Injection attack detection method and device, equipment, storage medium and program product

By illuminating the target face with light of different RGB values ​​and brightness, and comparing the grayscale values ​​of video frames, the problem of high resource consumption and low security in injection attack detection on mobile terminals is solved, achieving lightweight, fast, and stable detection results.

CN120807381APending Publication Date: 2025-10-17MASHANG CONSUMER FINANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410431075.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-10
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Existing technologies have difficulty in effectively detecting and preventing injection attacks, especially on mobile terminals, due to the problems of high resource consumption, low security and efficiency.

Method used

By illuminating the target face with light of different RGB values ​​and brightness, the grayscale values ​​of video frames are collected, and injection attacks are identified by comparing the grayscale values. The differences in light changes are used for detection.

Benefits of technology

It achieves lightweight, fast, stable and efficient injection attack detection, is suitable for mobile terminals, and improves detection success rate and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120807381A_ABST
    Figure CN120807381A_ABST
Patent Text Reader

Abstract

The invention discloses an injection attack detection method and device, equipment, a storage medium and a program product, which are used for realizing injection attack detection in a light-weight and low-complexity manner, are suitable for local execution in a mobile terminal, and are high in security, low in resource consumption and high in response speed. The method comprises the following steps: acquiring a to-be-detected video of a target face irradiated by light; carrying out gray scale transformation on a video frame of the to-be-detected video to obtain a first gray scale value of the video frame; converting the light value label of the video frame into a gray value to obtain a second gray value of the video frame; and based on the first gray value and the second gray value, determining whether the to-be-detected video is subjected to an injection attack.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of image processing, and in particular to an injection attack detection method and device, equipment, a storage medium and a program product. BACKGROUND

[0002] Identity verification technology based on face recognition is widely used in Internet financial scenarios. However, various identity spoofing methods emerge in endlessly. Among the many identity spoofing methods, injection attack is currently more difficult to detect and prevent. SUMMARY

[0003] The purpose of the embodiments of the present application is to provide an injection attack detection method, device, equipment, storage medium and program product, which is used to implement injection attack detection in a lightweight and low complexity manner, is suitable for local execution on a mobile terminal, and has high security, small resource consumption and fast response speed.

[0004] In order to achieve the above-mentioned purpose, the technical scheme adopted by the embodiments of the present application is as follows:

[0005] In a first aspect, the embodiments of the present application provide an injection attack detection method, comprising:

[0006] obtaining a to-be-detected video of a target face irradiated by light;

[0007] performing gray scale transformation on a video frame of the to-be-detected video to obtain a first gray scale value of the video frame;

[0008] converting a light value label of the video frame into a gray scale value to obtain a second gray scale value of the video frame;

[0009] determining whether the to-be-detected video is subjected to an injection attack based on the first gray scale value and the second gray scale value.

[0010] In a second aspect, the embodiments of the present application provide an injection attack detection device, comprising:

[0011] an acquisition unit configured to obtain a to-be-detected video of a target face irradiated by light;

[0012] a first conversion unit configured to perform gray scale transformation on a video frame of the to-be-detected video to obtain a first gray scale value of the video frame;

[0013] a second conversion unit configured to convert a light value label of the video frame into a gray scale value to obtain a second gray scale value of the video frame;

[0014] a detection unit configured to determine whether the to-be-detected video is subjected to an injection attack based on the first gray scale value and the second gray scale value.

[0015] In a third aspect, an electronic device is provided, including:

[0016] a processor;

[0017] a memory for storing instructions executable by the processor;

[0018] The processor is configured to execute the instructions to implement the injection attack detection method according to the first aspect.

[0019] In a fourth aspect, a computer-readable storage medium is provided, which, when instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to perform the injection attack detection method according to the first aspect.

[0020] In a fifth aspect, a computer program product is provided, which includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps of the method according to the first aspect.

[0021] The above at least one technical solution adopted by the embodiments of the present application can achieve the following beneficial effects: considering that there is a difference between the light change presented by the target face in the video subjected to the injection attack and the light change of the light irradiating the target face during the irradiation of the light to the target face, which is more obvious in the gray value. During the irradiation of the light to the target face, the target face is photographed to obtain a to-be-detected video; whether the obtained video is subjected to the injection attack can be determined by identifying whether there is an obvious difference between the gray value of the video frame in the to-be-detected video and the gray value of the light irradiating the target face. The entire algorithm logic is simple, stable, and has a high success rate, and the comparison of the gray value is easier than the comparison of the original pixel value, and has the advantage of lightweight. Therefore, the injection attack detection method provided by the embodiments of the present application can be run on a mobile terminal in real time, and is suitable for various scenes such as APP and H5. BRIEF DESCRIPTION OF DRAWINGS

[0022] The accompanying drawings, which are included to provide a further understanding of the present application, constitute a part of the present application, and the illustrative embodiments of the present application and their description serve to explain the present application, and do not constitute improper limitations on the present application. In the drawings:

[0023] Figure 1 A flowchart of an injection attack detection method provided by an embodiment of the present application;

[0024] Figure 2 A schematic diagram of an online face recognition process provided by an embodiment of the present application;

[0025] Figure 3A flowchart of an injection attack detection method provided for another embodiment of the present application is shown in FIG. 1.

[0026] Figure 4 A structural diagram of an injection attack detection device provided for an embodiment of the present application is shown in FIG. 2.

[0027] Figure 5 A structural diagram of an electronic device provided for an embodiment of the present application is shown in FIG. 3. DETAILED DESCRIPTION

[0028] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below in conjunction with specific embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative work under the premise that the embodiments in the present application fall within the scope of protection of the present application.

