Facial recognition anti-fraud method

Through optimal transmission and diffusion optimal transmission technology, the attack sample image is mapped to an unbiased representation space and a frequency-unbiased face image is generated. Frequency deviation is used for classification and identification, which solves the problem that the existing technology cannot effectively distinguish between real and forged faces, and improves the accuracy and security of facial recognition anti-fraud.

CN120635967APending Publication Date: 2025-09-12NINGXIA UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510816578.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing facial recognition anti-fraud technology is unable to effectively distinguish between real and forged faces when faced with diverse attacks, resulting in significant performance fluctuations in actual applications. In particular, it is unable to effectively identify unseen attacks in situations where security requirements are high.

Method used

Through optimal transmission and diffusion optimal transmission, the attack sample image is mapped to the unbiased representation space corresponding to the real face image, and the frequency-unbiased unbiased face image is generated through iterative denoising. The frequency deviation is used as a robust attack clue for classification and recognition.

Benefits of technology

It significantly improves the generalization detection capability of diverse forged attack samples and improves the accuracy and security of facial recognition anti-fraud detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120635967A_ABST
    Figure CN120635967A_ABST
Patent Text Reader

Abstract

The invention discloses a face recognition anti-fraud method, and relates to the technical field of face recognition. Comprising the following steps: acquiring a real face image and an attack sample image corresponding to the real face image; inputting the attack sample image into an image recognition model to obtain an image recognition result; training the image recognition model through a total loss function between the attack sample image and the recognition result to obtain a trained image recognition model; and inputting a face image to be recognized into the trained image recognition model to obtain an image recognition result, and applying the image recognition result to face anti-fraud recognition. According to the face recognition anti-fraud detection method, the generalization detection capability of diversified and forged attack sample images can be remarkably improved, and then the accuracy and the safety of face recognition anti-fraud detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of facial recognition technology, and in particular to a facial recognition anti-fraud method. Background Art

[0002] Face recognition technology has achieved remarkable success due to its convenience and accuracy, and has been widely used in mobile identity authentication and electronic payments. However, these systems are still threatened by various attacks, such as photo printing attacks, video replay attacks, and 3D face mask attacks. Under different attacks, the system will generate different attack sample images, such as photo printing images, video replay images, and 3D face masks. Therefore, face anti-spoofing technology has been proposed to protect face recognition systems from various malicious attacks. Current face anti-spoofing work uses attack classifiers to determine whether the input image contains attack clues. However, with the rapid growth of attack types, traditional anti-spoofing has gradually become a challenging open-ended recognition task.

[0003] Face anti-spoofing (FAS) is gaining increasing attention from both academia and industry. Early FAS work relied on handcrafted image descriptors, such as local binary patterns (LBP), histograms of oriented gradients (HoG), and scale-invariant feature transforms (SIFT), to extract features that describe spoofing patterns. However, these baseline methods are limited by the representational limitations of handcrafted features, resulting in suboptimal performance even within their domain. With the rapid development of deep learning, its powerful representation learning capabilities have significantly improved FAS detection capabilities. For example, pixel-level supervised methods can provide more fine-grained, context-aware supervision to help deep models learn attack cues. While these methods perform well in dataset-based scenarios, their performance degrades significantly when faced with unseen attacks in the real world.

[0004] To improve the generalization capability of unseen attacks, domain adaptation and domain generalization techniques have been proposed in recent years to enhance FAS detection performance in a wider range of scenarios. Domain adaptation-based methods aim to directly leverage target data to align the distributions of the source and target domains. However, data in the target domain is difficult to obtain or even unknown. Domain generalization-based methods, on the other hand, aim to learn domain-invariant features from multiple source domains. Most of these methods assume that aligning different source domains within a unified feature space preserves domain-invariant features. However, due to the significant differences between domains, such alignment can be difficult and may lose key discriminative cues. With the increasing number of attack types, methods based on open set recognition, by strengthening the boundary discrimination of each known category, can not only accurately distinguish between real faces and attack sample images, but also identify unknown attack types through their anomaly detection capabilities. Furthermore, existing research has recognized the importance of data hierarchical structure in generalization and has attempted to leverage this structural information to enhance the generalization capability and practical application of FAS. However, almost all previous methods either focus on learning domain-invariant features or extracting generalizable features from the entire sample, which may still lead to failure in real-world scenarios. The latest strategy is to leverage specific information to explore unknown attack features to improve generalization ability.

