A face recognition method, device, equipment, medium and product
By determining the risk level based on the attributes and attribute values of the facial recognition scenario and dynamically adjusting the corresponding strategies, the problem of time delays and resource waste caused by unreasonable facial recognition technology in complex banking scenarios is solved, achieving a balance between security and efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2025-08-15
- Publication Date
- 2026-07-31
AI Technical Summary
Banks have a large number of complex facial recognition scenarios. If different applications and scenarios use inappropriate facial recognition technologies, it will cause time delays and waste of resources.
Based on the attributes and attribute values of the face recognition scenario, the risk level is determined, and the biometric detection strategy, equipment environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy are dynamically adjusted based on the risk level to generate the target face recognition strategy.
It enables precise response to risks in facial recognition scenarios, ensures that security strategies are matched with risk levels in real time, reduces security risks in high-risk scenarios, avoids over-protection in low-risk scenarios, and improves system flexibility and resource utilization.
Smart Images

Figure CN122493538A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of facial recognition technology, information security, and artificial intelligence, and can be used in the field of financial technology. In particular, it relates to a facial recognition method, device, equipment, medium, and product. Background Technology
[0002] Facial recognition scenarios in banking are numerous and complex. Preliminary statistics indicate that they involve dozens of applications (such as personal e-banking, personal mobile banking, digital currency, corporate e-banking, and financial management) and over a hundred scenarios (such as mobile banking login, password reset, account cancellation, loan application, credit report inquiry, and fund transfer). Sub-scenarios (such as loan applications for different amounts, categories, and purposes) are even more diverse. Each scenario has different requirements for facial recognition technology. For example, some high-risk scenarios, such as large overseas transfers, require extremely meticulous security checks to ensure the highest possible accuracy. Conversely, some low-risk, high-frequency scenarios, even with the highest level of security authentication, may experience low pass rates and long verification times, significantly degrading the customer experience. Using inappropriate facial recognition technology for different applications and scenarios can lead to time delays and wasted resources. Summary of the Invention
[0003] This invention provides a face recognition method, device, equipment, medium, and product to address the problem that face recognition scenarios in banks are numerous and complex, and that using inappropriate face recognition technologies in different applications and scenarios can lead to time delays and resource waste.
[0004] According to one aspect of the present invention, a face recognition method is provided, comprising:
[0005] The risk level of a face recognition scenario is determined based on its attributes and attribute values. The attributes of the face recognition scenario include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk.
[0006] Based on the risk level, the configuration information of the multidimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information; the face recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
[0007] According to another aspect of the present invention, a face recognition device is provided, comprising:
[0008] The risk level determination module is used to determine the risk level of a face recognition scenario based on its attributes and attribute values. The attributes of the face recognition scenario include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk.
[0009] The strategy determination module is used to determine the configuration information of the multidimensional control factors in the candidate face recognition strategy according to the risk level, and generate the target face recognition strategy according to the configuration information; the face recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
[0010] According to another aspect of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the face recognition method according to any embodiment of the present invention.
[0011] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0012] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the face recognition method according to any embodiment of the present invention.
[0013] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the face recognition method according to any embodiment of the present invention.
[0014] According to another aspect of the present invention, a computer program product is provided, comprising a computer program / instructions that, when executed by a processor, implement the face recognition method as described in any embodiment of the present invention.
[0015] This invention, through a systematic quantification of attribute importance and risk factors, can objectively and consistently assess the risk level of facial recognition scenarios, reducing subjective bias. The scientific allocation of weights ensures more accurate impact of key attributes on risk values, while risk level classification provides clear security thresholds, helping to determine the risk level of different scenarios and thus the corresponding facial recognition strategy, improving the efficiency and reliability of overall security protection. By dynamically adjusting the working state and configuration parameters of control factors according to the risk level, it achieves precise response to risks in facial recognition scenarios, ensuring real-time matching between security strategies and risk levels. Selecting the optimal configuration based on risk levels effectively reduces security risks in high-risk scenarios while avoiding over-protection in low-risk scenarios, thereby improving system flexibility and resource utilization while ensuring security, achieving a balance between security and efficiency.
