect deepfakes and attack methods, reduces the false recognition rate and false negative rate, achieves comprehensive security control over the face verification environment, and can immediately activate multi-layered defense measures and optimize model discrimination boundaries.
Smart Images

Figure CN120564277B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of dynamic verification technology of facial data, specifically relating to a centralized dynamic verification and risk defense method based on facial data. Background Technology
[0002] With the rapid development of artificial intelligence technology, facial recognition technology, with its advantages of being contactless, highly convenient, and having a high recognition rate, has become one of the core tools for information management in universities. Currently, facial recognition technology is widely used in university access control, dormitory attendance, cafeteria payments, unified identity authentication, and new student identity verification, significantly improving campus management efficiency and the service experience for faculty and students. However, with the deepening expansion of facial data application scenarios, the issue of its full lifecycle security management is becoming increasingly prominent. In particular, multiple security risks exist in the data collection, storage, third-party access, distribution, and destruction stages, seriously threatening the personal information security of faculty and students and triggering widespread public concern about the misuse of the technology.
[0003] Existing liveness detection methods typically determine whether a person is alive by analyzing static facial images (such as interactive actions like blinking, opening the mouth, and head turning) or simple near-infrared reflection signals. However, these methods still have high false positive and false negative rates when dealing with sophisticated forgeries (such as the use of high-precision 3D-printed masks and AI-synthesized micro-expressions). On the other hand, existing risk control methods are mostly based on traditional environmental factors (such as IP addresses and device fingerprints) or single behavioral characteristics for risk control scoring, but they lack a centralized integrated assessment of biometric dynamic characteristics, environment, and history, and do not incorporate adaptive defense strategies and online model update mechanisms, thus failing to form a complete closed-loop security system. Summary of the Invention
[0004] The purpose of this invention is to provide a centralized dynamic verification and risk defense method based on facial data, which can extract multi-dimensional dynamic biometrics in real time, combine environmental risk factors and historical behavior vectors for comprehensive evaluation, and adaptively trigger hierarchical defense and online model / factor updates when the risk exceeds the threshold.
[0005] The specific technical solution adopted by this invention is as follows:
[0006] A centralized dynamic verification and risk prevention method based on facial data includes:
[0007] The raw biometric data of the target object is collected. The raw biometric data includes visible light face images, near-infrared live features and three-dimensional facial topology. Based on the raw biometric data, time-series processing is performed to extract dynamic biometric indicators, including micro-expression change coefficients, iris dynamic response parameters and facial blood flow waveform features.
[0008] Dynamic biometrics are input into a pre-trained adversarial generative validation model, and facial credibility scores are generated through feature space mapping and comparison.
[0009] The system obtains environmental risk factors and historical behavior patterns, and combines them with facial credibility scores to obtain a comprehensive risk value. Environmental risk factors include device credibility scores, network topology anomaly index, and geographical location offset.
[0010] When the acquired comprehensive risk value exceeds the preset threshold, the corresponding defense mechanism is triggered. The adversarial generation verification model is updated according to the defense effect of the corresponding defense mechanism, and the environmental risk factor is adjusted.
[0011] In a preferred embodiment, the steps of inputting dynamic biometrics into a pre-trained adversarial generative validation model and generating facial credibility scores through feature space mapping and comparison include:
[0012] Based on dynamic biometrics, obtain the corresponding micro-expression change vector, iris dynamic response vector, and facial blood flow waveform vector;
[0013] The micro-expression change vector, iris dynamic response vector, and facial blood flow waveform vector are input into the pre-trained adversarial generative validation model, and the output results are labeled as biometric values.
[0014] Obtain the indicator table, which includes multiple biometric value ranges and the facial credibility score corresponding to each biometric value range;
[0015] The facial credibility score is obtained from the indicator table based on the range of biometric values corresponding to the biometric values.
[0016] In a preferred embodiment, the steps of obtaining environmental risk factors and historical behavioral patterns, and combining them with facial credibility scores to obtain a comprehensive risk value, whereby environmental risk factors include device credibility scores, network topology anomaly indices, and geographic location offsets, include:
[0017] Obtain environmental risk factors and historical behavior patterns, including equipment trustworthiness scores, network topology anomaly index, and geographical location offset.
[0018] Obtain multiple historical behavior vectors based on historical behavior patterns;
[0019] A comprehensive risk value is obtained based on device credibility score, network topology anomaly index, geographic location offset, multiple historical behavior vectors, and facial credibility score.
[0020] In a preferred embodiment, when the acquired comprehensive risk value exceeds a preset threshold, a corresponding defense mechanism is triggered. The steps of updating the adversarial generation verification model and adjusting the environmental risk factors based on the defense effect of the corresponding defense mechanism include:
[0021] Obtain the comprehensive risk threshold and determine whether the comprehensive risk value exceeds the comprehensive risk threshold;
[0022] If the overall risk value exceeds the overall risk threshold, the face data is determined to be abnormal, and the overall risk value is marked as an abnormal risk value.
[0023] Obtain the defense table, which includes multiple abnormal risk value ranges and the corresponding defense mechanism for each abnormal risk value range;
[0024] The corresponding defense mechanism is obtained from the risk table based on the abnormal risk value range corresponding to the abnormal risk value. The defense mechanism includes low encryption mechanism for biometric obfuscation, medium encryption mechanism for biometric obfuscation, and high encryption mechanism for biometric obfuscation.
[0025] The adversarial generation and verification model is updated based on the defense effectiveness of the corresponding defense mechanism, and the environmental risk factor is adjusted.
[0026] In a preferred embodiment, the steps of updating the adversarial generation verification model based on the defense effectiveness of the corresponding defense mechanism and adjusting the environmental risk factors include:
[0027] When the defense mechanism is a low-encryption biometric obfuscation mechanism, the low-encryption biometric obfuscation mechanism is executed, and the low-encryption defense effect is obtained. The adversarial generation verification model is updated based on the low-encryption defense effect, and the environmental risk factor is adjusted.
[0028] When the defense mechanism is a biometric obfuscation and encryption mechanism, the biometric obfuscation and encryption mechanism is executed, the encryption defense effect is obtained, the adversarial generation verification model is updated based on the encryption defense effect, and the environmental risk factor is adjusted.
[0029] When the defense mechanism is a biometric obfuscation high encryption mechanism, the biometric obfuscation high encryption mechanism is executed, and the high encryption defense effect is obtained. The adversarial generation verification model is updated based on the high encryption defense effect, and the environmental risk factor is adjusted.
[0030] In a preferred embodiment, when the defense mechanism is a biometric obfuscation low-encryption mechanism, the steps of executing the biometric obfuscation low-encryption mechanism, obtaining the low-encryption defense effect, updating the adversarial generation verification model based on the low-encryption defense effect, and adjusting the environmental risk factors include:
[0031] When the defense mechanism is a biometric obfuscation low-encryption mechanism, then the biometric obfuscation low-encryption mechanism is executed.
[0032] Obtain the low encryption defense effect after implementing the biometric obfuscation low encryption mechanism, wherein the low encryption defense effect includes low encryption latency;
[0033] Obtain the low encryption latency time threshold and determine whether the low encryption latency time exceeds the low encryption latency time threshold;
[0034] If the low encryption latency threshold does not exceed the low encryption latency time threshold, the low encryption defense effect is determined to be stable, and the low encryption stability adjustment strategy is triggered. The adversarial generation verification model is updated according to the low encryption stability strategy, and the environmental risk factor is adjusted.