[0029] The terms "first", "second", and the like in the specification and claims are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means that the front and rear associated objects are in an "or" relationship.

[0030] Among the many identity spoofing means, injection attack is currently more difficult to detect and prevent. Although the vivo detection of the color flash using sequence verification has the best defense capability against injection attack, the design of most current injection attack algorithms requires high computing power, which needs to return the video collected in the front end to the server for processing on the server. In this way, the injection attack detection process consumes a lot of resources, has high requirements for network environment, and the security and efficiency cannot be guaranteed.

[0031] The present application studies a large number of videos subjected to injection attack and finds that there is a difference between the light change of the target face in the video subjected to injection attack and the light change of the light irradiating the target face during the irradiation of the light to the object to be detected. This difference is more obvious in the gray value.

[0032] Based on this, the embodiment of the present application proposes a lightweight injection attack detection method. It is considered that there is a difference between the light changes presented by the target face in the video subjected to the injection attack and the light changes of the light irradiating the target face during the irradiation of the light to the target face, and this difference is more obvious in the gray value. During the irradiation of the light to the target face, the target face is photographed to obtain a to-be-detected video; whether the obtained video is subjected to the injection attack can be determined by identifying whether there is an obvious difference between the gray value of the video frame in the to-be-detected video and the gray value of the light irradiating the target face, the whole algorithm logic is simple, stable, and has a high success rate, and the comparison of the gray value is easier than the comparison of the original pixel value, and has the advantage of lightweight. Therefore, the injection attack detection method provided by the embodiment of the present application can be run on a mobile terminal in real time, and is suitable for various scenes such as APP, H5, etc.

[0033] In addition, in order to enhance the defense ability against the injection attack, a large number of random spaces can be generated by randomly combining the RGB value, brightness and irradiation time of the light irradiating the target face, so that it is difficult for the attacker to achieve the injection attack through enumeration.

[0034] The injection attack detection method provided by the embodiment of the present application can be applied to various business scenarios with injection attack detection needs. For example, in a remote identity authentication scenario, after detecting the photographed to-be-detected video by using the injection attack detection method provided by the embodiment of the present application, the identity information of the to-be-detected object is confirmed according to the injection attack detection result. For another example, in a door control scenario, after detecting the photographed to-be-detected video by using the injection attack detection method provided by the embodiment of the present application, it is confirmed whether the to-be-detected object is allowed to enter a specific area according to the injection attack detection result. For another example, in a face payment scenario, after detecting the photographed to-be-detected video by using the injection attack detection method provided by the embodiment of the present application, it is determined whether to provide a payment service according to the injection attack detection result.

[0035] It should be understood that the application of the injection attack detection method provided by the embodiment of the present application to the remote identity authentication, door control, face payment and other business scenarios is only an exemplary description, and should not be understood as a limitation on the application scenarios of the injection attack detection method.

[0036] It should be understood that the injection attack detection method provided by the embodiments of the present application can be executed by an electronic device, and specifically can be executed by a processor of the electronic device. Here, the electronic device can include a terminal device, for example, including but not limited to a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart voice interaction device, a smart home appliance, a smart watch, a vehicle-mounted terminal, an aircraft, etc.; or the electronic device can also include a server, such as a standalone physical server, a server cluster or a distributed system formed by multiple physical servers, or a cloud server providing cloud computing services.

[0037] The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the drawings.

[0038] Please refer to Figure 1 A flowchart of an injection attack detection method provided by an embodiment of the present application is shown in the figure, and the method can include the following steps:

[0039] S102, a video to be detected for illuminating a target face with light is acquired.

[0040] The video to be detected is obtained by image acquisition of the target face under illumination of light. The video frame of the video to be detected contains the target face.

[0041] The light illuminating the target face includes a plurality of light arranged in sequence. Each light has a corresponding attribute. The attribute of the light at least includes a color attribute, and the color attribute represents the RGB value of the light. Since the absorption characteristics and polarization effects of the real face and the fake face to the same light are different, by illuminating the target face with light of different RGB values, acquiring the video of the target face under illumination of different light, and comparing the RGB value changes of the light illuminating the target face with the RGB value changes of the video, it can be accurately determined whether the target face is a fake face, that is, whether the acquired video is subjected to injection attack. The entire injection attack detection process does not require user cooperation with corresponding actions, and is simple and efficient.

[0042] In specific implementation, the RGB values of the plurality of light can be set according to actual business needs, which is not limited by the embodiments of the present application. In an embodiment, the generation manner of the light illuminating the target face includes: randomly selecting a plurality of RGB values from an RGB value range for combination to obtain a target RGB value sequence; and illuminating the target face with light based on the target RGB value sequence. In this manner, since the plurality of RGB values are randomly selected and combined, the target RGB value sequence obtained by combination has a certain randomness, which can increase the difficulty of enumerating the light illuminating the target face by an attacker, thereby enhancing the defense against injection attack.

[0043] In practical applications, the light irradiated to the target face can be realized in various ways. As an example, the screen of the terminal device can be used to emit light according to the target RGB value sequence, which is simple to implement and does not require the use of external light source equipment, thereby reducing the implementation cost of the method. As another example, an external light source equipment can be used to control the external light source equipment to emit light according to the target RGB value sequence to form the light irradiated to the target face.