[0016] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a first flowchart of a face recognition method provided in an embodiment of the present invention;
[0019] Figure 2 This is a second flowchart of a face recognition method provided in an embodiment of the present invention;
[0020] Figure 3 This is a schematic diagram of the structure of a face recognition device provided in an embodiment of the present invention;
[0021] Figure 4 This is a schematic diagram of the structure of an electronic device that implements an embodiment of the present invention. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] All information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) disclosed herein are information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of such data comply with the relevant laws, regulations and standards of the relevant regions.
[0025] Figure 1 This is a first flowchart of a face recognition method provided in an embodiment of the present invention. This embodiment is applicable to complex application scenarios in banks, establishing an adaptive scenario parameter configuration mechanism to dynamically adapt to various face recognition technologies, achieving a comprehensive optimal solution for security and user experience. This method can be executed by a face recognition device, which can be implemented in hardware and / or software, and can be configured in an electronic device with corresponding data processing capabilities. Figure 1 As shown, the method includes:
[0026] S110. Determine the risk level of the face recognition scenario based on its attributes and attribute values.
[0027] The attributes of the facial recognition scenario include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk.
[0028] By obtaining data such as single transaction amount, daily cumulative amount, and historical average fraud loss from the transaction system and risk control database, financial risks are determined; by obtaining user information regarding fund changes and account permission levels from the user permission management system, identity sensitivity is determined; by obtaining data on accessing devices, network IP risk scores, and proxy tool usage from terminal probes and network traffic analysis, operational environment risks are determined; by obtaining risk coefficients for operation periods (e.g., +2 points for late-night operations) from the timestamp analysis module, time sensitivity is determined; by obtaining operational speed deviation and historical successful transaction patterns from the user behavior analysis engine, user behavior baselines are determined; by obtaining the number of accounts associated with the same device and the number of recent abnormal operations from graph calculation network, associated business risks are determined; and by obtaining the deviation between IP address location and operation location from the geofencing system and matching it with a list of high-risk areas, geographical location risks are determined.
[0029] Optionally, determining the risk level of a face recognition scenario based on its attributes and attribute values includes: constructing a judgment matrix based on the relative importance of the attributes; determining the weight of each attribute of the face recognition scenario based on the judgment matrix; determining the risk value of the face recognition scenario based on the weight and attribute value of each attribute; and determining the risk level of the face recognition scenario based on the risk value and a preset classification rule.
[0030] For specific scenarios, several relevant business experts and financial security experts were invited to conduct pairwise comparisons of the relative importance of attributes in facial recognition scenarios, constructing a judgment matrix. Assume there are n evaluation indicators C1, C2, ..., C... n A judgment matrix A = (a) is constructed by business experts and financial security experts. ij ) n×n , where a ij Indicator C i Compared to C j The importance ratio. Determine the eigenvector corresponding to the largest eigenvalue of the judgment matrix, normalize this eigenvector, and obtain the weight vector.
[0031] The consistency check verifies whether the judgment matrix satisfies logical consistency. For example, if indicator 1 is 3 times more important than indicator 2, and indicator 2 is 2 times more important than indicator 3, then logically indicator 1 should be 6 times more important than indicator 3. If the actual value of indicator 1 relative to indicator 3 in the judgment matrix is not 6, it indicates a contradiction in the judgment, and the matrix needs to be adjusted. If the consistency check passes, it means that all pairwise comparisons in the judgment matrix satisfy transitivity; its eigenvectors (weights) can truly reflect the relative importance between indicators, and the weight allocation result is not distorted due to logical conflicts; a highly consistent judgment matrix can reduce the sensitivity of weight allocation to input perturbations and improve the stability of the model in complex scenarios. If the consistency check passes, then the weight vector represents the weights of each attribute in the face recognition scenario.
[0032] The risk value of the face recognition scenario is determined based on the weight of each attribute and the weighted sum of the attribute values, as shown in the following formula (1):
[0033]
[0034] Among them, S i S is the scene score (attribute value) for the i-th attribute of a face recognition scene. i ∈[0,10];w i R is the weight of the i-th attribute in the face recognition scenario; R is the risk value of the face recognition scenario.
[0035] Based on risk values and preset classification rules, the risk level of a facial recognition scenario is determined. For example, a risk value range of 0.0–1.9 corresponds to Level 1 risk, such as account balance inquiries; 2.0–3.4 corresponds to Level 2 risk, such as personal information modification; 3.5–4.8 corresponds to Level 3 risk, such as third-party quick login; 4.9–6.2 corresponds to Level 4 risk, such as credit card repayments; 6.3–7.6 corresponds to Level 5 risk, such as cross-border remittances; and a risk value ≥7.7 corresponds to Level 6 risk, such as large loan applications.