[0035] If the low encryption latency threshold exceeds the low encryption latency time threshold, the low encryption defense effect is determined to be abnormal. The low encryption update table is then obtained, which includes multiple low encryption latency time intervals and a corresponding low encryption abnormal update strategy for each low encryption latency time interval. The corresponding low encryption abnormal update strategy is obtained from the low encryption update table according to the low encryption latency time interval corresponding to the low encryption latency time. The adversarial generation verification model is then updated according to the low encryption abnormal update strategy, and the environmental risk factor is adjusted.
[0036] In a preferred embodiment, when the defense mechanism is a biometric obfuscation-within-encryption mechanism, the steps of executing the biometric obfuscation-within-encryption mechanism, obtaining the effectiveness of the obfuscation defense, updating the adversarial generation verification model based on the effectiveness of the obfuscation defense, and adjusting the environmental risk factors include:
[0037] When the defense mechanism is encryption within biometric obfuscation, then the encryption within biometric obfuscation is executed.
[0038] The effectiveness of the encryption defense after implementing the encryption mechanism in the biometric obfuscation is obtained. The effectiveness of the encryption defense includes the success rate of the encryption attack interception and the false positive rate of the encryption biometric verification.
[0039] Obtain the threshold for the success rate of intercepting medium-encryption attacks and the threshold for the false alarm rate of medium-encryption biometric verification, and determine whether the success rate of intercepting medium-encryption attacks is lower than the threshold for the success rate of intercepting medium-encryption attacks and whether the false alarm rate of medium-encryption biometric verification is higher than the threshold for the false alarm rate of medium-encryption biometric verification.
[0040] If the success rate of intercepting Chinese encryption attacks is higher than the threshold for the success rate of Chinese encryption attack interception, and the false alarm rate of Chinese encryption biometric verification is lower than the threshold for the false alarm rate of Chinese encryption biometric verification, then the Chinese encryption defense effect is determined to be secure, the adversarial generation verification model is not updated, and the environmental risk factor is not adjusted.
[0041] If the success rate of intercepting medium-encryption attacks is lower than the threshold for the success rate of medium-encryption attack interception, and the false positive rate of medium-encryption biometric verification is lower than the threshold for the false positive rate of medium-encryption biometric verification, then the medium-encryption defense effect is determined to be an interception anomaly. An environmental factor adjustment table is obtained, which includes multiple medium-encryption attack interception success rate intervals and environmental risk factor adjustment strategies corresponding to each medium-encryption attack interception success rate interval. The corresponding environmental risk factor adjustment strategy is obtained from the environmental factor adjustment table according to the medium-encryption attack interception success rate interval, and the environmental risk factors are adjusted according to the environmental risk factor adjustment strategy, without updating the adversarial generation verification model.
[0042] If the success rate of intercepting Chinese encryption attacks is higher than the threshold for the success rate of Chinese encryption attack interception, and the false positive rate of Chinese encryption biometric verification is higher than the threshold for the false positive rate of Chinese encryption biometric verification, then the Chinese encryption defense effect is determined to be biometric anomaly. An adversarial update table is obtained, which includes multiple false positive rate intervals for Chinese encryption biometric verification and the corresponding adversarial generation verification model update strategy for each Chinese encryption biometric verification false positive rate interval. The corresponding adversarial generation verification model update strategy is obtained from the adversarial update table according to the Chinese encryption biometric verification false positive rate interval, and the adversarial generation verification model is updated according to the adversarial generation verification model update strategy without adjusting the environmental risk factor.
[0043] If the success rate of intercepting medium-encryption attacks is lower than the threshold for medium-encryption attack interception success rate, and the false positive rate of medium-encryption biometric verification is higher than the threshold for medium-encryption biometric verification false positive rate, then the medium-encryption defense effect is determined to be biometric anomaly. An environmental factor adjustment table and an adversary update table are then obtained. The environmental factor table includes multiple medium-encryption attack interception success rate intervals and corresponding environmental risk factor adjustment strategies for each interval. The adversary update table includes multiple medium-encryption biometric verification false positive rate intervals and corresponding adversary generation verification model update strategies for each interval. Based on the medium-encryption attack interception success rate interval, the corresponding environmental risk factor adjustment strategy is obtained from the environmental factor adjustment table. Based on the medium-encryption biometric verification false positive rate interval, the corresponding adversary generation verification model update strategy is obtained from the adversary update table. The adversary generation verification model is updated according to the adversary generation verification model update strategy, and the environmental risk factors are adjusted according to the environmental risk factor adjustment strategy.
[0044] In a preferred embodiment, when the defense mechanism is a biometric obfuscation high-encryption mechanism, the steps of executing the biometric obfuscation high-encryption mechanism, obtaining the high-encryption defense effect, updating the adversarial generation verification model based on the high-encryption defense effect, and adjusting the environmental risk factors include:
[0045] When the defense mechanism is a biometric obfuscation and high encryption mechanism, then the biometric obfuscation and high encryption mechanism is executed.
[0046] The high encryption defense effect after implementing the biometric obfuscation high encryption mechanism is obtained. The high encryption defense effect includes high encryption latency, high encryption attack interception success rate and high encryption biometric verification false alarm rate.
[0047] Normalization is performed based on high encryption latency, high encryption attack interception success rate and high encryption biometric verification false alarm rate to obtain encryption latency value, attack interception success value and biometric verification value.
[0048] A high encryption overall value is obtained based on the encryption delay value, attack interception success value, and biometric verification value.
[0049] Obtain the comprehensive mechanism table, which includes multiple high-encryption comprehensive value ranges and the comprehensive processing strategy corresponding to each high-encryption comprehensive value range;
[0050] Based on the high-encryption comprehensive value range corresponding to the high-encryption comprehensive value, the corresponding comprehensive processing strategy is obtained from the comprehensive mechanism table, and the adversarial generation verification model is updated according to the comprehensive processing strategy, and the environmental risk factor is adjusted.
[0051] In a preferred embodiment, it also includes:
[0052] When the defense mechanism is triggered more than the preset number of times, the face data destruction policy is activated.
[0053] The original biometric data and related historical behavioral patterns of the target object are destroyed according to the facial data destruction strategy;
[0054] Perform a manual data entry procedure to re-enter the original biometric data of the target object.
[0055] And, a centralized dynamic verification and risk defense terminal based on facial data, comprising:
[0056] One or more processors;
[0057] A storage device on which one or more programs are stored;
[0058] When one or more programs are executed by one or more processors, the one or more processors implement a centralized dynamic verification and risk defense method based on face data.