[0044] Secondly, the combination of the multiple RGB values randomly selected from the RGB value range can be realized in various ways. As an example, the combination of the multiple RGB values randomly selected from the RGB value range includes: selecting the maximum RGB value and the minimum RGB value from the RGB value range, and randomly selecting at least one target RGB value from the RGB value range, wherein the R component, the G component and the B component of the target RGB value are the same, and the target RGB value is between the maximum RGB value and the minimum RGB value; and combining the maximum RGB value, the minimum RGB value and the at least one target RGB value to obtain the target RGB value sequence.

[0045] For example, the at least one target RGB value includes a target RGB value representing light gray and a target RGB value representing dark gray, the maximum RGB value represents white, and the minimum RGB value represents black. The maximum RGB value, the minimum RGB value and the two target RGB values are randomly combined to obtain the target RGB value sequence. Since the class interval between black, white and gray is small and difficult to distinguish, the combination of the RGB values representing these colors can further increase the difficulty of enumerating the target RGB value sequence and further enhance the defense against injection attacks. Furthermore, the random combination of these RGB values further increases the randomness of the target RGB value sequence, further increasing the difficulty of enumerating the target RGB value sequence.

[0046] For another example, the at least one target RGB value includes target RGB values corresponding to various gray colors, and the target RGB values are randomly combined to obtain a candidate RGB value sequence. Then, the minimum RGB value representing black is added before the first RGB value of the candidate RGB value sequence, and the maximum RGB value representing white is added after the last RGB value of the candidate RGB value sequence to obtain the target RGB value sequence. In this combination manner, on the one hand, the class interval between black, white and gray is small and difficult to distinguish, and the combination of the RGB values representing these colors can further increase the difficulty of enumerating the target RGB value sequence and further enhance the defense against injection attacks. On the other hand, the light generated based on the target RGB value sequence starts with black light and ends with white light, so that the imaging of the target face in the collected video to be detected presents a sequence starting and ending rule, which helps to improve the injection attack detection accuracy.

[0047] In another embodiment, in order to increase the number of random spaces formed by the combination of the multiple light rays, the attribute of the light ray can further include a non-color attribute, which can specifically include, but is not limited to, at least one of the following attributes: brightness, illumination time length, etc. In this case, based on the target RGB value sequence, the light ray is irradiated to the target face, including the following steps: randomly selecting multiple attribute values from the value range of the non-color attribute to combine, to obtain a non-color attribute sequence; and based on the target RGB value sequence and the non-color attribute sequence, the light ray is irradiated to the target face.

[0048] As an example, the non-color attribute includes brightness and illumination time length. In this case, multiple brightness values are randomly selected from the brightness value range to combine, to obtain a brightness value sequence; multiple time lengths are randomly selected from the time length value range to combine, to obtain a time length sequence; and based on the target RGB value sequence, the brightness value sequence, and the time length sequence, the light ray is irradiated to the target face.

[0049] For example, the multiple light rays include light ray 1 to light ray 4, the target RGB value sequence is {the minimum RGB value representing black, the target RGB value 1 representing light gray, the target RGB value 2 representing dark gray, and the maximum RGB value representing white}, the brightness value sequence is {brightness 1, brightness 2, brightness 3, and brightness 4}, and the time length sequence is {300 ms, 500 ms, 800 ms, and 1000 ms}. In this case, the screen of the terminal device is controlled to continuously emit the light ray with the minimum RGB value and the brightness of brightness 1; after continuously irradiating for 300 ms, the screen is controlled to continuously emit the light ray with the target RGB value 1 and the brightness of brightness 2; after continuously irradiating for 500 ms, the screen is controlled to continuously emit the light ray with the target RGB value 2 and the brightness of brightness 3; after continuously irradiating for 800 ms, the screen is controlled to continuously emit the light ray with the maximum RGB value and the brightness of brightness 4; and after continuously irradiating for 1000 ms, the screen is controlled to stop emitting the light ray. During the period when the target face is irradiated by the above-mentioned multiple light rays, the camera of the terminal device is synchronously controlled to capture images of the target face, to obtain a to-be-detected video.

[0050] In this embodiment, at least one of the illumination parameters such as the brightness, the illumination time length, etc. is configured for the multiple light rays, so that the multiple RGB values, the multiple brightnesses, and the multiple illumination time lengths can be randomly combined, thereby significantly increasing the number of random spaces, further increasing the randomness of the light ray found to the target face, increasing the difficulty of the light ray being enumerated by the attacker, and thereby enhancing the defense against the injection attack.

[0051] In S104, a first gray value of a video frame of the to-be-detected video is obtained through gray transformation.

[0052] In implementation, for each video frame of the video to be detected, the video frame is converted into a corresponding gray image by performing gray scale transformation on the video frame, and then the first gray value of the video frame can be determined according to the gray values of the gray image.

[0053] In an embodiment, the S104 comprises the following steps: Step A1, determining a face key region in the video frame that satisfies a preset pixel distribution condition based on the pixel values of the pixels of the video frame; Step A2, performing gray scale transformation on the face key region to obtain a first gray image; and Step A3, determining the gray mean value of the first gray image as the first gray value of the video frame.

[0054] The preset pixel distribution condition can be set according to actual needs, and the embodiments of the present application do not limit this. As an example, considering that the color of the image region with uniform pixel distribution in the video frame is more obvious and easier to compare and analyze, performing gray scale transformation on this region and then performing injection attack recognition helps to improve the detection accuracy. Therefore, the preset pixel distribution condition can include uniform pixel distribution. In actual application, whether the pixel distribution is uniform can be realized by various pixel analysis algorithms commonly used in the art.

