Method for processing input data, associated electronic system and computer program

The method uses two neural networks to enhance the security of facial recognition systems by detecting adversarial attacks through similarity score comparison, effectively addressing the vulnerability of neural networks to such attacks.

FR3143801B3Active Publication Date: 2025-05-23IDEMIA PUBLIC SECURITY FRANCE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022013180
Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2022-12-12
Publication Date
2025-05-23
Estimated Expiration
2032-12-12

AI Technical Summary

Technical Problem

Neural networks used in facial recognition systems are vulnerable to adversarial attacks, where imperceptible changes in input data can significantly alter the network's output, leading to false identifications and security breaches.

Method used

A method involving two neural networks is proposed, where a first neural network encodes input data into a model, modified data is created by altering the input data, and a second, smaller neural network, trained by knowledge distillation, encodes the modified data. A similarity score is calculated between the models from both networks, and if it exceeds a predetermined threshold, the input data is considered clean and secure.

Benefits of technology

This approach effectively detects adversarial attacks by comparing the similarity scores of the models generated by the two neural networks, thereby enhancing the security of facial recognition systems without degrading performance on clean images.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for processing an input data item, implemented by an electronic system and comprising the following steps: - Obtaining (E100) a first model encoding the input data item, by applying a first neural network to the input data item, - Obtaining (E200) a modified data item from the input data item, by modifying at least one characteristic of the input data item, - Obtaining (E300) a second model encoding the modified data item, by applying a second neural network to the modified data item, the second neural network being smaller than the first neural network and trained by distilling the knowledge of the first neural network, - Calculating (E400) a similarity score between the first model and the second model, - Verifying (E500) that the first model and the second model coincide, by comparing the similarity score to a predetermined threshold. Figure for the abstract: fig. 2.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for processing input data, associated electronic system and computer program

[0001] The present invention relates to a method for processing input data, as well as to a computer program, a computer-readable storage medium, and an electronic system associated therewith.

[0002] Neural networks are widely used to process data, for example images.

[0003] With a machine learning phase, a neural network “learns” and becomes capable of implementing a targeted task on its own.

[0004] More precisely, the value of the weights and parameters of the neural network is progressively modified until the latter is capable of implementing the targeted task.

[0005] Tasks previously considered impossible are now accomplished by neural networks with excellent reliability.

[0006] A challenge encountered by neural networks is the existence of "adversarial attacks", i.e. changes that are imperceptible or barely perceptible to a human, which significantly change the output of a neural network, when they are applied to an input of said neural network.

[0007] For example, we see in the document A Simple Explanation for the Existence of Adversarial Examples with Small Hamming Distance by Adi Shamir, Itay Safran, Eyal Ronen, and Orr Dunkelman, https: / / arxiv.org / pdf / 190L10861vLpdf how an antagonistic perturbation applied to an image of a cat can lead to it being wrongly classified as an image of guacamole.

[0008] A common adversarial attack consists of adding at least one signal, typically among the high frequencies, in the input data.

[0009] In the context of facial recognition, this has serious implications, for example for border control.

[0010] It is possible to imagine that an attacker prohibited from traveling creates an identity document from an image of an accomplice, said image being modified using antagonistic disturbances such that a facial recognition algorithm, implemented in the form of a neural network, falsely associates this modified image of the accomplice with the attacker, and thus allows the attacker to travel.

[0011] The neural network of a facial recognition algorithm encodes an image of a face into a standardized model (a vector) of a fixed size in a given vector space.

[0012] In principle, images belonging to different identities form distinct groups of models in the vector space.

[0013] In the case of adversarial attacks, the manipulated image is found far from the region of the characteristic space associated with the true identity and close to that of the targeted identity.

[0014] One way to guard against such attacks is to strengthen the neural network against these attacks by modifying the neural network itself, for example by including "adversarial perturbations" on the input data of the neural network during the training phase of said neural network.

[0015] However, the disadvantage of such a solution is that the performance of the neural network is degraded for clean images, i.e. images that are not modified by adversarial attack.

[0016] Another way to protect against such attacks is to detect adversarial attacks so as not to take into account an attacked input data and / or the output of a neural network applied to said attacked input data.

[0017] One way to detect such attacks is proposed by Xu et al. Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks, Network and Distributed System Security Symposium, 2018.

[0018] However, a disadvantage of this method is that it requires implementing a neural network twice.

[0019] The neural network, particularly for biometric recognition, is generally the most resource-intensive component.

[0020] Furthermore, particularly in the context of biometric recognition systems, for example in the context of facial recognition systems, computing resources are often limited and implementing the neural network twice constitutes a prohibitive bottleneck.