[0059] The technical effects achieved by this invention are as follows:
[0060] This invention significantly improves the detection capability against attacks such as deepfakes, face masks, and screenshots by integrating multi-dimensional dynamic indicators such as micro-expressions, iris responses, and blood flow fluctuations. It reduces the false recognition and false negative rates and incorporates external risks such as device integrity, network security, and geographical location deviations into a comprehensive assessment. It not only focuses on the face itself but also provides security control over the entire verification environment, achieving more comprehensive defense. Once a threshold alarm is triggered, multi-layered defense measures can be activated immediately, and the defense results can be fed back to the model to continuously optimize the discrimination boundary of the adversarial generation network, ensuring high efficiency and robustness in long-term operation. Attached Figure Description
[0061] Figure 1 This is a flowchart of the method provided by the present invention. Detailed Implementation
[0062] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0063] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0064] Secondly, the term "an embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in a preferred embodiment" appearing in different places throughout this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that mutually excludes other embodiments.
[0065] Furthermore, the present invention will be described in detail with reference to the schematic diagrams. When describing the embodiments of the present invention in detail, the schematic diagrams are merely examples for ease of explanation and should not limit the scope of protection of the present invention.
[0066] Please see the appendix Figure 1 As shown, a centralized dynamic verification and risk defense method based on facial data is provided, including:
[0067] S1. Collect the original biometric data of the target object. The original biometric data includes visible light face images, near-infrared live features and three-dimensional facial topology. Based on the original biometric data, perform time-series processing to extract dynamic biometric indicators including micro-expression change coefficients, iris dynamic response parameters and facial blood flow waveform features.
[0068] S2. Input dynamic biometrics into a pre-trained adversarial generative verification model, and generate facial credibility scores through feature space mapping and comparison.
[0069] S3. Obtain environmental risk factors and historical behavior patterns, and combine them with facial credibility scores to obtain a comprehensive risk value. Environmental risk factors include device credibility scores, network topology anomaly index, and geographical location offset.
[0070] S4. When the obtained comprehensive risk value exceeds the preset threshold, the corresponding defense mechanism is triggered. The adversarial generation verification model is updated according to the defense effect of the corresponding defense mechanism, and the environmental risk factor is adjusted.
[0071] As described in steps S1 to S4 above, multi-source biometric data of the target object are collected simultaneously. Visible light facial images provide high-resolution texture information, near-infrared liveness features are used to penetrate shallow camouflage, and three-dimensional facial topology reflects facial geometry. The collected time-series data is preprocessed, including face alignment, denoising, and standardization. Then, deep micro-expression change coefficients (revealing subtle muscle movements), iris dynamic response parameters (reflecting changes in iris brightness and shape under light stimulation), and facial blood flow waveform features (mapping blood pulsation patterns through optical blood oxygenation signals) are extracted. The dynamic biometric indicators are input into a pre-trained adversarial generative network verification model. The credibility score is calculated according to the formula within the model to quantify whether the target is a real living being and resist threats such as deepfakes and photo / mask attacks. Environmental risk factors are monitored in real time, including device credibility score (based on device firmware integrity, self-identification, etc. to determine whether the terminal has been tampered with), network topology anomaly index (to determine whether there is a man-in-the-middle attack or traffic hijacking in the network link), and location. The system calculates an overall "comprehensive risk value" by combining environmental risk factors with facial credibility scores, based on the location offset (a measure of deviation between the current location and the historical authorized location). When the comprehensive risk value exceeds a preset threshold, corresponding defense strategies are automatically triggered. Simultaneously, the parameters of the adversarial generative verification model are adjusted based on the actual interception effect of the defense strategies, and the environmental factor weights are dynamically updated to form a closed-loop optimization, enhancing the accuracy and efficiency of subsequent recognition. By integrating multi-dimensional dynamic indicators such as micro-expressions, iris responses, and blood flow fluctuations, the system significantly improves the detection capabilities against attacks such as deepfakes, face masks, and screenshots, reducing false recognition and false negative rates. External risks such as device integrity, network security, and geographical location deviations are integrated into the comprehensive assessment, focusing not only on the face itself but also on the security control of the entire verification environment, achieving more comprehensive defense. Once a threshold alarm is triggered, multi-layered defense measures can be activated immediately, and the defense results are fed back to the model to continuously optimize the discrimination boundary of the adversarial generative network, ensuring high efficiency and robustness in long-term operation.
[0072] In a preferred implementation, the step of inputting dynamic biometrics into a pre-trained adversarial generative verification model and generating facial credibility scores through feature space mapping includes:
[0073] S201. Obtain the corresponding micro-expression change vector, iris dynamic response vector and facial blood flow waveform vector based on dynamic bioindicators;
[0074] S202. Input the micro-expression change vector, iris dynamic response vector and facial blood flow waveform vector into the pre-trained adversarial generative validation model, and label the output results as biometric values.
[0075] S203. Obtain the indicator table, which includes multiple biometric value ranges and the facial credibility score corresponding to each biometric value range.
[0076] S204. Obtain the corresponding facial credibility score from the indicator table based on the range of biometric values corresponding to the biometric values.
[0077] As described in steps S201 to S204 above, the micro-expression change coefficients, iris dynamic response parameters, and facial blood flow waveform features obtained after time-series processing are vectorized. The micro-expression change vector describes the amplitude and rate of movement of key facial muscle groups at each time step; the iris dynamic response vector depicts the contraction and relaxation curves of the iris under different light or stress conditions; and the facial blood flow waveform vector reflects the periodicity and amplitude of blood pulsation on the skin surface. This vectorization process can use a temporal convolutional network or a recurrent neural network to extract the feature distribution in the time dimension while preserving the local patterns in the spatial dimension. The formula for calculating biometric values in the pre-trained adversarial generative validation model is S = W·H·M, where S represents the biometric value, W represents the micro-expression change vector, H represents the iris dynamic response vector, and M represents the... The facial blood flow waveform vector outputs a biometric value. Based on a large number of validation samples, the biometric value is statistically processed, dividing the value range into several intervals. Each interval is pre-assigned a corresponding facial credibility score, for example, a low interval corresponds to "low credibility" and a high interval corresponds to "high credibility". The biometric value of the current frame or time period is read in real time to determine which predefined interval it falls into. The corresponding facial credibility score is quickly retrieved and returned from the index mapping table. The pre-trained model only needs to perform forward computation to obtain the biometric value during the inference phase. Combined with the pre-built mapping table, it can achieve millisecond-level facial credibility score output, meeting the needs of high-concurrency scenarios. The mapping table between index value intervals and credibility scores provides a clear quantitative standard, which makes it convenient for security policy makers to adjust the interval division or score level according to business needs, realizing a more flexible risk management strategy.
[0078] In a preferred embodiment, the steps of obtaining environmental risk factors and historical behavioral patterns, and combining them with facial credibility scores to obtain a comprehensive risk value, whereby environmental risk factors include device credibility scores, network topology anomaly indices, and geographic location offsets, include:
[0079] S301. Obtain environmental risk factors and historical behavior patterns, including equipment trustworthiness scores, network topology anomaly index, and geographical location offset.
[0080] S302. Obtain multiple historical behavior vectors based on historical behavior patterns;
[0081] S303. Obtain a comprehensive risk value based on device credibility score, network topology anomaly index, geographical location offset, multiple historical behavior vectors, and facial credibility score.