[0055] The face key region can be set according to actual needs, and the embodiments of the present application do not limit this. As an example, considering that the difference between the RGB values of the pseudo-fake face and the RGB values of the light under the same light irradiation is more obvious in the nose and cheek regions, analyzing the RGB values of these regions helps to improve the accuracy of injection attack detection. Therefore, the face key region can include the nose and cheek regions in the video frame.

[0056] For example, first, the video frame is subjected to face key point analysis to obtain nose key points and cheek key points; then, based on the nose key points and the cheek key points, a face region containing the nose and the cheek is cropped from the video frame; then, based on the pixel values of the pixels of the face region, a region with uniform pixel distribution is further cropped from the face region to obtain a face key region; finally, the gray mean value of the pixels of the first gray image obtained by performing gray scale transformation on the face key region is calculated, that is, the gray mean value of the first gray image, and then the gray mean value is taken as the first gray value of the video frame.

[0057] In the embodiment, the face key region in the video frame that satisfies the pixel distribution condition is not only more obvious and easier to compare and analyze in the RGB values presented, but also can clearly distinguish the real face from the pseudo-fake face. By performing gray scale transformation on the face key region to determine the gray mean value, the first gray value obtained can clearly distinguish the real face from the pseudo-fake face, which helps to improve the detection accuracy.

[0058] In another implementation, the S104 includes the following steps: Step B1, determining the illumination direction of the light line illuminating the target face; Step B2, determining the imaging shadow area of the target face in the video frame based on the illumination direction; Step B3, performing gray scale transformation on the imaging shadow area to obtain a second gray scale image; and Step B4, determining the gray scale average of the second gray scale image as the first gray scale value of the video frame.

[0059] In actual application, each light line illuminating the target face can have different illumination directions, which can be selected according to actual needs. By illuminating the target face with light lines in different illumination directions, the collected video frame contains certain depth information, which helps to accurately distinguish real faces from fake faces.

[0060] The imaging shadow area refers to the area where the protruding parts of the target face leave shadows. Under the illumination of light lines in different illumination directions, the imaging shadow area of the target face in the video frame is different. For example, when the target face is illuminated by a left light line, the protruding parts such as the nose, mouth and eyebrows will leave shadows on the right side of the face, and the imaging shadow area is the right side area of the video frame; when the target face is illuminated by a right light line, the protruding parts such as the nose, mouth and eyebrows will leave shadows on the left side of the face, and the imaging shadow area is the left side area of the video frame; when the target face is illuminated by an upper light line, the protruding parts such as the eyebrows and nose will leave shadows on the upper side of the face, and the imaging shadow area is the upper side area of the video frame; when the target face is illuminated by a lower light line, the protruding parts such as the mouth and nose will leave shadows on the lower side of the face, and the imaging shadow area is the upper side area of the video frame.

[0061] In this implementation, the image features of the imaging shadow area are relatively obvious and stable, which can reflect the depth information of the face to some extent, and the real face and the fake face have obvious differences in depth information. By determining the gray scale average after performing gray scale transformation on the imaging shadow area in the video frame, the second gray scale value obtained can distinguish the real face from the fake face, which helps to improve the detection accuracy.

[0062] The present application embodiment shows part of the implementation of the above S104. Of course, it should be understood that the above S104 can also be implemented in other ways, for example, performing gray scale transformation on the entire video frame to obtain a third gray scale image, and determining the gray scale average of the third gray scale image as the first gray scale value of the video frame, etc., which is not limited by the present application embodiment.

[0063] S106, converting the light value label of the video frame into a gray scale value to obtain a second gray scale value of the video frame.

[0064] Each video frame in the to-be-detected video has a corresponding light value label. The light value label represents the attribute of the light irradiating the target face when the video frame is captured, for example, including but not limited to the RGB value, brightness, and the like of the light. In an embodiment, the RGB value of the light has a first corresponding relationship with the gray value, and the brightness of the light has a second corresponding relationship with the gray value. For example, the gray value corresponding to the RGB value representing light green is 200, the gray value corresponding to the RGB value representing dark green is 80, the gray value corresponding to the RGB value representing dark blue is 60, the gray value corresponding to low brightness is 30, the gray value corresponding to moderate brightness is 50, the gray value corresponding to high brightness is 90, and the like.

[0065] In this case, for each video frame, the RGB value indicated by the light value label is converted into a corresponding gray value based on the first corresponding relationship and the RGB value indicated by the light value label of the video frame, and the brightness indicated by the light value label is converted into a corresponding gray value based on the second corresponding relationship and the brightness indicated by the light value label of the video frame; then, the two gray values are weighted and summed to obtain a second gray value of the video frame.

[0066] In actual application, in the case that the brightness of each light can be controlled, such as in the APP use scenario, the light value label of the video frame includes the RGB value and the brightness, in which case, the RGB value of the light can be converted into an HSV color value, and the value of the V component in the HSV color value can be taken as the brightness in the light value label. In the case that the brightness of each light cannot be controlled, such as in the H5 page use scenario, the brightness of the light cannot be directly obtained, in which case, the RGB value of the light can be converted into an HSV color value, and the product of the V component in the HSV color value and a preset brightness coefficient can be taken as the brightness in the light value label. The preset brightness coefficient can be set according to actual needs, for example, the brightness coefficient is 0.3 when the light is dark, the brightness coefficient is 0.5 when the light is normal, and the brightness coefficient is 0.9 when the light is bright.

[0067] In S108, whether the to-be-detected video is subjected to the injection attack is determined based on the first gray value and the second gray value.