[0036] For example, a branch launched a new generation of consumer loans and is now integrating facial recognition into the loan service to mitigate related risks. Five experts from the head office and branches specializing in credit and inclusive finance were invited to score and evaluate the relative importance of seven attributes in the current scenario: funding risk, identity sensitivity, operational environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk. The results are shown in Table 1 below.
[0037] Table 1
[0038]
[0039]
[0040] Weights are calculated using the eigenvector method: W = [0.30, 0.25, 0.18, 0.12, 0.08, 0.05, 0.02] T Consistency test: CI = 0.018, RI = 1.32, CR = 0.018 / 1.32 = 0.0136 < 0.1 (passes the test).
[0041] A customer of this bank intends to apply for a consumer loan of 150,000 yuan. Based on this user information, the system triggers feature quantification of 7 attributes. The quantification results are shown in Table 2 below:
[0042] Table 2
[0043]
[0044]
[0045] Risk value calculation:
[0046]
[0047] The risk value is between 3.5 and 4.8, which is classified as Level 3 risk. A face recognition strategy corresponding to Level 3 risk is adopted for risk defense.
[0048] By extracting key attributes of a scene and integrating expert scores, the importance of attributes and risk factors can be systematically quantified. This allows for an objective and consistent assessment of the risk level of a facial recognition scene, reducing subjective bias. The scientific allocation of weights ensures that the impact of key attributes on risk values is more accurate, while the risk level classification provides clear security thresholds, which helps to determine the risk level of different scenes and thus determine the corresponding facial recognition strategy, improving the efficiency and reliability of overall security protection.
[0049] S120. Based on the risk level, determine the configuration information of the multi-dimensional control factors in the candidate face recognition strategy, and generate the target face recognition strategy based on the configuration information.
[0050] The face recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
[0051] A four-layer strategy system is constructed, comprising biometric detection strategy, equipment environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy, supporting the intelligent configuration of no less than 200 multi-dimensional control factors. Based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information.
[0052] This invention, through a systematic quantification of attribute importance and risk factors, can objectively and consistently assess the risk level of facial recognition scenarios, reducing subjective bias. The scientific allocation of weights ensures more accurate impact of key attributes on risk values, while risk level classification provides clear security thresholds, helping to determine the risk level of different scenarios and thus the corresponding facial recognition strategy, improving the efficiency and reliability of overall security protection. By dynamically adjusting the working state and configuration parameters of control factors according to the risk level, it achieves precise response to risks in facial recognition scenarios, ensuring real-time matching between security strategies and risk levels. Selecting the optimal configuration based on risk levels effectively reduces security risks in high-risk scenarios while avoiding over-protection in low-risk scenarios, thereby improving system flexibility and resource utilization while ensuring security, achieving a balance between security and efficiency.
[0053] In one optional implementation, the method further includes: optimizing the configuration information of the multidimensional control factors in the candidate face recognition strategy based on reinforcement learning; performing face recognition according to the optimized configuration information of the multidimensional control factors; determining the reward based on the recognition success rate, recognition error rate, recognition time, and expected recognition time; and updating the configuration information of the multidimensional control factors if the reward is greater than the reward before the configuration information optimization.
[0054] Based on reinforcement learning, the configuration information of multidimensional regulatory factors is optimized and updated, and the reward determination process is shown in the following formula (2):
[0055]
[0056] If the reward after optimizing the configuration information of the multidimensional regulatory factor is greater than the reward before optimization, then the configuration information of the multidimensional regulatory factor is updated.
[0057] For example, if only 68% of users aged 60 and above achieve the 30° head turn, the recognition error rate spikes to 0.32% (industry average 0.1%). This user group's average head turn is 25.3°, below the 30° threshold; the timeout rate is 42% (expected to be completed within 6 seconds, but actually takes 6.8 seconds). Therefore, the head turn threshold in the head turn action control factor configuration is adjusted from 30° to 25°; the expected recognition time per action is adjusted from 6 seconds to 8 seconds. Face recognition is then performed based on the optimized configuration of the head turn action control factor. If the reward after optimization is greater than the reward before optimization, the configuration of the head turn action control factor is updated.