[0082] As described in steps S301 to S303 above, three types of environmental risk factors are retrieved from the server or security monitoring platform: Device Trustworthiness Score, a score derived from firmware integrity checks, root certificate chain verification, and hardware anti-tampering detection of the terminal device; Network Topology Anomaly Index, which detects anomalies such as man-in-the-middle attacks, traffic replay, and DNS tampering through network traffic monitoring and traffic behavior analysis, and quantifies them into an index value; and Geographic Location Offset, which calculates the distance or regional deviation between the current device location and the user's historical authorized area (such as frequently used cities or office buildings) to obtain an offset metric. Simultaneously, the user's historical behavior patterns (such as recent login time distribution, terminal type switching frequency, and operation path habits) are queried, and these patterns are mapped to vectors. This vectorization can employ autoencoder or embedded vector technology to compress multi-dimensional log information into a fixed-dimensional set of historical behavior vectors. The Device Trustworthiness Score, Network Topology Anomaly Index, Geographic Location Offset, multiple historical behavior vectors, and Facial Trustworthiness Score are input into the comprehensive risk value calculation formula, outputting a comprehensive risk value. The formula for calculating the comprehensive risk value is as follows: In the formula, Z represents the comprehensive risk value, k represents the device trustworthiness score, p represents the network topology anomaly index, d represents the geographic location offset, S represents the biometric value, and i represents the number of multiple historical behavior vectors, i = 1, 2, 3…n, X i Represented as the i-th historical behavior vector, it not only relies on a single biometric result, but also incorporates multi-source information such as terminal, network and geography into the evaluation, realizing multi-dimensional risk insight through human-machine-environment linkage. By introducing historical behavior vectors, it can identify atypical usage habits and potential account hijacking scenarios, and improve the ability to defend against risks that may exist even if liveness detection is passed.
[0083] In a preferred embodiment, when the acquired comprehensive risk value exceeds a preset threshold, a corresponding defense mechanism is triggered. The steps of updating the adversarial generation verification model and adjusting the environmental risk factors based on the defense effect of the corresponding defense mechanism include:
[0084] S401. Obtain the comprehensive risk threshold and determine whether the comprehensive risk value exceeds the comprehensive risk threshold;
[0085] If the overall risk value exceeds the overall risk threshold, the face data is determined to be abnormal, and the overall risk value is marked as an abnormal risk value.
[0086] S402. Obtain the defense table, which includes multiple abnormal risk value ranges and the defense mechanism corresponding to each abnormal risk value range.
[0087] S403. Obtain the corresponding defense mechanism from the risk table based on the abnormal risk value range corresponding to the abnormal risk value. The defense mechanism includes a low-encryption mechanism for biometric obfuscation, a medium-encryption mechanism for biometric obfuscation, and a high-encryption mechanism for biometric obfuscation.
[0088] S404. Update the adversarial generation verification model based on the defense effect of the corresponding defense mechanism, and adjust the environmental risk factor.
[0089] As described in steps S401 to S404 above, a "comprehensive risk threshold" is pre-set to distinguish between normal and abnormal face verification scenarios. The current comprehensive risk value is obtained in real time and compared with the threshold. If the comprehensive risk value > the threshold, the face data is determined to be abnormal, and the value is marked as an "abnormal risk value," initiating the defense process. Otherwise, the risk is considered acceptable, and the normal process continues without triggering defense. The defense table is a mapping table containing several "abnormal risk value intervals" and their corresponding "defense mechanisms." Based on which interval the current "abnormal risk value" falls into, the corresponding "defense mechanism" is obtained by looking up the table. Examples of defense mechanisms include: a low-encryption biometric obfuscation mechanism, which lightly perturbs and encrypts dynamic biometric data to ensure traceability while increasing the difficulty of attacks; a medium-encryption biometric obfuscation mechanism, which uses more complex sequence obfuscation and encryption algorithms combined with randomized noise to combat common forgery attacks; and a high-encryption biometric obfuscation mechanism, which provides full-link protection. End-to-end encryption, along with the introduction of timing perturbations and multi-signatures, maximizes protection. The selected defense mechanism is immediately executed to protect or isolate subsequent data streams or storage, and may alert the security operations center. Based on the actual interception effect of the defense mechanism (such as attack success, false alarm rate, interception delay, etc.), the pre-trained adversarial generation verification model is fine-tuned or retrained to improve the ability to identify new attack samples. Combining environmental data such as device trustworthiness, network anomalies, and geographical offsets in this incident, the weights or threshold ranges of environmental risk factors are dynamically adjusted to optimize the sensitivity and accuracy of the next round of risk assessment. Low / medium / high-strength encryption and obfuscation strategies are flexibly selected according to the degree of anomaly, avoiding the performance overhead of over-protection and enabling rapid upgrades to defense strength in high-risk scenarios. Through real-time feedback on the defense effect, the adversarial generation verification model is continuously updated, enabling rapid absorption of new attack samples and improving the ability to defend against unknown threats.
[0090] In a preferred embodiment, the steps of updating the adversarial generation verification model based on the defense effectiveness of the corresponding defense mechanism and adjusting the environmental risk factors include:
[0091] S404a. When the defense mechanism is a biometric obfuscation low encryption mechanism, execute the biometric obfuscation low encryption mechanism, obtain the low encryption defense effect, update the adversarial generation verification model based on the low encryption defense effect, and adjust the environmental risk factor.
[0092] S404b. When the defense mechanism is a biometric obfuscation and encryption mechanism, execute the biometric obfuscation and encryption mechanism, obtain the encryption defense effect, update the adversarial generation verification model based on the encryption defense effect, and adjust the environmental risk factor.
[0093] S404c When the defense mechanism is a biometric obfuscation high encryption mechanism, execute the biometric obfuscation high encryption mechanism and obtain the high encryption defense effect. Update the adversarial generation verification model based on the high encryption defense effect and adjust the environmental risk factor.
[0094] As mentioned above, among the three defense mechanisms S404a, S404b, and S404c, when the "biometric obfuscation low-encryption mechanism" is selected, the collected dynamic biometric data is lightly perturbed and symmetrically encrypted, while retaining sufficient discriminative information for normal verification. The actual interception and discrimination performance indicators under this mechanism are monitored, and the collected real and attack samples and their defense results are fed back to the adversarial generation verification model. Online fine-tuning or incremental training is used to adjust the sensitivity to lightly perturbed forged samples. Based on the device reliability and network stability performance in the low-encryption scenario, the adversarial generation verification model is updated, and the environmental risk factor is adjusted. When the "biometric obfuscation medium-encryption mechanism" is selected, random noise injection and multi-channel sequence obfuscation are introduced, and the dynamic vector is moderately perturbed and protected with asymmetric encryption. Based on the adversarial samples and feedback data collected under the medium-encryption strategy, combined with network load and geographic location drift data in the medium-encryption scenario, the adversarial generation verification model is dynamically updated, and the environmental risk factor is adjusted. When employing a "high-level encryption mechanism" to obfuscate and confuse, multiple protections are implemented for dynamic biometrics, combining end-to-end encryption, temporal perturbation, and digital signatures to ensure the highest level of data confidentiality and integrity. Attack samples and real samples under high-encryption conditions are fed back to the adversarial generative model for batch retraining or adversarial training to improve the model's discrimination accuracy under extreme perturbation conditions. Based on the device stability issues or network bottlenecks exposed by this high-intensity defense, the adversarial generative verification model is updated, and environmental risk factors are adjusted. Different encryption mechanisms are used to defend against and provide model feedback for light, medium, and high attack intensities, ensuring that the discriminator can obtain customized training samples under various perturbation conditions, achieving accurate and hierarchical capability improvement. An adaptive defense strategy is adopted, switching to medium and high-intensity encryption only when necessary, avoiding high-overhead one-size-fits-all measures, balancing security and system performance. Factor adjustments after each defense make the environmental risk assessment more in line with the actual scenario, reducing the false alarm rate, and improving sensitivity to new threats.