[0068] Considering that there is a difference between the RGB value of the target face presented in the video subjected to the injection attack and the RGB value of the light during irradiation of the light to the target face, the difference is more obvious in the gray value, and whether the collected video is subjected to the injection attack can be determined by identifying whether there is a significant difference between the gray value of the target face and the gray value of the light in the to-be-detected video. The entire algorithm logic is simple, stable, and has a high success rate, and the comparison of the gray value is easier than the comparison of the original pixel value, and has the advantage of lightweight.

[0069] In an embodiment, the S108 comprises the following steps: step C1, for each video frame in the to-be-detected video, matching the first gray value and the second gray value of the video frame to obtain a matching degree; step C2, if the matching degree between the first gray value and the second gray value of more than a preset proportion of video frames in the to-be-detected video is less than a preset matching degree, it is determined that the light change presented by the target face in the to-be-detected video is inconsistent with the light change irradiating the target face, and it is further determined that the to-be-detected video is subjected to the injection attack. Otherwise, if the matching degree between the first gray value and the second gray value of more than a preset proportion of video frames in the to-be-detected video is greater than or equal to the preset matching degree, it is determined that the light change presented by the target face in the to-be-detected video is consistent with the light change irradiating the target face, and it is further determined that the to-be-detected video is a real face video.

[0070] In another embodiment, the S108 comprises the following steps: step D1, generating a first gray value sequence of the to-be-detected video based on the first gray value of the video frame in the to-be-detected video; step D2, generating a second gray value sequence of the to-be-detected video based on the second gray value of the video frame in the to-be-detected video; step D3, performing correlation analysis on the first gray value sequence and the second gray value sequence to obtain a first coefficient; and step D4, if the first coefficient is less than a preset coefficient, it is determined that the to-be-detected video is subjected to the injection attack.

[0071] In actual application, the correlation analysis can use various correlation analysis algorithms commonly used in the art, such as Pearson correlation analysis, etc., which are not limited by the embodiments of the present application. If the first coefficient between the first gray value sequence and the second gray value sequence is greater, it indicates that the consistency between the light change presented by the target face in the to-be-detected video and the light change irradiating the target face is higher, and the possibility of the to-be-detected video being a real face video is greater. If the first coefficient between the first gray value sequence and the second gray value sequence is smaller, it indicates that the consistency between the light change presented by the target face in the to-be-detected video and the light change irradiating the target face is lower, and the possibility of the to-be-detected video being a real face video is smaller, and it is more likely to be a video injected by hijacking the camera (such as an image considered to be edited or forged).

[0072] For example, first gray scale values of video frames in the to-be-detected video are combined according to the time sequence of the video frames to obtain a first gray scale value sequence, and second gray scale values of the video frames in the to-be-detected video are combined according to the time sequence of the video frames to obtain a second gray scale value sequence. Then, a first coefficient between the first gray scale value sequence and the second gray scale value sequence is calculated by Pearson correlation analysis method. If the first coefficient is greater than or equal to a preset coefficient, it indicates that the light change presented by the target face in the to-be-detected video is consistent with the light change irradiating the target face, and it is further determined that the to-be-detected video is a real face video. If the first coefficient is less than the preset coefficient, it indicates that the light change presented by the target face in the to-be-detected video is inconsistent with the light change irradiating the target face, and it is further determined that the to-be-detected video is subjected to injection attack.

[0073] In the embodiment, by performing correlation analysis on the entire gray scale value sequence of the to-be-detected video, the consistency between the light change presented by the target face in the to-be-detected video and the light change irradiating the target face can be quickly and accurately identified, and whether the to-be-detected video is subjected to injection attack can be quickly and accurately identified. The entire algorithm logic is simple, stable, and has high success rate. The correlation analysis based on the gray scale value sequence is relatively easy and has the advantage of lightweight.

[0074] In another embodiment, considering that there is a certain delay between the collection time of the to-be-detected video and the generation time of the light, for example, after controlling the light source to emit light, the process of the sensor of the terminal device collecting the light and collecting the video is a physical process, specifically including sensor photosensing, data processing and conversion, etc. The process takes time, and thus there is a delay between the generation time of the light and the collection time of the to-be-detected video. This delay can cause a large misalignment between the two gray scale value sequences, which can cause the originally related two gray scale value sequences to become unrelated, and thus the detection result is inaccurate.

[0075] Therefore, in step D3, an interval duration between the collection time of the to-be-detected video and the generation time of the light is obtained; based on the interval duration, the first gray scale value sequence and the second gray scale value sequence are aligned; and correlation analysis is performed on the first gray scale value sequence and the second gray scale value sequence after the alignment to obtain the first coefficient.

[0076] As an example, the first gray scale value sequence and the second gray scale value sequence are normalized respectively; then, based on the above interval duration, the first gray scale value sequence after the normalization is left shifted by a number of bits relative to the second gray scale value sequence after the normalization, so that the two gray scale value sequences are consistent in time, thereby realizing the alignment of the two; finally, correlation analysis is performed on the first gray scale value sequence and the second gray scale value sequence after the alignment to obtain the first coefficient.

[0077] For example, the two gray value sequences before alignment are as follows:

[0078] The first gray value sequence: 0010233240001

[0079] The second gray value sequence: 10233240001

[0080] By left shifting the first gray value sequence by two bits, the two gray value sequences are as follows:

[0081] The first gray value sequence after left shifting: 10233240001

[0082] The second gray value sequence: 10233240001

[0083] Therefore, by left shifting the first gray value sequence by a number of bits, the two can be aligned.