[0058] By leveraging the dynamic optimization capabilities of reinforcement learning, the system automatically adjusts the configuration of multi-dimensional control factors to achieve an optimal balance between recognition success rate, error rate, and efficiency (recognition time) in face recognition strategies. Through continuous feedback and reward mechanisms, the system can adapt to different scenario requirements, improving recognition accuracy while reducing false recognition rate and optimizing response speed. This significantly enhances the intelligence level and overall performance of face recognition methods, while reducing manual parameter tuning costs and achieving efficient and reliable adaptive security protection.
[0059] Figure 2 This is a second flowchart of a face recognition method provided in an embodiment of the present invention. This embodiment optimizes and improves the process of "determining the configuration information of multi-dimensional control factors in the candidate face recognition strategy according to the risk level, and generating the target face recognition strategy according to the configuration information" based on the above embodiment. For example... Figure 2 As shown, the method includes:
[0060] S210. Determine the risk level of the face recognition scenario based on its attributes and attribute values.
[0061] The attributes of facial recognition scenarios include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk.
[0062] Optionally, based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, including: for any control factor, determining the working status of the control factor based on the risk level; if the control factor is in an enabled state, determining the available configuration of the control factor; based on the risk level, selecting a target configuration from the available configurations, and determining the configuration parameters of the target configuration to obtain the configuration information of the control factor.
[0063] By dynamically adjusting the working status and configuration parameters of the control factors according to the risk level, the system can accurately respond to the risks in facial recognition scenarios and ensure that the security strategy matches the risk level in real time. By selecting the optimal configuration based on the risk level, the system can effectively reduce the security risks in high-risk scenarios and avoid over-protection in low-risk scenarios. This ensures security while improving system flexibility and resource utilization, achieving a balance between security and efficiency.
[0064] The facial recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
[0065] With the development of multimodal large model technology, banks have encountered new attack methods such as AI face swapping and deepfakes in the face recognition process. AI face swapping attacks can imitate biological features such as blinking and turning the head, and traditional liveness detection is prone to failure. The face recognition strategy in this embodiment of the invention includes a face swapping recognition model, and different face swapping recognition model configuration strategies are set according to different risk levels.
[0066] S220. If the candidate face recognition strategy is a face-swapping recognition model configuration strategy, then the multi-dimensional control factors include the face-swapping recognition model version, risk threshold, and response strategy.
[0067] S230. Determine the working status of the face-swapping recognition model based on the risk level.
[0068] When the risk level is Level 1, facial recognition is a high-frequency scenario with extremely low financial risk. In this case, the face recognition strategy does not enable the face-swapping model to avoid degrading the user experience. Without using the face-swapping model, there is no need to configure the face-swapping model version or risk threshold; the response strategy is configured to log only.
[0069] S240. If the face-swapping recognition model is enabled, determine the available version of the face-swapping recognition model and the available configuration of the risk threshold.
[0070] When the risk level is not Level 1, the face recognition strategy includes a face-swapping model configuration strategy. The face-swapping model is enabled, and it is necessary to determine the available versions of the face-swapping model and the available configurations of the risk threshold. The available configurations of the risk threshold include the false recognition rate.
[0071] S250. Based on the risk level, select a target face-swapping recognition model from at least two available versions of face-swapping recognition models, determine the configuration parameters of the false recognition rate, and obtain the configuration information of the face-swapping recognition model version and the false recognition rate.
[0072] The different versions of the face-swapping recognition model include varying numbers of facial feature detection points. For a risk level of 2, the basic version V1.0 face-swapping recognition model with 21 facial feature detection points is selected as the target model; the false recognition rate is configured to be 0.1%. For a risk level of 3, the enhanced version V2.0 face-swapping recognition model with 48 facial feature detection points is selected as the target model; the false recognition rate is configured to be 0.05%. For a risk level of 4, the professional version V3.0 face-swapping recognition model with 72 facial feature detection points is selected as the target model; the false recognition rate is configured to be 0.01%. For a risk level of 5, the financial-grade version V4.0 face-swapping recognition model with 107 facial feature detection points is selected as the target model; the false recognition rate is configured to be 0.001%. When the risk level is level six, a military-grade V5.0 face-swapping recognition model with more than 200 facial feature detection points is selected as the target face-swapping recognition model; the false recognition rate is configured to be 0.0001%.
[0073] S260. Based on the risk level, determine the configuration information of the response strategy.