[0095] In a preferred embodiment, when the defense mechanism is a biometric obfuscation low-encryption mechanism, the steps of executing the biometric obfuscation low-encryption mechanism, obtaining the low-encryption defense effect, updating the adversarial generation verification model based on the low-encryption defense effect, and adjusting the environmental risk factors include:
[0096] S404a1. When the defense mechanism is a biometric obfuscation low encryption mechanism, execute the biometric obfuscation low encryption mechanism.
[0097] S404a2. Obtain the low encryption defense effect after executing the biometric obfuscation low encryption mechanism, wherein the low encryption defense effect includes low encryption latency time;
[0098] S404a3. Obtain the low encryption delay time threshold and determine whether the low encryption delay time exceeds the low encryption delay time threshold.
[0099] If the low encryption latency threshold does not exceed the low encryption latency time threshold, the low encryption defense effect is determined to be stable, and the low encryption stability adjustment strategy is triggered. The adversarial generation verification model is updated according to the low encryption stability strategy, and the environmental risk factor is adjusted.
[0100] If the low encryption latency threshold exceeds the low encryption latency time threshold, the low encryption defense effect is determined to be abnormal. The low encryption update table is then obtained, which includes multiple low encryption latency time intervals and a corresponding low encryption abnormal update strategy for each low encryption latency time interval. The corresponding low encryption abnormal update strategy is obtained from the low encryption update table according to the low encryption latency time interval corresponding to the low encryption latency time. The adversarial generation verification model is then updated according to the low encryption abnormal update strategy, and the environmental risk factor is adjusted.
[0101] As described in steps S404a1 to S404a3 above, when the "biometric obfuscation low-encryption mechanism" is selected, the dynamic biometric data is immediately subjected to mild perturbation and symmetric encryption. This process focuses on minimizing interference with subsequent feature discrimination processes, ensuring that the encrypted data can still be efficiently identified by the verification model. After encryption is completed and transmitted / stored, the low encryption latency time of this encryption process is monitored and recorded as a key performance indicator for measuring the efficiency of the defense mechanism. A "low encryption latency time threshold" is pre-set to balance security and performance. If the low encryption latency is ≤ the threshold, it is determined that the "low encryption defense effect is stable," triggering the low encryption stability adjustment strategy. According to this strategy, the adversarial generation verification model is fine-tuned online (e.g., slightly strengthening the weighted training of adversarial examples), and the environmental risk factors are fine-tuned (e.g., slightly reducing the device trust weight to reflect the stable performance). If the low encryption latency is ≤ the threshold, the low encryption latency time is determined to be stable. The threshold is used to determine "abnormal low-encryption defense effect". The low-encryption update table is read, which divides the latency range into multiple intervals and specifies a corresponding low-encryption anomaly update strategy for each interval. Based on the interval where the actual latency falls, the corresponding strategy is retrieved (such as enhancing the model's tolerance to noise, adjusting encryption parameters, or improving data packaging methods). After the strategy is executed, the adversarial generation verification model and environmental risk factors are updated accordingly. By determining the latency threshold, the cost of encryption can be dynamically monitored and controlled while ensuring sufficient protection strength, achieving both high efficiency and security. The latency of the low-encryption process is quantified in real time, which can immediately detect performance bottlenecks or anomalies, avoiding lag or verification failures during peak business or critical scenarios. The weight of environmental risk factors is adjusted according to different strategies for stability and anomalies, making subsequent risk assessments more in line with real defense capabilities and scenario requirements, reducing the risk of misjudgment and missed judgment.
[0102] In a preferred embodiment, when the defense mechanism is a biometric obfuscation-intermediate encryption mechanism, the steps of executing the biometric obfuscation-intermediate encryption mechanism, obtaining the intermediate encryption defense effect, updating the adversarial generation verification model based on the intermediate encryption defense effect, and adjusting the environmental risk factors include:
[0103] S404b1. When the defense mechanism is a biometric obfuscation encryption mechanism, execute the biometric obfuscation encryption mechanism.
[0104] S404b2. Obtain the mid-encryption defense effect after executing the mid-encryption mechanism of biometric obfuscation, wherein the mid-encryption defense effect includes the mid-encryption attack interception success rate and the mid-encryption biometric verification false alarm rate.
[0105] S404b3. Obtain the threshold for the success rate of intercepting medium-encryption attacks and the threshold for the false alarm rate of medium-encryption biometric verification, and determine whether the success rate of intercepting medium-encryption attacks is lower than the threshold for the success rate of intercepting medium-encryption attacks and whether the false alarm rate of medium-encryption biometric verification is higher than the threshold for the false alarm rate of medium-encryption biometric verification.
[0106] If the success rate of intercepting Chinese encryption attacks is higher than the threshold for the success rate of Chinese encryption attack interception, and the false alarm rate of Chinese encryption biometric verification is lower than the threshold for the false alarm rate of Chinese encryption biometric verification, then the Chinese encryption defense effect is determined to be secure, the adversarial generation verification model is not updated, and the environmental risk factor is not adjusted.
[0107] If the success rate of intercepting medium-encryption attacks is lower than the threshold for the success rate of medium-encryption attack interception, and the false positive rate of medium-encryption biometric verification is lower than the threshold for the false positive rate of medium-encryption biometric verification, then the medium-encryption defense effect is determined to be an interception anomaly. An environmental factor adjustment table is obtained, which includes multiple medium-encryption attack interception success rate intervals and environmental risk factor adjustment strategies corresponding to each medium-encryption attack interception success rate interval. The corresponding environmental risk factor adjustment strategy is obtained from the environmental factor adjustment table according to the medium-encryption attack interception success rate interval, and the environmental risk factors are adjusted according to the environmental risk factor adjustment strategy, without updating the adversarial generation verification model.
[0108] If the success rate of intercepting Chinese encryption attacks is higher than the threshold for the success rate of Chinese encryption attack interception, and the false positive rate of Chinese encryption biometric verification is higher than the threshold for the false positive rate of Chinese encryption biometric verification, then the Chinese encryption defense effect is determined to be biometric anomaly. An adversarial update table is obtained, which includes multiple false positive rate intervals for Chinese encryption biometric verification and the corresponding adversarial generation verification model update strategy for each Chinese encryption biometric verification false positive rate interval. The corresponding adversarial generation verification model update strategy is obtained from the adversarial update table according to the Chinese encryption biometric verification false positive rate interval, and the adversarial generation verification model is updated according to the adversarial generation verification model update strategy without adjusting the environmental risk factor.