[0084] Alternatively, the second gray value sequence can also be right shifted by two bits, and the two gray value sequences are as follows:

[0085] The first gray value sequence: 0010233240001

[0086] The second gray value sequence: 0010233240001

[0087] Therefore, by right shifting the second gray value sequence by a number of bits, the two can be aligned.

[0088] In this embodiment, by aligning the first gray value sequence and the second gray value sequence and then performing correlation analysis, the delay of the collection time of the to-be-detected video relative to the generation time of the light can be avoided to affect the injection attack detection result, thereby improving the detection accuracy.

[0089] The injection attack detection method provided by one or more embodiments of the present application considers that there is a difference between the light change presented by the target face in the video subjected to the injection attack and the light change of the light irradiating the target face during the irradiation of the light to the target face, and this difference is more obvious in the gray value. During the irradiation of the light to the target face, the target face is photographed to obtain a to-be-detected video; whether the video obtained is subjected to the injection attack can be determined by identifying whether there is an obvious difference between the gray value of the video frame in the to-be-detected video and the gray value of the light irradiating the target face, the entire algorithm logic is simple, stable, and has a high success rate, and the comparison of the gray value is easier than the comparison of the original pixel value and has the advantage of lightweight. Therefore, the injection attack detection method provided by the embodiments of the present application can be run on a mobile terminal in real time and is suitable for various scenes such as APP and H5.

[0090] The injection attack detection algorithm provided by the embodiments of the present application can be used in the live body detection link of an online face recognition system, as a sub-link for preventing injection attacks, and combined with other live body verification technologies, such as face quality verification technology, motion live body / quiet live body detection technology, and the like, to achieve the best anti-fake effect.

[0091] As shown in FIG. 1, the terminal device enters an identity verification process in response to a user's identity verification request. In the identity verification process, first, a face quality verification algorithm is used to verify the quality of a face image captured by a camera of the terminal device, specifically including but not limited to face posture detection, distance detection, ambient light detection, and the like, and in the case that the detection result does not meet the requirements, the user is immediately prompted to make adjustments. For example, when it is detected that the face is too far from the screen of the terminal device, the user is prompted to get closer to ensure that the light has sufficient illumination intensity on the face. Figure 2 Next, a live body detection algorithm is used to detect the live body of the face to intercept conventional presentation attacks, such as electronic screen pseudo-fake faces, paper photos, paper masks, 3D masks, and the like.

[0092] After the live body detection verification passes, the injection attack detection algorithm provided by the embodiments of the present application is used to detect whether the to-be-detected video collected by the camera is subjected to an injection attack. As shown in FIG. 2, first, the RGB values, brightness, and illumination time length of multiple lights and the like are randomly configured. Then, the screen of the terminal device is controlled to emit light according to the configured properties to form multiple lights and illuminate the target face. At the same time, the camera is controlled to capture images of the target face to obtain a to-be-detected video. Further, the injection attack detection algorithm provided by the embodiments of the present application is used to perform grayscale transformation on the video frames of the to-be-detected video to obtain first grayscale values of the video frames to form a first grayscale value sequence, and convert the light value labels of the video frames into grayscale values to obtain second grayscale values of the video frames to form a second grayscale value sequence. Finally, the correlation between the first grayscale value sequence and the second grayscale value sequence is calculated, so that based on the first grayscale values and the second grayscale values of the video frames in the to-be-detected video, it can be determined whether the to-be-detected video is subjected to an injection attack.

[0093] Figure 3 If the to-be-detected video is subjected to an injection attack, subsequent processing of the to-be-detected video is rejected, and an identity verification failure message is output. If the to-be-detected video is a real face video, i.e., not subjected to an injection attack, an identity verification success message is output, and subsequent processing of the to-be-detected video is performed.

[0094] If the to-be-detected video is subjected to an injection attack, subsequent processing of the to-be-detected video is rejected, and an identity verification failure message is output. If the to-be-detected video is a real face video, i.e., not subjected to an injection attack, an identity verification success message is output, and subsequent processing of the to-be-detected video is performed.

[0095] ​The above describes particular embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims can be performed in a different order than those in the embodiments and still achieve desirable results. Additionally, the processes depicted in the accompanying figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous or possible.

[0096] Based on the same inventive concept, the embodiments of the present application also provide an injection attack detection device. Please refer to Figure 4 A structural schematic diagram of an injection attack detection device 400 provided by an embodiment of the present application is shown in the figure. The device 400 comprises an acquisition unit 410, a first conversion unit 420, a second conversion unit 430, and a detection unit 440.

[0097] The acquisition unit 410 is configured to acquire a to-be-detected video of a target face irradiated by light.

[0098] The first conversion unit 420 is configured to perform grayscale conversion on a video frame of the to-be-detected video to obtain a first grayscale value of the video frame.

[0099] The second conversion unit 430 is configured to convert a light value label of the video frame into a grayscale value to obtain a second grayscale value of the video frame.

[0100] The detection unit 440 is configured to determine whether the to-be-detected video is subjected to an injection attack based on the first grayscale value and the second grayscale value.

[0101] In another embodiment, the first conversion unit 420 is configured to:

[0102] determine a face key region in the video frame that meets a preset pixel distribution condition based on a pixel value of a pixel of the video frame;

[0103] perform grayscale conversion on the face key region to obtain a first grayscale image;

[0104] determine a grayscale mean value of the first grayscale image as the first grayscale value of the video frame.