[0021] The present invention aims to minimize the aforementioned drawbacks and proposes a method for processing input data, said method being implemented by an electronic system and comprising the following steps: - Obtaining a first model encoding the input data, by applying a first neural network to the input data, - Obtaining modified data from the input data, by modifying at least one characteristic of the input data, - Obtaining a second model encoding the modified data, by applying a second neural network to the modified data, - Calculating a similarity score between the first model and the second model, - Verifying that the first model and the second model coincide, by comparing the similarity score to a predetermined threshold, the method being characterized in that the second neural network is a smaller neural network than the first neural network and trained by distilling the knowledge of the first neural network.

[0022] The method for processing an input data item may also include the following optional features, taken alone or in combination whenever technically possible.

[0023] The similarity score is calculated by applying a scalar product to the first model and the second model.

[0024] The modification of at least one characteristic of the input data is by applying to the input data a bilateral filter and / or a median filter and / or a reduction of the color depth.

[0025] The input data is an image of a biometric trait, the first neural network encodes its input into a pattern of a fixed size in a vector space, and the second neural network encodes its input into another pattern of the fixed size in this vector space.

[0026] The biometric feature is a face.

[0027] The method for processing an input data further comprises the following steps: - recovery of input data from an identity document, - acquisition of reference data on the biometric trait of an individual, - obtaining a third model encoding the reference data, by applying the first neural network to the reference data, - Calculation of another similarity score between the first model and the third model, - Verification that the first model and the third model coincide, by comparing the other similarity score to another predetermined threshold, - Authorization of the individual to access a secure access area if the first model and the third model coincide and if the first model and the second model coincide.

[0028] The invention also proposes a computer program comprising instructions executable by a processor and adapted for implementing a method for processing input data as defined previously, when these instructions are executed by the processor.

[0029] This program may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code. object, such as in a partially compiled form, or in any other desirable form.

[0030] The invention also relates to a storage medium (or information medium or recording medium) readable by computer and characterized in that it stores a computer program comprising instructions for implementing, by a processor, the method for processing an input data item as defined previously, when said program is executed by said processor.

[0031] The invention also proposes an electronic system comprising means adapted for implementing a method for processing input data as defined previously.

[0032] The invention relates in particular to an electronic system for processing input data comprising: - A module for obtaining a first model configured to obtain a first model encoding the input data, by applying a first neural network to the input data, - A module for obtaining modified data configured to obtain modified data from the input data, by modifying at least one characteristic of the input data, - A module for obtaining a second model configured to obtain a second model encoding the modified data, by applying a second neural network to the modified data, - A verification module configured to calculate a similarity score between the first model and the second model, and compare the similarity score to a predetermined threshold, the system being characterized in that the second neural network is a smaller neural network than the first neural network and trained by distilling the knowledge of the first neural network.

[0033] This electronic data processing system may be a border access control system.

[0034] This electronic system can be configured to implement each of the embodiment possibilities envisaged for the method of processing input data as defined previously.

[0035] According to one embodiment, the invention is implemented by means of software and / or hardware components. In this regard, the term "module" may correspond in this document to a software component, a hardware component or a set of hardware and software components.

[0036] A software component corresponds to one or more computer programs, one or more sub-programs of a program, or more generally to any element of a program or software capable of implementing a function or set of functions, as described for the module concerned.

[0037] Similarly, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or a set of functions, as described below for the module concerned. It may be a programmable hardware component or a processor for executing software.

[0038] Of course, the various features, variants and embodiments of the invention may be combined with each other in various combinations to the extent that they are not incompatible or mutually exclusive.

[0039] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended figures which illustrate exemplary embodiments thereof which are not limiting in nature.

[0040] In the figures:

[0041] [Fig-1] is a diagram of an electronic system for implementing the method according to the invention;

[0042] [Fig.2] schematically represents the steps of a first embodiment of the method according to the invention.

[0043] [Fig.3] schematically represents the steps of a second embodiment of the method according to the invention.

[0044] Unless otherwise indicated, elements common or similar to several figures bear the same reference signs and have identical or similar characteristics, so that these common elements are generally not described again for the sake of simplicity.

[0045] In the context of the present description, the qualifiers “first”, “second”, “third” are only indicative to distinguish elements that they qualify, but do not imply an order between them.

[0046] The invention proposes a method for processing input data implemented by an electronic system 1 as represented by [Fig.l].

[0047] The electronic data processing system 1 is, for example, a border access control system.

[0048] It will be noted that certain elements have been omitted because they are not necessary for the understanding of the present invention.

[0049] The electronic system comprises one or more electronic devices 1a, 1b, 1c, typically one or more servers.

[0050] Three electronic devices are shown in [Fig.l], a first electronic device 1a, a second electronic device 1b and a third electronic device 1c.

[0051] The electronic devices 1a, 1b, 1c may be remote and connected to a wide area network 10 such as the Internet network for the exchange of data.

[0052] Each electronic device comprises a data processing means 11a, 11b, 11c of the processor type, a data storage means 12a, 12b, 12c and a RAM 13a, 13b, 13c.