[0074] The response strategy is progressively enhanced according to the risk level, from low to high. It gradually upgrades from simply recording logs to recording medium-risk accounts, secondary authentication for high-risk accounts, preset freezing duration for high-risk accounts, blocking high-risk accounts with manual review, and finally to real-time account freezing and linkage with the anti-fraud system for the highest risk level.
[0075] S270. Generate a target face recognition strategy based on the face-swapping recognition model version, the configuration information of the false recognition rate, and the configuration information of the response strategy.
[0076] Optionally, based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information, including:
[0077] If the candidate face recognition strategy is a device environment governance strategy, then the multi-dimensional control factors include device fingerprint detection, network environment monitoring, and application layer protection.
[0078] The operational status of network environment monitoring and application layer protection is determined based on the risk level. When the risk level is Level 1, the face recognition scenario is a high-frequency scenario with extremely low financial risk. In this case, network environment monitoring and application layer protection are not enabled in the face recognition strategy to avoid reducing the user experience; device fingerprint detection is configured as basic device ID verification. When the risk level is not Level 1, the face recognition strategy includes network environment monitoring and application layer protection, and these are enabled.
[0079] If the network environment monitoring and application layer protection are enabled, then determine the available configurations for network environment monitoring and application layer protection;
[0080] The available configurations for network environment monitoring include: proxy detection, overseas IP recording, overseas IP two-factor authentication, high-risk area IP blocking, and forced dedicated VPN tunnels; the available configurations for application layer protection include: basic virtual camera protection, screen sharing blocking, process injection detection, real-time kernel monitoring, and hardware security key authentication; from level 2 risk to level 6 risk, as the risk level increases, the available configurations for network environment monitoring are selected sequentially as the configuration information for network environment monitoring;
[0081] Based on the risk level, the target configurations for network environment monitoring, application layer protection, and device fingerprint detection are determined, and configuration information is obtained. Among them, device fingerprint detection is progressively enhanced from low to high risk level, from the most basic device ID verification to metadata verification, hardware feature matching, sensor fingerprint deep verification, hardware-level security environment verification, and finally to the highest risk level device blacklist and associated network prevention and control mechanism.
[0082] Based on the configuration information of the device fingerprint detection, network environment monitoring, and application layer protection, a target face recognition strategy is generated.
[0083] Optionally, based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information, including:
[0084] If the candidate face recognition strategy is a biometric detection strategy, then the multidimensional regulatory factors include action biopsy, light biopsy, and silent liveness detection.
[0085] The working status of action liveness detection and light liveness detection is determined based on the risk level. When the risk level is Level 1, the face recognition scenario is a high-frequency scenario with extremely low financial risk. In this case, action liveness detection and light liveness detection are not enabled in the face recognition strategy to avoid reducing the user experience. Silent liveness detection is configured as basic micro-expression detection including 20 feature points. When the risk level is not Level 1, the face recognition strategy includes action liveness detection and light liveness detection, and both are enabled.
[0086] If the action biopsy and optical biopsy are enabled, determine the available configurations for action biopsy and optical biopsy;
[0087] The available configurations for action biopsy include: simple actions such as blinking and nodding; medium-difficulty actions such as turning the head 30° while nodding; complex actions such as reading numbers aloud and turning the head left and right; and compound actions such as reading numbers aloud and turning the head in three dimensions. The transaction is blocked, and the process is transferred to a human operator. The available configurations for optical biopsy include: visible light analysis; visible light plus 850nm infrared analysis; three-band infrared analysis; multispectral imaging; and multispectral imaging plus laser scanning. From level 2 risk to level 6 risk, as the risk level increases, the corresponding available configurations for action biopsy and optical biopsy are selected sequentially as the configuration information for action biopsy and optical biopsy.
[0088] Based on the risk level, the target configurations for action biopsy, light biopsy, and silent liveness detection are determined, and configuration information is obtained. Among them, silent liveness detection is progressively enhanced from low to high risk level, gradually upgrading from basic micro-expression detection including 20 feature points to pupil contraction detection (0.5Hz threshold), 52 feature point tracking, 72 feature points + micro-tremor detection, 107 feature points + blood flow analysis, and finally to 3D depth modeling at the highest risk level.
[0089] Based on the configuration information of the action liveness detection, light liveness detection, and silent liveness detection, a target face recognition strategy is generated.