[0005] In summary, existing technologies focus on improving the generalization capabilities of identifying unknown attacks, but ignore the significant frequency domain variations between different attacks. This results in significant performance fluctuations in anti-spoofing systems in real applications, making it difficult to effectively distinguish between real and forged faces. This, in turn, limits the application of existing facial recognition anti-spoofing technology in a wider range of scenarios, particularly those requiring high security. Summary of the Invention

[0006] Based on this, it is necessary to provide a facial recognition anti-fraud method to address the above technical issues.

[0007] An embodiment of the present invention provides a facial recognition anti-fraud method, comprising: Obtain a real face image and an attack sample image corresponding to the real face image; Input the attack sample image into the image recognition model, which includes multiple real face generation modules and classifiers connected in sequence; the multiple real face generation modules are diffusion models that introduce optimal transmission into the forward diffusion process and introduce the diffusion optimal transmission into the reverse generation process; For each real face generation module, the attack sample image is mapped to the unbiased representation space corresponding to the real face image using optimal transmission through the forward diffusion process of the real face generation module to obtain an unbiased feature image; the unbiased feature image is gradually iteratively denoised using diffusion optimal transmission through the reverse generation process of the real face generation module to gradually obtain the generated face image; the frequency deviation between the attack sample image and the generated face image is calculated by a classifier, and classification and recognition are performed based on the frequency deviation to obtain a recognition result; the image recognition model is trained using the total loss function between the attack sample image and the recognition result to obtain a trained image recognition model; The face image to be identified is input into the trained image recognition model to obtain the image recognition result, and the image recognition result is used for facial anti-fraud recognition.

[0008] Optionally, mapping the attack sample image to an unbiased representation space corresponding to the real face image using optimal transmission through the forward diffusion process of the real face generation module to obtain an unbiased feature image, specifically including: Define the mapping for the forward Markov diffusion process ,make Characterize samples for unbiased spatial distribution Determine the transportation plans corresponding to multiple attack sample images based on the following formula: ; Adding diffuse forward noise to the transportation plan, embedding the attack sample image as a condition into the cost matrix, and obtaining the optimal transportation plan, the formula is expressed as: ; ; in, To diffuse the forward noise, is the target output distribution, is the attack sample image, for and The cost matrix between is the cost matrix after embedding the attack sample image, For the optimal transportation solution; The mapping is determined by the optimal transportation solution based on the following formula: ; The attack sample image is projected into the unbiased representation space corresponding to the real face image through mapping to obtain an unbiased feature image.

[0009] Optionally, the unbiased feature image is subjected to stepwise iterative denoising using diffusion optimal transmission through the reverse generation process of the real face generation module to obtain a generated face image, specifically comprising: The definition of diffusion optimal transmission is determined based on the following formula: ; t= M ,...,1 ; in, is a latent variable, T is the number of iterations, is the number of time steps of the reverse Markov diffusion process; At each time step, the latent variables are used to predict the noise distribution to be removed, and the Markov chain is used to perform denoising step by step to convert the random noise into a face image, thereby obtaining a generated face image.

[0010] Optionally, a classifier is used to calculate the frequency deviation between the attack sample image and the generated face image, and classification and recognition are performed based on the frequency deviation to obtain an image recognition result, specifically including: The unbiased face image is converted from the spatial domain to a complex representation in the frequency domain through discrete Fourier transform based on the following formula: ; in, is the horizontal coordinate of the unbiased face image in the frequency domain, is the ordinate of the unbiased face image in the frequency domain, H is the image height of the unbiased face image, W is the image width of the unbiased face image, C is the number of image channels for unbiased face images; The amplitude of the real face image and the amplitude of the unbiased face image are calculated based on the following formula: ; in, is the real part, is the imaginary part; The frequency deviation is determined by the amplitude of the real face image and the amplitude of the unbiased face image based on the following formula: ; in, is the frequency deviation, is the amplitude of the real face image, is the amplitude of the unbiased face image; Based on the following formula, the frequency deviation is normalized by the exponential function through the fully connected layer to predict the probability of the input image being recognized as a real face image or a non-real face image, and the recognition result is obtained: ; in, Indicates whether the recognition result is a real face image or a non-real face image label, represents a fully connected layer.