[0109] If the success rate of intercepting medium-encryption attacks is lower than the threshold for medium-encryption attack interception success rate, and the false positive rate of medium-encryption biometric verification is higher than the threshold for medium-encryption biometric verification false positive rate, then the medium-encryption defense effect is determined to be biometric anomaly. An environmental factor adjustment table and an adversary update table are then obtained. The environmental factor table includes multiple medium-encryption attack interception success rate intervals and corresponding environmental risk factor adjustment strategies for each interval. The adversary update table includes multiple medium-encryption biometric verification false positive rate intervals and corresponding adversary generation verification model update strategies for each interval. Based on the medium-encryption attack interception success rate interval, the corresponding environmental risk factor adjustment strategy is obtained from the environmental factor adjustment table. Based on the medium-encryption biometric verification false positive rate interval, the corresponding adversary generation verification model update strategy is obtained from the adversary update table. The adversary generation verification model is updated according to the adversary generation verification model update strategy, and the environmental risk factors are adjusted according to the environmental risk factor adjustment strategy.
[0110] As described in steps S404b1 to S404b3 above, once "encryption mechanism in biometric obfuscation" is selected, random noise is immediately injected into the dynamic biometric vector. Multi-channel sequence obfuscation and asymmetric encryption are used for protection, making it difficult for attackers to reverse engineer the original signal while maintaining the model's discriminability. Two key indicators for this encryption defense are statistically analyzed: attack interception success rate (the proportion of encrypted adversarial (forged) samples intercepted and identified as "abnormal" by the discriminator); and biometric verification false positive rate (the proportion of real users' dynamic features incorrectly judged as "forged" or "abnormal" after encryption). Two thresholds are preset: the encryption attack interception success rate threshold and the encryption biometric verification false positive rate threshold. The error rate threshold is determined by comparing the current metric with the threshold, and four scenarios are handled: **Secure Status:** If the success rate of intercepting medium-encryption attacks is higher than the threshold, and the false positive rate of medium-encryption biometric verification is lower than the threshold, the medium-encryption defense is considered effective, and no model or environmental factor updates are needed; the existing configuration is maintained. **Insufficient Interception Performance:** If the success rate of intercepting medium-encryption attacks is lower than the threshold, and the false positive rate of medium-encryption biometric verification is lower than the threshold, the environmental factor adjustment table (with adjustment strategies defined according to different interception rate ranges) is read, and the weights of relevant environmental factors are dynamically reduced only based on the insufficient interception success rate. Alternatively, improve the network / device risk score to enhance the sensitivity of subsequent assessments; without modifying the validation model itself, the false positive rate is abnormal, the success rate of intercepting medium-encryption attacks is higher than the threshold for medium-encryption attack interception success rate, and the false positive rate of medium-encryption biometric verification is higher than the threshold for medium-encryption biometric verification false positive rate. Read the adversarial update table (defining model update strategies according to different false positive rate ranges), and only address the problem of excessively high false positive rates by fine-tuning or incrementally training the discriminator to reduce false rejections of real samples; without adjusting environmental factors, both interception and false positives are abnormal, the success rate of intercepting medium-encryption attacks is lower than the threshold for medium-encryption attack interception success rate, and the false positive rate of medium-encryption biometric verification is higher than the threshold for medium-encryption biometric verification false positive rate. The system uses thresholds and simultaneously reads environmental factor adjustment tables and adversarial update tables. It adjusts environmental factors according to interception rate ranges to improve alertness and updates the verification model according to false positive rate ranges to improve fault tolerance for real samples. The four branch strategies target two dimensions: insufficient interception and false positive anomalies. They precisely trigger local or bidirectional optimization to avoid resource waste or user experience degradation caused by a "one-size-fits-all" approach. The thresholds for interception rate and false positive rate, the corresponding table ranges, and the strategies can all be intuitively adjusted by security operators to meet the risk preferences under different business scenarios. Model retraining or factor recalibration is only triggered when truly needed, and the system maintains the best performance configuration under normal circumstances to ensure that the response speed and success rate of the verification process for most real users are not affected.
[0111] In a preferred embodiment, when the defense mechanism is a biometric obfuscation high-encryption mechanism, the steps of executing the biometric obfuscation high-encryption mechanism, obtaining the high-encryption defense effect, updating the adversarial generation verification model based on the high-encryption defense effect, and adjusting the environmental risk factors include:
[0112] S404c1. When the defense mechanism is a biometric obfuscation high encryption mechanism, execute the biometric obfuscation high encryption mechanism.
[0113] S404c2. Obtain the high encryption defense effect after executing the biometric obfuscation high encryption mechanism, wherein the high encryption defense effect includes high encryption latency time, high encryption attack interception success rate and high encryption biometric verification false alarm rate.
[0114] S404c3. Normalize the high encryption delay time, high encryption attack interception success rate and high encryption biometric verification false alarm rate to obtain the encryption delay value, attack interception success value and biometric verification value.
[0115] S404c4: Obtain a high encryption comprehensive value based on the encryption delay value, attack interception success value, and biometric verification value;
[0116] S404c5. Obtain the comprehensive mechanism table, which includes multiple high-encryption comprehensive value ranges and the comprehensive processing strategy corresponding to each high-encryption comprehensive value range.
[0117] S404c6. Obtain the corresponding comprehensive processing strategy from the comprehensive mechanism table based on the high encryption comprehensive value range corresponding to the high encryption comprehensive value, update the adversarial generation verification model according to the comprehensive processing strategy, and adjust the environmental risk factor.
[0118] As described in steps S404c1 to S404c6 above, when the "biometric obfuscation high encryption mechanism" is selected, multiple protection measures, including end-to-end encryption, timing perturbation, and digital signatures, are immediately implemented on the dynamic biometric vector to ensure data confidentiality and integrity during transmission and storage. After high encryption is executed, three key performance and security indicators are monitored and recorded: high encryption latency, high encryption attack interception success rate, and high encryption biometric verification false alarm rate. Normalization is performed on each of these three indicators to obtain encryption latency, attack interception success rate, and biometric verification value. The high encryption comprehensive value is calculated based on these values to quantify the overall performance and security of the high encryption strategy. The formula for calculating the high encryption comprehensive value is Q = y * j * t, where Q represents the high encryption comprehensive value, y represents the encryption latency, j represents the attack interception success rate, and t represents the biometric verification value. A "Comprehensive Mechanism Table" is maintained to record the comprehensive value. The value range is divided into several levels (such as low, medium, high, and extremely high), and a corresponding comprehensive processing strategy is assigned to each range. Based on which range it falls into, the corresponding comprehensive processing strategy is retrieved from the comprehensive mechanism table and executed. This strategy may include: adversarial generative model updates (such as batch retraining, threshold fine-tuning, and noise tolerance adjustment); and environmental risk factor adjustments (dynamically modifying the weights or thresholds of factors such as device trustworthiness, network anomalies, and geographical offset). By normalizing and weighting the encryption latency, interception success rate, and false alarm rate, a comprehensive value is formed, avoiding the bias of a single indicator influencing decision-making and achieving a comprehensive measurement of the encryption strategy. The comprehensive mechanism table supports multi-level partitioning and one-to-one strategy mapping. Operators can intuitively control the model and factor optimization actions under different comprehensive value ranges, flexibly responding to various business scenarios. The comprehensive processing strategy acts on both the model and environmental factors, forming a "double closed-loop" feedback, ensuring that both performance bottlenecks and security vulnerabilities can be quickly identified and continuously iterated and improved.