[0090] Optionally, based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information, including:
[0091] If the candidate face recognition strategy is a dynamic governance strategy, then the multi-dimensional control factors include circuit breaker strategy, storage strategy and collaborative defense strategy;
[0092] The operating status of the circuit breaker strategy, storage strategy, and collaborative defense strategy is determined based on the risk level. When the risk level is Level 1, the facial recognition scenario is a high-frequency scenario with extremely low financial risk. In this case, the circuit breaker strategy, storage strategy, and collaborative defense strategy are not enabled in the facial recognition strategy to avoid reducing the user experience. When the risk level is not Level 1, the facial recognition strategy includes the circuit breaker strategy, storage strategy, and collaborative defense strategy, and these strategies are enabled.
[0093] If the circuit breaker policy, storage policy, and collaborative defense policy are enabled, then determine the available configurations of the circuit breaker policy, storage policy, and collaborative defense policy.
[0094] The circuit breaker strategy is progressively strengthened according to risk level, from 5 device errors, 3 device errors or 5 user errors, 2 device errors or 3 user errors, 1 device error, to the highest risk level of permanent blacklisting upon the first error; the storage strategy is progressively strengthened according to risk level, from 30 days of feature vector storage, 6 months of original image storage, 2 years of original image storage, 3 years of original image storage + permanent feature storage, to the highest risk level of permanent storage of all data + blockchain evidence; the collaborative defense strategy is progressively strengthened according to risk level, from basic scanning of the same device, 1st degree association account monitoring, 2nd degree association real-time scanning, 3rd degree association deep scanning, to the highest risk level of full network blacklist synchronization;
[0095] Based on the risk level, the target configurations of the circuit breaker strategy, storage strategy, and collaborative defense strategy are determined to obtain configuration information; based on the configuration information of the circuit breaker strategy, storage strategy, and collaborative defense strategy, a target face recognition strategy is generated.
[0096] This invention utilizes an adaptive scene parameter configuration engine to dynamically configure facial recognition strategies across four levels: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy. This comprehensively addresses the shortcomings of traditional fixed AI recognition technologies, such as long response times and difficulty in balancing security and user experience. Furthermore, it integrates face-swapping strategies to address emerging attacks such as AI face-swapping and deepfakes encountered by banks in facial recognition processes due to the development of multimodal large-scale model technology. AI face-swapping attacks can mimic biometric features like blinking and head turning, causing traditional liveness detection to fail, thus improving the effectiveness of facial recognition and enhancing system security. The 7-dimensional risk assessment model improves risk identification accuracy by 41% compared to traditional solutions. Parameter optimization response speed is increased by 5 times after the emergence of new attack methods. A built-in parameter verification rule library based on the "Personal Information Security Specification" automatically mitigates compliance risks.
[0097] Figure 3 This is a structural schematic diagram of a face recognition device provided in an embodiment of the present invention. Figure 3 As shown, the device includes:
[0098] The risk level determination module 310 is used to determine the risk level of a face recognition scenario based on the attributes and attribute values of the face recognition scenario; the attributes of the face recognition scenario include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk.
[0099] The strategy determination module 320 is used to determine the configuration information of the multi-dimensional control factors in the candidate face recognition strategy according to the risk level, and generate the target face recognition strategy according to the configuration information; the face recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
[0100] The face recognition device provided in the embodiments of the present invention can execute the face recognition method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0101] Optionally, the strategy determination module includes a regulation factor determination unit, used to determine the working status of any regulation factor according to the risk level; if the regulation factor is in an enabled state, determine the available configuration of the regulation factor; select a target configuration from the available configurations according to the risk level, and determine the configuration parameters of the target configuration to obtain the configuration information of the regulation factor.
[0102] Optionally, the strategy determination module includes a face-swapping strategy determination unit, configured to: if the candidate face recognition strategy is a face-swapping model configuration strategy, then the multi-dimensional control factors include the face-swapping model version, risk threshold, and response strategy; determine the working state of the face-swapping model based on the risk level; if the face-swapping model is in an enabled state, determine the available version of the face-swapping model and the available configuration of the risk threshold; wherein the available configuration of the risk threshold includes the false recognition rate; and select a target face-swapping model from at least two available versions of face-swapping models based on the risk level, and determine the configuration of the false recognition rate. The parameters are used to obtain the configuration information of the face-swapping recognition model version and false recognition rate; among which, different versions of the face-swapping recognition model contain different numbers of facial feature detection points; according to the risk level, the configuration information of the response strategy is determined; among which, the response strategy is progressively enhanced from low to high risk level, from only logging to medium-risk logging, high-risk secondary authentication, high-risk freezing for a preset duration, high-risk blocking plus manual review, until the highest risk level of real-time account freezing and linkage with the anti-fraud system; based on the configuration information of the face-swapping recognition model version, false recognition rate and response strategy, the target face recognition strategy is generated.