[0011] Optionally, the image recognition model is trained by using a total loss function between the attack sample image and the recognition result to obtain a trained image recognition model, specifically including: The total loss function between the attack sample image and the recognition result is calculated based on the following formula: ; ; ; ; in, is the optimal transmission loss, is the diffusion loss, is the frequency deviation loss, is the total loss function, To diffuse the forward noise, is the target output distribution, is the attack sample image, is the frequency deviation, To identify the label of a real face image or a non-real face image, represents the fully connected layer, is the mean square error of the optimal transportation plan under the row constraint condition, is the mean square error of the optimal transportation plan under column constraints, are the attack sample images and real face images in the dataset; With the goal of minimizing the total loss function between the attack sample image and the recognition result, the image recognition model is trained to obtain a trained image recognition model.

[0012] Optionally, the method further includes performing size alignment processing on the real face image and the attack sample image corresponding to the real face image using facial landmarks detection, so as to adjust the real face image and the attack sample image to the same size.

[0013] The facial recognition anti-fraud method provided by the embodiment of the present invention has the following beneficial effects compared with the prior art: The present invention is based on optimal transmission and diffusion optimal transmission. The attack sample image is mapped to the unbiased representation space corresponding to the real face image through optimal transmission, and then the unbiased feature image is gradually iteratively denoised through diffusion optimal transmission to obtain the generated face image; the frequency deviation between the generated face image and the attack sample image is used as a robust attack clue to accurately locate the forgery traces, and deeply analyze the essential differences between the generated face image and the attack sample image, significantly improving the generalization detection capability of diversified forged attack sample images, thereby improving the accuracy and security of facial recognition anti-fraud detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 A diagram illustrating the principle of a facial recognition anti-fraud method provided in one embodiment; Figure 2 A flowchart of a facial recognition anti-fraud method provided in one embodiment. DETAILED DESCRIPTION

[0015] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0016] In one embodiment, a facial recognition anti-fraud method is provided, the method comprising: like Figure 1 As shown, by analyzing the representation of different attacks in the frequency domain, the present invention observes that different attacks have significant frequency deviations relative to real faces, even in the case of weak texture attacks ( Figure 1 The arrows in the figure indicate that the texture similarity between the attack sample image and the real face gradually increases. Frequency deviation is also evident. Therefore, the frequency deviation between different attacks and real faces can serve as a robust attack cue. Based on the above analysis, different types of attacks are regarded as varying degrees of frequency degradation, and the face anti-spoofing task is reformulated as a super-resolution problem to evaluate the quality of real face restoration. Specifically, an image restoration model is constructed to facilitate the transformation between attack samples and real faces. In this model, optimal transmission is integrated into a diffusion model to project different attack vectors into an unbiased representation space. Subsequently, the diffusion-based restoration model utilizes the unbiased features to generate a generated face image. By iterating this process, an unbiased face image with no frequency bias is ultimately generated. Finally, the frequency deviation between the unbiased face image and the real face image serves as a robust attack cue for face anti-spoofing recognition.

[0017] The attack sample image is fed into an image recognition model, which consists of multiple sequentially connected real face generation modules (DOT-LFG) and a classifier (FBC). The multiple real face generation modules are a diffusion model that introduces optimal transmission into the forward diffusion process and the diffusion optimal transmission into the reverse generation process.

[0018] like Figure 2 As shown, for each real face generation module, the attack sample image is mapped to the unbiased representation space corresponding to the real face image using optimal transmission through the forward diffusion process of the real face generation module to obtain an unbiased feature image; the unbiased feature image is gradually iteratively denoised using diffusion optimal transmission through the reverse generation process of the real face generation module to gradually obtain the generated face image; the frequency deviation between the attack sample image and the generated face image is calculated by the classifier, and classification and recognition are performed according to the frequency deviation to obtain the recognition result; the image recognition model is trained by the total loss function between the attack sample image and the recognition result to obtain the trained image recognition model.

[0019] The face image to be identified is input into the trained image recognition model to obtain the image recognition result, and the image recognition result is used for facial anti-fraud recognition.