[0105] In another embodiment, the first conversion unit 420 is configured to:

[0106] determine an irradiation direction of the light irradiating the target face;

[0107] determine an imaging shadow region of the target face in the video frame based on the irradiation direction;

[0108] performing a gray scale transformation on the imaging shadow region to obtain a second gray scale image;

[0109] determining a gray scale mean value of the second gray scale image as a first gray scale value of the video frame.

[0110] In another embodiment, the detection unit 440 is configured to:

[0111] generate a first gray scale value sequence of the video to be detected based on the first gray scale value of the video frame in the video to be detected;

[0112] generate a second gray scale value sequence of the video to be detected based on the second gray scale value of the video frame in the video to be detected;

[0113] perform a correlation analysis on the first gray scale value sequence and the second gray scale value sequence to obtain a first coefficient;

[0114] if the first coefficient is less than a preset coefficient, determine that the video to be detected is subjected to an injection attack.

[0115] In another embodiment, when the detection unit 440 performs a correlation analysis on the first gray scale value sequence and the second gray scale value sequence to obtain a first coefficient, the detection unit 440 performs the following steps:

[0116] obtain an interval duration between a capture time of the video to be detected and a generation time of the light;

[0117] perform an alignment processing on the first gray scale value sequence and the second gray scale value sequence based on the interval duration;

[0118] perform a correlation analysis on the first gray scale value sequence and the second gray scale value sequence after the alignment processing to obtain a first coefficient.

[0119] In another embodiment, the attribute of the light includes a color attribute, the color attribute represents an RGB value of the light, and the generation manner of the light irradiating the target face includes:

[0120] randomly select a plurality of RGB values from an RGB value range to obtain a target RGB value sequence;

[0121] irradiate the light to the target face based on the target RGB value sequence.

[0122] In another embodiment, the randomly selecting a plurality of RGB values from an RGB value range to obtain a target RGB value sequence includes:

[0123] selecting a maximum RGB value and a minimum RGB value from the RGB value range, and randomly selecting at least one target RGB value from the RGB value range, the target RGB value being the same in R component, G component and B component, and the target RGB value being between the maximum RGB value and the minimum RGB value;

[0124] combining the maximum RGB value, the minimum RGB value and the at least one target RGB value to obtain the target RGB value sequence.

[0125] In another embodiment, the attribute of the light also includes a non-color attribute;

[0126] The method also includes irradiating the target face with light based on the target RGB value sequence, including:

[0127] randomly selecting a plurality of attribute values from a value range of the non-color attribute to obtain a non-color attribute sequence;

[0128] Irradiating the target face with light based on the target RGB value sequence and the non-color attribute sequence.

[0129] Obviously, the injection attack detection device provided by the embodiments of the present application can be used as Figure 1 the execution subject of the injection attack detection method shown in the method, for example Figure 1 In the injection attack detection method shown in the method, step S102 can be performed by Figure 4 the acquisition unit 410 in the injection attack detection device shown in the device, and step S104 can be performed by Figure 4 the first conversion unit 420 in the injection attack detection device shown in the device, and step S106 can be performed by Figure 4 the second conversion unit 430 in the injection attack detection device shown in the device, and step S108 can be performed by Figure 4 the detection unit 440 in the injection attack detection device shown in the device.

[0130] According to another embodiment of the present application, Figure 4 The various units in the injection attack detection device shown in the device can be combined into one or several other units respectively or all, or some of the units can be further split into a plurality of units with smaller functions to constitute, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above units are divided based on logical functions, and in actual application, the functions of one unit can also be realized by multiple units, or the functions of multiple units can be realized by one unit. In the embodiments of the present application, the injection attack detection device can also include other units, and in actual application, these functions can also be assisted by other units, and can be realized by multiple units.

[0131] According to another embodiment of the present application, the injection attack detection apparatus as shown in Figure 1 the injection attack detection method of the present application can be constructed by running a computer program (including program codes) capable of executing the steps involved in the corresponding method as shown in Figure 4 the injection attack detection method of the present application can be constructed by running a computer program (including program codes) capable of executing the steps involved in the corresponding method as shown in

[0132] Figure 5 is a structural schematic diagram of an electronic device according to an embodiment of the present application. Please refer to Figure 5 At the hardware level, the electronic device includes a processor, and optionally further includes an internal bus, a network interface, and a memory. The memory can include a memory such as a high-speed random access memory (RAM), and can also include a non-volatile memory such as at least one disk memory. Of course, the electronic device can also include other hardware required by the business.

[0133] The processor, the network interface, and the memory can be connected to each other through the internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 only one bidirectional arrow is used in the figure, but it does not mean that there is only one bus or only one type of bus.

[0134] The memory is used to store programs. Specifically, the program can include program codes, and the program codes include computer operation instructions. The memory can include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0135] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it, forming an injection attack detection device at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:

[0136] Obtain a video of the target face to be detected using light;

[0137] Performing grayscale transformation on a video frame of the video to be detected to obtain a first grayscale value of the video frame;

[0138] Converting the light value label of the video frame into a grayscale value to obtain a second grayscale value of the video frame;

[0139] Based on the first grayscale value and the second grayscale value, it is determined whether the video to be detected is subjected to an injection attack.

[0140] The above application Figure 1 The method performed by the injection attack detection device disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or by software instructions. The above processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0141] The electronic device may also perform Figure 1 Method and implementation of injection attack detection device in Figure 1、 Figure 2 、 Figure 3 The functions of the embodiments of the above-described embodiments are not repeated here.

[0142] The embodiments of the present application also provide a computer program product, which comprises a non-transitory computer-readable storage medium storing a computer program, the computer program being operable to cause a computer to perform some or all of the steps of the injection attack detection method provided by the embodiments of the present application.