[0103] Optionally, the strategy determination module includes a device environment governance strategy determination unit, used to determine the working status of network environment monitoring and application layer protection based on the risk level if the candidate face recognition strategy is a device environment governance strategy; if the candidate face recognition strategy is a device environment governance strategy, the multi-dimensional control factors include device fingerprint detection, network environment monitoring, and application layer protection; if the network environment monitoring and application layer protection are enabled, determine the available configuration of network environment monitoring and application layer protection; and determine the target configuration of network environment monitoring, application layer protection, and device fingerprint detection based on the risk level to obtain configuration information. Specifically, device fingerprint detection is progressively enhanced from low to high risk level, upgrading from basic device ID verification to metadata verification, hardware feature matching, sensor fingerprint deep verification, hardware-level security environment verification, and finally to the highest risk level device blacklist and associated network control mechanisms. Based on the configuration information of device fingerprint detection, network environment monitoring, and application layer protection, a target face recognition strategy is generated.
[0104] Optionally, the strategy determination module includes a dynamic governance strategy determination unit, used to: if the candidate face recognition strategy is a dynamic governance strategy, then the multi-dimensional control factors include a circuit breaker strategy, a storage strategy, and a collaborative defense strategy; determine the working state of the circuit breaker strategy, the storage strategy, and the collaborative defense strategy according to the risk level; if the circuit breaker strategy, the storage strategy, and the collaborative defense strategy are enabled, determine the available configurations of the circuit breaker strategy, the storage strategy, and the collaborative defense strategy; determine the target configurations of the circuit breaker strategy, the storage strategy, and the collaborative defense strategy according to the risk level, and obtain configuration information; and generate a target face recognition strategy based on the configuration information of the circuit breaker strategy, the storage strategy, and the collaborative defense strategy.
[0105] Optionally, the risk level determination module includes a risk level determination unit, which is used to construct a judgment matrix based on the relative importance between attributes, determine the weight of each attribute in the face recognition scenario based on the judgment matrix, determine the risk value of the face recognition scenario based on the weight and attribute value of each attribute, and determine the risk level of the face recognition scenario based on the risk value and a preset classification rule.
[0106] Optionally, it also includes a regulatory factor optimization module, which is used to optimize the configuration information of multidimensional regulatory factors in the candidate face recognition strategy based on reinforcement learning; perform face recognition according to the optimized configuration information of multidimensional regulatory factors, determine the reward according to the recognition success rate, recognition error rate, recognition time and expected recognition time, and if the reward is greater than the reward before the configuration information is optimized, then update the configuration information of multidimensional regulatory factors.
[0107] The face recognition device described in further detail can also execute the face recognition method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0108] According to embodiments of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.
[0109] Figure 4 A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0110] like Figure 4As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded into the RAM 43 from storage unit 48. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0111] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0112] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as face recognition methods.
[0113] In some embodiments, the face recognition method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the face recognition method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the face recognition method by any other suitable means (e.g., by means of firmware).
[0114] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0115] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0116] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0117] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0118] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0119] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0120] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0121] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A face recognition method, characterized in that, The method includes: The risk level of a face recognition scenario is determined based on its attributes and attribute values. The attributes of the face recognition scenario include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk. Based on the risk level, the configuration information of the multidimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information; the face recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
2. The method according to claim 1, characterized in that, Based on the aforementioned risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, including: For any given control factor, determine the operating status of the control factor based on the risk level; If the regulatory factor is enabled, then determine the available configuration of the regulatory factor; Based on the risk level, a target configuration is selected from the available configurations, and the configuration parameters of the target configuration are determined to obtain the configuration information of the control factor.