[0020] Among them, the real face generation module first uses the optimal transmission module (i.e., unbiased representation space The previous module) will degrade the frequency of the attack sample image Mapping to the unbiased representation space corresponding to the real face Subsequently, based on the diffusion model (i.e., unbiased representation space The subsequent module) generates the corresponding real face and obtains the generated face image ( , ,……, ).

[0021] Among them, this process is iterated through multiple real face generation modules to finally obtain an unbiased face image .

[0022] Among them, the frequency deviation between the unbiased face image and the real face image is calculated in the classifier, and the frequency deviation is used as a robust attack clue for classification and recognition to obtain the image recognition result.

[0023] 1. Realistic face generation based on diffusion optimal transmission.

[0024] 1. Debiasing through optimal transmission.

[0025] In order to degrade the frequency of the attack sample image Projected to the unbiased representation space corresponding to the real face, first find a mapping , making is a representative sample of the unbiased spatial distribution. Among the many mappings that satisfy this condition, the optimal transmission is achieved by minimizing the quality transmission cost To select a mapping. Function Defines the probability mass of a unit from Move to Consider two random variables and , whose metrics are The optimal transport (OT) is given by the solution of Monge's problem:

[0026] (1) The mapping Induced forward measure It is defined as follows, where represents the Dirac measure: (2) However, in practice, it is difficult to solve the Monge problem directly, and there may even be no solution. A common way to relax Equation (1) is to find a joint probability distribution, called a coupling or transport scheme. An effective transport scheme is Probability measure on , whose marginal distribution is and In order to effectively estimate the is the quadratic cost (i.e. c ( ), solving the problem with entropy regularization.

[0027] (3) in represents the KL divergence, ϵ >0 is a small regularization parameter. Using the Sinkhorn algorithm, it can solve Equation (2) with a small running time complexity. Transportation solution The final solution of is given by:

[0028] (4) The potential energy function and To meet transportation plans The marginal distribution constraint of . Unlike directly transforming the distribution through optimal transmission, the optimal transmission is used in the process of conditional diffusion model to achieve frequency deviation from the attack sample image to the real face. Therefore, the input of the original optimal transmission in formula (3) is modified to ,in is the diffuse forward noise, is the target output distribution, Is the attack sample image. To achieve the attack sample image Guided learning from arrive The optimal transmission solution .

[0029] In addition, in order to make full use of the conditional information of the attack sample image, it is analyzed that the transportation plans of different attack sample images have different cost matrices. Therefore, the attack sample image is embedded in the cost matrix as a condition, and the modified transportation plan is obtained as follows: (5) in yes and The cost matrix between is embedded with attack sample image conditions With the modified transportation plan, we can calculate the mapping .

[0030] (6) Through mapping Implement the attack sample image Projected to the unbiased representation space corresponding to the real face image.

[0031] 2. Generate realistic faces through optimal diffusion transmission.

[0032] Given a dataset of real face and attack sample image pairs, denoted as , Represents a real face Using the generated unbiased features, realistic face generation based on diffusion optimal transmission is achieved.

[0033] (1) Training process

[0034] First, we define a forward Markov diffusion process, which is T In the iterations, diffuse forward noise is gradually added to the unbiased face image. : (7) Since the conditional input is a biased attack sample image , first by m The step diffusion model attacks the sample image Projection to unbiased representation space By derivation of the optimal transmission, the input diffuse forward noise , attack sample image and the target output distribution arrive :

[0035] (8) in It is an unbiased representation space and realizes the arrive to accelerate the diffusion model.

[0036] Optimal transportation solution In Equation (4), there are row and column constraints, so the loss function is : (9) The next goal: From Restore the final noise-free .

[0037] The objective function of training is: (10) in , are the attack sample images and real face images in the dataset, , .

[0038] (2) Reasoning process.

[0039] In time Given an initial , for the attack sample image , Diffusion Optimal Transport (DOT) first passes through T - M Step, where , to obtain frequency unbiased characteristics. express and The inference formula of DOT is defined as follows:

[0040] t= M,...,1 (11) in, is a latent variable, T is the number of iterations, is the number of time steps of the inverse Markov diffusion process.

[0041] In the inference phase, DOT first transmits the attack sample image through the optimal transmission Mapping to an unbiased representation space.