[0119] In a preferred embodiment, it further includes:
[0120] When the defense mechanism is triggered more than the preset number of times, the face data destruction policy is activated.
[0121] The original biometric data and related historical behavioral patterns of the target object are destroyed according to the facial data destruction strategy;
[0122] Perform a manual data entry procedure to re-enter the original biometric data of the target object.
[0123] The above-mentioned system counts each trigger of the defense mechanism, maintaining a "consecutive trigger count" metric. When this metric exceeds a pre-set "consecutive trigger threshold," the account or terminal is deemed to be at high risk or under continuous attack, initiating the "face data destruction" process. This process completely deletes all original biometric data (visible light images, near-infrared liveness data, 3D topology models) and their derived historical behavioral pattern vectors and log records stored in the system. Irreversible erasure algorithms (such as multiple overwrites, encrypted garbage filling, and physical database reclamation) are used to ensure the data cannot be recovered. Simultaneously, the destruction time, triggering reason, and execution node are recorded in the audit log for post-event security review and compliance filing. After destruction is complete, any automatic verification channels are automatically blocked, and the system enters the "manual verification" phase. In the "Input" mode, the security administrator or authorized operations and maintenance personnel initiate the manual data entry process to collect and verify a new round of original biometric data and basic behavioral samples of the target object according to the standard procedure. The newly collected data is encrypted locally, transmitted and re-entered into the database. At the same time, the initial threat model and risk factor baseline are updated. Continuous high-frequency triggering often means that the system has been repeatedly attacked or the data may have been leaked. The destruction strategy can quickly block attackers from using old data and reduce further risks. If an account repeatedly triggers the defense, the noise or anomalies of the old data may have interfered with the model's judgment. Re-entry can eliminate the accumulation of historical errors and ensure the accuracy of subsequent verification. The comprehensive destruction and re-collection process complies with data privacy and security compliance requirements and leaves traces in the audit log to ensure that the operation is traceable.
[0124] And, a centralized dynamic verification and risk defense terminal based on facial data, comprising:
[0125] One or more processors;
[0126] A storage device on which one or more programs are stored;
[0127] When one or more programs are executed by one or more processors, the one or more processors implement a centralized dynamic verification and risk defense method based on face data.
[0128] The above description is merely a preferred embodiment of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention. Structures, devices, and operating methods not specifically described or explained in this invention are implemented according to conventional methods in the art unless otherwise specified or limited.
Claims
1. A centralized dynamic verification and risk prevention method based on facial data, characterized in that, include: The raw biometric data of the target object is collected. The raw biometric data includes visible light face images, near-infrared live features and three-dimensional facial topology. Based on the raw biometric data, time-series processing is performed to extract dynamic biometric indicators, including micro-expression change coefficients, iris dynamic response parameters and facial blood flow waveform features. Dynamic biometrics are input into a pre-trained adversarial generative validation model, and facial credibility scores are generated through feature space mapping and comparison. The system obtains environmental risk factors and historical behavior patterns, and combines them with facial credibility scores to obtain a comprehensive risk value. Environmental risk factors include device credibility scores, network topology anomaly index, and geographical location offset. When the acquired comprehensive risk value exceeds the preset threshold, the corresponding defense mechanism is triggered. The adversarial generation verification model is updated according to the defense effect of the corresponding defense mechanism, and the environmental risk factor is adjusted.
2. The centralized dynamic verification and risk prevention method based on face data according to claim 1, characterized in that, The steps of inputting dynamic biometrics into a pre-trained adversarial generative validation model and generating facial credibility scores through feature space mapping and comparison include: Based on dynamic biometrics, obtain the corresponding micro-expression change vector, iris dynamic response vector, and facial blood flow waveform vector; The micro-expression change vector, iris dynamic response vector, and facial blood flow waveform vector are input into the pre-trained adversarial generative validation model, and the output results are labeled as biometric values. Obtain the indicator table, which includes multiple biometric value ranges and the facial credibility score corresponding to each biometric value range; The facial credibility score is obtained from the indicator table based on the range of biometric values corresponding to the biometric values.
3. The centralized dynamic verification and risk prevention method based on face data according to claim 1, characterized in that, The process of obtaining environmental risk factors and historical behavioral patterns, and combining them with facial credibility scores to obtain a comprehensive risk value, includes the following steps: Environmental risk factors include device credibility scores, network topology anomaly index, and geographic location offset. Obtain environmental risk factors and historical behavior patterns, including equipment trustworthiness scores, network topology anomaly index, and geographical location offset. Obtain multiple historical behavior vectors based on historical behavior patterns; A comprehensive risk value is obtained based on device credibility score, network topology anomaly index, geographic location offset, multiple historical behavior vectors, and facial credibility score.
4. The centralized dynamic verification and risk prevention method based on face data according to claim 1, characterized in that, When the acquired comprehensive risk value exceeds a preset threshold, the corresponding defense mechanism is triggered. The steps for updating the adversarial generation verification model and adjusting the environmental risk factors based on the effectiveness of the corresponding defense mechanism include: Obtain the comprehensive risk threshold and determine whether the comprehensive risk value exceeds the comprehensive risk threshold; If the overall risk value exceeds the overall risk threshold, the face data is determined to be abnormal, and the overall risk value is marked as an abnormal risk value. Obtain the defense table, which includes multiple abnormal risk value ranges and the corresponding defense mechanism for each abnormal risk value range; The corresponding defense mechanism is obtained from the risk table based on the abnormal risk value range corresponding to the abnormal risk value. The defense mechanism includes low encryption mechanism for biometric obfuscation, medium encryption mechanism for biometric obfuscation, and high encryption mechanism for biometric obfuscation. The adversarial generation and verification model is updated based on the defense effectiveness of the corresponding defense mechanism, and the environmental risk factor is adjusted.
5. The centralized dynamic verification and risk prevention method based on face data according to claim 4, characterized in that, The steps for updating the adversarial generation validation model based on the defense effectiveness of the corresponding defense mechanism and adjusting the environmental risk factors include: When the defense mechanism is a low-encryption biometric obfuscation mechanism, the low-encryption biometric obfuscation mechanism is executed, and the low-encryption defense effect is obtained. The adversarial generation verification model is updated based on the low-encryption defense effect, and the environmental risk factor is adjusted. When the defense mechanism is a biometric obfuscation and encryption mechanism, the biometric obfuscation and encryption mechanism is executed, the encryption defense effect is obtained, the adversarial generation verification model is updated based on the encryption defense effect, and the environmental risk factor is adjusted. When the defense mechanism is a biometric obfuscation high encryption mechanism, the biometric obfuscation high encryption mechanism is executed, and the high encryption defense effect is obtained. The adversarial generation verification model is updated based on the high encryption defense effect, and the environmental risk factor is adjusted.