[0143] Of course, in addition to the software implementation, the electronic device of the present application does not exclude other implementation manners, such as logic devices or a combination of software and hardware, and the like, that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or a logic device.

[0144] The embodiments of the present application also propose a computer-readable storage medium storing one or more programs, the one or more programs comprising instructions that, when executed by a portable electronic device comprising a plurality of applications, can cause the portable electronic device to perform the method of the embodiments shown above, and specifically to perform the following operations: Figure 1 The embodiments of the present application also propose a computer-readable storage medium storing one or more programs, the one or more programs comprising instructions that, when executed by a portable electronic device comprising a plurality of applications, can cause the portable electronic device to perform the method of the embodiments shown above, and specifically to perform the following operations:

[0145] Obtaining a to-be-detected video of irradiating a target human face with light;

[0146] Performing gray scale conversion on a video frame of the to-be-detected video to obtain a first gray scale value of the video frame;

[0147] Converting a light value label of the video frame into a gray scale value to obtain a second gray scale value of the video frame;

[0148] Determining whether the to-be-detected video is subjected to an injection attack based on the first gray scale value and the second gray scale value.

[0149] In summary, the above only describes the preferred embodiments of the present application, and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

[0150] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer. Specifically, the computer may, for example, be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0151] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0152] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed, or inherent to such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.

[0153] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

Claims

1. A method for detecting an injection attack, characterized in that: include: Obtain a video of the target face to be detected using light; Performing grayscale transformation on a video frame of the video to be detected to obtain a first grayscale value of the video frame; Converting the light value label of the video frame into a grayscale value to obtain a second grayscale value of the video frame; Based on the first grayscale value and the second grayscale value, it is determined whether the video to be detected is subjected to an injection attack.

2. The method according to claim 1, characterized in that The step of performing grayscale transformation on the video frame of the video to be detected to obtain a first grayscale value of the video frame includes: determining, based on pixel values ​​of pixels of the video frame, a key facial area in the video frame that meets a preset pixel distribution condition; Performing grayscale transformation on the key facial area to obtain a first grayscale image; The grayscale mean value of the first grayscale image is determined as the first grayscale value of the video frame.

3. The method according to claim 1, characterized in that The step of performing grayscale transformation on the video frame of the video to be detected to obtain a first grayscale value of the video frame includes: Determining the direction of light irradiating the target face; Determining an imaging shadow area of ​​the target face in the video frame based on the illumination direction; Performing grayscale transformation on the imaging shadow area to obtain a second grayscale image; The grayscale mean value of the second grayscale image is determined as the first grayscale value of the video frame.

4. The method according to claim 1, wherein The determining, based on the first grayscale value and the second grayscale value, whether the video to be detected is subjected to an injection attack includes: generating a first grayscale value sequence of the video to be detected based on a first grayscale value of a video frame in the video to be detected; generating a second grayscale value sequence of the video to be detected based on the second grayscale value of the video frame in the video to be detected; performing a correlation analysis on the first gray value sequence and the second gray value sequence to obtain a first coefficient; If the first coefficient is less than a preset coefficient, it is determined that the video to be detected is subjected to an injection attack.

5. The method according to claim 4, characterized in that The performing correlation analysis on the first gray value sequence and the second gray value sequence to obtain a first coefficient includes: Obtaining the interval between the capture moment of the video to be detected and the generation moment of the light; performing alignment processing on the first grayscale value sequence and the second grayscale value sequence based on the interval duration; A correlation analysis is performed on the aligned first gray value sequence and the second gray value sequence to obtain a first coefficient.

6. The method according to any one of claims 1 to 5, characterized in that The light attribute includes a color attribute, and the color attribute represents an RGB value of the light. The light irradiating the target face is generated in the following manner: Randomly select multiple RGB values ​​from the RGB value range and combine them to obtain the target RGB value sequence; Based on the target RGB value sequence, light is irradiated toward the target face.

7. The method according to claim 6, characterized in that The method randomly selects multiple RGB values ​​from the RGB value range and combines them to obtain a target RGB value sequence, including: Selecting a maximum RGB value and a minimum RGB value from the RGB value range, and randomly selecting at least one target RGB value from the RGB value range, wherein the R component, the G component, and the B component of the target RGB value are the same, and the target RGB value is between the maximum RGB value and the minimum RGB value; The maximum RGB value, the minimum RGB value, and the at least one target RGB value are combined to obtain the target RGB value sequence.

8. The method according to claim 6, characterized in that The properties of the light also include non-color properties; The irradiating light toward the target face based on the target RGB value sequence includes: Randomly selecting multiple attribute values ​​from the value range of the non-color attribute and combining them to obtain a non-color attribute sequence; Based on the target RGB value sequence and the non-color attribute sequence, light is irradiated toward the target face.

9. An injection attack detection device, characterized in that: include: An acquisition unit, configured to acquire a video of a target face to be detected by illuminating it with light; A first transformation unit is configured to perform grayscale transformation on a video frame of the video to be detected to obtain a first grayscale value of the video frame; a second conversion unit, configured to convert the light value label of the video frame into a grayscale value to obtain a second grayscale value of the video frame; A detection unit is configured to determine whether the video to be detected is subjected to an injection attack based on the first grayscale value and the second grayscale value.

10. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the injection attack detection method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the injection attack detection method according to any one of claims 1 to 8.

12. A computer program product, characterized in that The computer program product comprises a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to execute part or all of the steps of the method according to any one of claims 1 to 8.