[0042] In addition, the inverse Markov diffusion process uses the latent variable Estimate the inverse noise and obtain the generated face image. At each time step, the latent variable is used to predict the noise distribution to be removed, and the Markov chain is used to iterate the denoising step by step to convert the random noise into a face image to obtain the generated face image. By iterating the above process, a frequency-unbiased "real" face can be generated. .

[0043] 2. Classification based on frequency deviation.

[0044] Generating unbiased real faces in the frequency domain from attack sample images. By carefully analyzing the frequency components of different attacks, we observed that subtle differences between attack sample images and real faces manifest as more pronounced deviations in the frequency domain. Based on these observations, we define "frequency deviations" between real faces and attack sample images as attack cues, providing fine-grained evidence for model classification.

[0045] The following is the calculation process of frequency domain deviation: Discrete Fourier Transform (DFT) is widely used in the frequency domain of image analysis and is denoted as F . The attack sample image Convert to complex number representation in frequency domain. The mathematical expression is as follows:

[0046] (12) in, is the horizontal coordinate of the unbiased face image in the frequency domain, is the ordinate of the unbiased face image in the frequency domain, H is the image height of the unbiased face image, W is the image width of the unbiased face image, C is the number of image channels for unbiased face images: (13) in, is the real part, is the imaginary part.

[0047] Then define the unbiased face image and attack sample images The "frequency deviation" between them is used as an attack clue: (14) in, is the frequency deviation, is the amplitude of the real face image, is the amplitude of the unbiased face image.

[0048] Next, use the calculated frequency deviation to perform classification: (15) in, Indicates whether the recognition result is a real face image or a non-real face image label, represents the fully connected layer, ∈{0 , 1}, It is a fully connected layer that performs a normalized exponential function (softmax function) on the frequency deviation to predict the probability of the input image being recognized as a real face image or an attack image to obtain the recognition result.

[0049] 3. Loss function.

[0050] The above loss functions are integrated into a unified form to facilitate end-to-end training. Specifically, the total loss function can be expressed as:

[0051] (16) in, α and β are two hyperparameters used to balance the effects of diffusion loss and optimal transmission loss.

[0052] 4. Implementation examples

[0053] 1. Composition.

[0054] Datasets: We use datasets containing real faces and various attack types (photos, video replays, different lighting conditions, etc.), CASIA-MFSD(C), Replay-Attack(I), MSU-MFSD(M), OULU-NPU(O).

[0055] Data preprocessing: Use facial landmarks detection to align the input real face and attack sample images and adjust them to a uniform size.

[0056] Diffusion-based optimal transmission real face generation module: The Sinkhorn algorithm is used for optimal transmission to map the frequency-degraded attack sample image to the unbiased representation space corresponding to the real face. The forward and reverse Markov diffusion processes are used to achieve real face generation based on unbiased features.

[0057] Classifier: First, the frequency deviation between the generated real face and the input attack sample is calculated, and a classifier based on frequency deviation is constructed to distinguish the real face and the attack sample image using the frequency domain deviation.

[0058] 2. Effect.

[0059] (1) This model can improve face anti-spoofing in the case of weak texture attacks and more accurately distinguish between real and attacked faces.

[0060] (2) Since the frequency domain deviation can well characterize the essential differences between real faces and attack sample images, the model can improve the generalization ability of unknown attack recognition.

[0061] (3) In comparative evaluations on multiple public face anti-spoofing datasets, the model shows better performance than existing state-of-the-art methods, demonstrating its robustness in different environments.

[0062] The above-described embodiments merely illustrate several implementations of the present invention. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, and all such variations and improvements fall within the scope of protection of the present invention.

Claims

1. A facial recognition anti-fraud method, characterized in that: include: Obtain a real face image and an attack sample image corresponding to the real face image; Inputting the attack sample image into an image recognition model, the image recognition model comprising a plurality of real face generation modules and classifiers connected in sequence; the plurality of real face generation modules are diffusion models that introduce optimal transmission into the forward diffusion process and introduce the diffusion optimal transmission into the reverse generation process; For each real face generation module, the attack sample image is mapped to the unbiased representation space corresponding to the real face image using optimal transmission through the forward diffusion process of the real face generation module to obtain an unbiased feature image; the unbiased feature image is gradually iteratively denoised using diffusion optimal transmission through the reverse generation process of the real face generation module to gradually obtain the generated face image; the frequency deviation between the attack sample image and the generated face image is calculated by a classifier, and classification and recognition are performed based on the frequency deviation to obtain a recognition result; The image recognition model is trained by attacking the total loss function between the sample image and the recognition result to obtain the trained image recognition model; The face image to be identified is input into the trained image recognition model to obtain the image recognition result, and the image recognition result is used for facial anti-fraud recognition.