6. The centralized dynamic verification and risk prevention method based on face data according to claim 5, characterized in that, When the defense mechanism is a low-encryption biometric obfuscation mechanism, the steps include: executing the low-encryption biometric obfuscation mechanism, obtaining the low-encryption defense effect, updating the adversarial generation verification model based on the low-encryption defense effect, and adjusting the environmental risk factors. When the defense mechanism is a biometric obfuscation low-encryption mechanism, then the biometric obfuscation low-encryption mechanism is executed. Obtain the low encryption defense effect after implementing the biometric obfuscation low encryption mechanism, wherein the low encryption defense effect includes low encryption latency; Obtain the low encryption latency time threshold and determine whether the low encryption latency time exceeds the low encryption latency time threshold; If the low encryption latency threshold does not exceed the low encryption latency time threshold, the low encryption defense effect is determined to be stable, and the low encryption stability adjustment strategy is triggered. The adversarial generation verification model is updated according to the low encryption stability strategy, and the environmental risk factor is adjusted. If the low encryption latency threshold exceeds the low encryption latency time threshold, the low encryption defense effect is determined to be abnormal. The low encryption update table is then obtained, which includes multiple low encryption latency time intervals and a corresponding low encryption abnormal update strategy for each low encryption latency time interval. The corresponding low encryption abnormal update strategy is obtained from the low encryption update table according to the low encryption latency time interval corresponding to the low encryption latency time. The adversarial generation verification model is then updated according to the low encryption abnormal update strategy, and the environmental risk factor is adjusted.
7. The centralized dynamic verification and risk prevention method based on face data according to claim 5, characterized in that, When the defense mechanism is a biometric obfuscation-intermediate encryption mechanism, the steps include: executing the biometric obfuscation-intermediate encryption mechanism, obtaining the effectiveness of the intermediate encryption defense, updating the adversarial generation verification model based on the effectiveness of the intermediate encryption defense, and adjusting the environmental risk factors. When the defense mechanism is encryption within biometric obfuscation, then the encryption within biometric obfuscation is executed. The effectiveness of the encryption defense after implementing the encryption mechanism in the biometric obfuscation is obtained. The effectiveness of the encryption defense includes the success rate of the encryption attack interception and the false positive rate of the encryption biometric verification. Obtain the threshold for the success rate of intercepting medium-encryption attacks and the threshold for the false alarm rate of medium-encryption biometric verification, and determine whether the success rate of intercepting medium-encryption attacks is lower than the threshold for the success rate of intercepting medium-encryption attacks and whether the false alarm rate of medium-encryption biometric verification is higher than the threshold for the false alarm rate of medium-encryption biometric verification. If the success rate of intercepting Chinese encryption attacks is higher than the threshold for the success rate of Chinese encryption attack interception, and the false alarm rate of Chinese encryption biometric verification is lower than the threshold for the false alarm rate of Chinese encryption biometric verification, then the Chinese encryption defense effect is determined to be secure, the adversarial generation verification model is not updated, and the environmental risk factor is not adjusted. If the success rate of intercepting medium-encryption attacks is lower than the threshold for the success rate of medium-encryption attack interception, and the false positive rate of medium-encryption biometric verification is lower than the threshold for the false positive rate of medium-encryption biometric verification, then the medium-encryption defense effect is determined to be an interception anomaly. An environmental factor adjustment table is obtained, which includes multiple medium-encryption attack interception success rate intervals and environmental risk factor adjustment strategies corresponding to each medium-encryption attack interception success rate interval. The corresponding environmental risk factor adjustment strategy is obtained from the environmental factor adjustment table according to the medium-encryption attack interception success rate interval, and the environmental risk factors are adjusted according to the environmental risk factor adjustment strategy, without updating the adversarial generation verification model. If the success rate of intercepting Chinese encryption attacks is higher than the threshold for the success rate of Chinese encryption attack interception, and the false positive rate of Chinese encryption biometric verification is higher than the threshold for the false positive rate of Chinese encryption biometric verification, then the Chinese encryption defense effect is determined to be biometric anomaly. An adversarial update table is obtained, which includes multiple false positive rate intervals for Chinese encryption biometric verification and the corresponding adversarial generation verification model update strategy for each Chinese encryption biometric verification false positive rate interval. The corresponding adversarial generation verification model update strategy is obtained from the adversarial update table according to the Chinese encryption biometric verification false positive rate interval, and the adversarial generation verification model is updated according to the adversarial generation verification model update strategy without adjusting the environmental risk factor. If the success rate of intercepting medium-encryption attacks is lower than the threshold for medium-encryption attack interception success rate, and the false positive rate of medium-encryption biometric verification is higher than the threshold for medium-encryption biometric verification false positive rate, then the medium-encryption defense effect is determined to be biometric anomaly. An environmental factor adjustment table and an adversary update table are then obtained. The environmental factor table includes multiple medium-encryption attack interception success rate intervals and corresponding environmental risk factor adjustment strategies for each interval. The adversary update table includes multiple medium-encryption biometric verification false positive rate intervals and corresponding adversary generation verification model update strategies for each interval. Based on the medium-encryption attack interception success rate interval, the corresponding environmental risk factor adjustment strategy is obtained from the environmental factor adjustment table. Based on the medium-encryption biometric verification false positive rate interval, the corresponding adversary generation verification model update strategy is obtained from the adversary update table. The adversary generation verification model is updated according to the adversary generation verification model update strategy, and the environmental risk factors are adjusted according to the environmental risk factor adjustment strategy.
8. The centralized dynamic verification and risk prevention method based on face data according to claim 5, characterized in that, When the defense mechanism is a biometric obfuscation and high encryption mechanism, the steps include: executing the biometric obfuscation and high encryption mechanism, obtaining the high encryption defense effect, updating the adversarial generation and verification model based on the high encryption defense effect, and adjusting the environmental risk factors. When the defense mechanism is a biometric obfuscation and high encryption mechanism, then the biometric obfuscation and high encryption mechanism is executed. The high encryption defense effect after implementing the biometric obfuscation high encryption mechanism is obtained. The high encryption defense effect includes high encryption latency, high encryption attack interception success rate and high encryption biometric verification false alarm rate. Normalization is performed based on high encryption latency, high encryption attack interception success rate and high encryption biometric verification false alarm rate to obtain encryption latency value, attack interception success value and biometric verification value. A high encryption overall value is obtained based on the encryption delay value, attack interception success value, and biometric verification value. Obtain the comprehensive mechanism table, which includes multiple high-encryption comprehensive value ranges and the comprehensive processing strategy corresponding to each high-encryption comprehensive value range; Based on the high-encryption comprehensive value range corresponding to the high-encryption comprehensive value, the corresponding comprehensive processing strategy is obtained from the comprehensive mechanism table, and the adversarial generation verification model is updated according to the comprehensive processing strategy, and the environmental risk factor is adjusted.
9. The centralized dynamic verification and risk prevention method based on face data according to claim 1, characterized in that, Also includes: When the defense mechanism is triggered more than the preset number of times, the face data destruction policy is activated. The original biometric data and related historical behavioral patterns of the target object are destroyed according to the facial data destruction strategy; Perform a manual data entry procedure to re-enter the original biometric data of the target object.
10. A centralized dynamic verification and risk prevention terminal based on facial data, characterized in that, include: One or more processors; A storage device on which one or more programs are stored; When one or more programs are executed by one or more processors, the one or more processors implement the centralized dynamic verification and risk defense method based on face data as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Living body detection method and device, equipment and storage medium
CN116206374A
Face attack detection method, equipment, storage medium and device
CN118799929A