3. The method according to claim 2, characterized in that, Based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information, including: If the candidate face recognition strategy is a face-swapping recognition model configuration strategy, then the multi-dimensional control factors include the face-swapping recognition model version, risk threshold, and response strategy; The working status of the face-swapping recognition model is determined based on the aforementioned risk level. If the face-swapping recognition model is enabled, then the available version of the face-swapping recognition model and the available configuration of the risk threshold are determined; wherein, the available configuration of the risk threshold includes the false recognition rate; Based on the risk level, a target face-swapping recognition model is selected from at least two available versions of the face-swapping recognition model, and the configuration parameters for the false recognition rate are determined to obtain the configuration information of the face-swapping recognition model version and the false recognition rate; wherein, different versions of the face-swapping recognition model contain different numbers of facial feature detection points; Based on the risk level, the configuration information of the response strategy is determined; wherein, the response strategy is progressively enhanced from low to high risk level, from simply recording logs to medium-risk recording, high-risk secondary authentication, high-risk freezing for a preset duration, high-risk blocking plus manual review, until the highest risk level of real-time account freezing and linkage with the anti-fraud system; Based on the configuration information of the face-swapping recognition model version, the false recognition rate, and the response strategy, a target face recognition strategy is generated.
4. The method according to claim 2, characterized in that, Based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information, including: If the candidate face recognition strategy is a device environment governance strategy, then the multi-dimensional control factors include device fingerprint detection, network environment monitoring, and application layer protection. The operational status of network environment monitoring and application layer protection is determined based on the aforementioned risk level. If the network environment monitoring and application layer protection are enabled, then determine the available configurations for network environment monitoring and application layer protection; Based on the risk level, the target configurations for network environment monitoring, application layer protection, and device fingerprint detection are determined, and configuration information is obtained. Among them, device fingerprint detection is progressively enhanced from low to high risk level, from the most basic device ID verification to metadata verification, hardware feature matching, sensor fingerprint deep verification, hardware-level security environment verification, and finally to the highest risk level device blacklist and associated network prevention and control mechanism. Based on the configuration information of the device fingerprint detection, network environment monitoring, and application layer protection, a target face recognition strategy is generated.
5. The method according to claim 2, characterized in that, Based on the risk level, the configuration information of the multi-dimensional control factors in the candidate face recognition strategy is determined, and the target face recognition strategy is generated based on the configuration information, including: If the candidate face recognition strategy is a dynamic governance strategy, then the multi-dimensional control factors include circuit breaker strategy, storage strategy and collaborative defense strategy; The operational status of the circuit breaker strategy, storage strategy, and collaborative defense strategy is determined based on the risk level. If the circuit breaker strategy, storage strategy, and collaborative defense strategy are enabled, then determine the available configurations of the circuit breaker strategy, storage strategy, and collaborative defense strategy. Based on the risk level, the target configurations of the circuit breaker strategy, storage strategy, and collaborative defense strategy are determined to obtain configuration information; based on the configuration information of the circuit breaker strategy, storage strategy, and collaborative defense strategy, a target face recognition strategy is generated.
6. The method according to claim 1, characterized in that, The step of determining the risk level of a face recognition scenario based on its attributes and attribute values includes: A judgment matrix is constructed based on the relative importance of the attributes, and the weights of each attribute in the face recognition scenario are determined based on the judgment matrix. The risk value of the face recognition scenario is determined based on the weight and value of each attribute. Based on the risk value and preset classification rules, the risk level of the face recognition scenario is determined.
7. The method according to claim 1, characterized in that, Also includes: The configuration information of multi-dimensional control factors in the candidate face recognition strategy is optimized based on reinforcement learning; Face recognition is performed based on the optimized configuration information of the multidimensional control factors. The reward is determined based on the recognition success rate, recognition error rate, recognition time, and expected recognition time. If the reward is greater than the reward before the configuration information was optimized, the configuration information of the multidimensional control factors is updated.
8. A face recognition device, characterized in that, The device includes: The risk level determination module is used to determine the risk level of a face recognition scenario based on its attributes and attribute values. The attributes of the face recognition scenario include: financial risk, identity sensitivity, operating environment risk, time sensitivity, user behavior baseline, related business risk, and geographical location risk. The strategy determination module is used to determine the configuration information of the multidimensional control factors in the candidate face recognition strategy according to the risk level, and generate the target face recognition strategy according to the configuration information; the face recognition strategy includes at least one of the following: biometric detection strategy, device environment management strategy, face-swapping recognition model configuration strategy, and dynamic management strategy.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the face recognition method according to any one of claims 1-7.
10. A computer program product comprising a computer program that, when executed by a processor, implements the face recognition method according to any one of claims 1-7.