2. A facial recognition anti-fraud method according to claim 1, characterized in that: The forward diffusion process of the real face generation module uses optimal transmission to map the attack sample image to the unbiased representation space corresponding to the real face image to obtain the unbiased feature image, specifically including: Define the mapping for the forward Markov diffusion process ,make Characterize samples for unbiased spatial distribution Determine the transportation plans corresponding to multiple attack sample images based on the following formula: ; Adding diffuse forward noise to the transportation plan, embedding the attack sample image as a condition into the cost matrix, and obtaining the optimal transportation plan, the formula is expressed as: ; ; in, To diffuse the forward noise, is the target output distribution, is the attack sample image, for and The cost matrix between is the cost matrix after embedding the attack sample image, For the optimal transportation solution; The mapping is determined by the optimal transportation solution based on the following formula: ; The attack sample image is projected into the unbiased representation space corresponding to the real face image through mapping to obtain an unbiased feature image.

3. A facial recognition anti-fraud method according to claim 2, characterized in that: The reverse generation process of the real face generation module uses diffusion optimal transmission to perform step-by-step iterative denoising on the unbiased feature image to obtain a generated face image, specifically including: The definition of diffusion optimal transmission is determined based on the following formula: ; t= M ,...,1 ; in, is a latent variable, T is the number of iterations, is the number of time steps of the inverse Markov diffusion process; At each time step, the latent variables are used to predict the noise distribution to be removed, and the Markov chain is used to perform denoising step by step to convert the random noise into a face image, thereby obtaining a generated face image.

4. A facial recognition anti-fraud method according to claim 1, characterized in that: The classifier calculates the frequency deviation between the attack sample image and the generated face image, and performs classification and recognition based on the frequency deviation to obtain the image recognition result, specifically including: The unbiased face image is converted from the spatial domain to a complex representation in the frequency domain through discrete Fourier transform based on the following formula: ; in, is the horizontal coordinate of the unbiased face image in the frequency domain, is the ordinate of the unbiased face image in the frequency domain, H is the image height of the unbiased face image, W is the image width of the unbiased face image, C is the number of image channels for unbiased face images; The amplitude of the real face image and the amplitude of the unbiased face image are calculated based on the following formula: ; in, is the real part, is the imaginary part; The frequency deviation is determined by the amplitude of the real face image and the amplitude of the unbiased face image based on the following formula: ; in, is the frequency deviation, is the amplitude of the real face image, is the amplitude of the unbiased face image; Based on the following formula, the frequency deviation is normalized by the exponential function through the fully connected layer to predict the probability of the input image being recognized as a real face image or a non-real face image, and the recognition result is obtained: ; in, Indicates whether the recognition result is a real face image or a non-real face image label, represents a fully connected layer.

5. The facial recognition anti-fraud method according to claim 1, wherein: The training of the image recognition model by attacking the total loss function between the sample image and the recognition result to obtain the trained image recognition model specifically includes: The total loss function between the attack sample image and the recognition result is calculated based on the following formula: ; ; ; ; in, is the optimal transmission loss, is the diffusion loss, is the frequency deviation loss, is the total loss function, To diffuse the forward noise, is the target output distribution, is the attack sample image, is the frequency deviation, To identify the label of a real face image or a non-real face image, represents the fully connected layer, is the mean square error of the optimal transportation plan under the row constraint condition, is the mean square error of the optimal transportation plan under column constraints, are the attack sample images and real face images in the dataset; With the goal of minimizing the total loss function between the attack sample image and the recognition result, the image recognition model is trained to obtain a trained image recognition model.

6. A facial recognition anti-fraud method according to claim 1, characterized in that: It also includes using facial landmarks detection to perform size alignment processing on the real face image and the attack sample image corresponding to the real face image, so as to adjust the real face image and the attack sample image to the same size.

Citation Information

Cited By

  • General depth forgery detection method based on spatial domain and frequency domain joint depolarization

    CN121810669A