[0053] The data storage means and the RAM of an electronic device are each linked to the data processing means of said electronic device, so that the data processing means can read or write data in the data storage means and / or the RAM.

[0054] The data storage means 12a, 12b, 12c store computer program instructions, some of which are designed to implement a method of processing an input data item as described with reference to FIGS. 2 and 3 when these instructions are executed by the data processing means 11a, 11b, 11c.

[0055] Each data storage means 12a, 12b, 12c is for example in practice a hard disk or a non-volatile memory, possibly rewritable, for example of the EEPROM type (for "Electrically Erasable and Programmable Read-Only Memory" according to the commonly used English term).

[0056] Furthermore, each of the data storage means and each of the RAMs 13a, 13b, 13c can store at least some of the elements (in particular the input data, the modified data, the first model and / or the second model as described below with reference to FIGS. 2 and 3) manipulated during the various processing operations carried out during one of the methods described below.

[0057] In the remainder of the description, memory is any one of the data storage means and the random access memories.

[0058] The electronic system 1 also comprises several modules not shown.

[0059] Typically, the electronic system 1 comprises a module for obtaining a first model, a module for obtaining modified data, a module for obtaining a second model and a verification module.

[0060] The electronic system 1 may also comprise a module for recovering input data, a module for acquiring reference data, a module for obtaining a third model, a module for calculating another similarity score, another verification module and an authorization module.

[0061] These modules can in practice be implemented by a combination of hardware elements and software elements.

[0062] Each module is configured to carry out the steps described in the methods according to the invention and set out below, and therefore has a functionality described in the methods according to the invention and set out below.

[0063] Thus, for each module, the electronic system 1 stores, for example, software instructions executable by at least one processor 11a, 11b, 11c in order to use a hardware element (for example a memory) and thus implement the functionality offered by the module.

[0064] According to one possible embodiment, the computer program instructions stored in a data storage means 12a, 12b, 12c have for example been received (for example from a remote computer) during an operating phase of the electronic system 1 prior to the methods described with reference to FIGS. 2 and 3.

[0065] The second electronic device 1b and the third electronic device are optional.

[0066] According to one embodiment, the electronic system 1 comprises a single electronic device, the first electronic device. The first electronic device comprises all the modules of the electronic system 1. Typically, the first electronic device 1a comprises a module for obtaining a first model, a module for obtaining modified data, a module for obtaining a second model and a verification module.

[0067] According to a second embodiment, the electronic system 1 comprises two electronic devices, for example the first electronic device and the second electronic device. The modules of the electronic system 1 are then distributed between the two electronic devices. For example, the first electronic device comprises a module for obtaining a first model and the second electronic device comprises a module for obtaining modified data, a module for obtaining a second model and a verification module.

[0068] According to a third embodiment, the electronic system 1 comprises three electronic devices, typically the first electronic device, the second electronic device and the third electronic device. The modules of the electronic system 1 are then distributed between the three electronic devices. For example, the first electronic device comprises a module for obtaining a first model, the second electronic device comprises a module for obtaining modified data and a module for obtaining a second model, and the third electronic device comprises a verification module.

[0069] Other implementation modes are possible.

[0070] The electronic system 1 may comprise more than three electronic devices, the modules of the electronic system 1 being distributed over all said electronic devices.

[0071] A module may be distributed across a plurality of electronic devices, each electronic device of the plurality implementing a portion of said module and cooperating with the other electronic devices of the plurality so that the electronic system 1 thus implements the functionality offered by the module.

[0072] Furthermore, the electronic system 1 may comprise a reader, not shown in [Fig.l], for reading the content, for example the photo of a face, of an electronic chip, typically remotely by radiofrequency communication with the electronic chip.

[0073] The electronic chip is for example incorporated into an individual's identity document.

[0074] The electronic system 1 may also comprise a first image sensor, not shown in [Fig.l], for acquiring, i.e. recovering, the input data from the physical medium of an identity document of an individual.

[0075] An identity document of an individual is for example a passport, an identity card, a driving license, an access badge, a health card or a bank card.

[0076] The first image sensor is for example a digital camera or a digital camera.

[0077] The input data is for example the photo of a face printed on the page of a passport.

[0078] The electronic system 1 may also comprise a second image sensor and an image processing module adapted to acquire reference data on a biometric trait of an individual, typically an image of the biometric trait of the individual, for example an image of the face of the individual.

[0079] [Fig.2] schematically represents the steps of a first embodiment of the method according to the invention.

[0080] This method is implemented by the electronic system 1 and detects adversarial attacks. It makes it possible not to take into account an attacked input data and / or the output of a neural network applied to said attacked input data.

[0081] According to a step of obtaining a first model (step E100), the electronic system 1 obtains a first model encoding the input data, by applying a first neural network to the input data. The first model is the output of the first neural network when the input of said first neural network is the input data.

[0082] This step of obtaining a first model is typically implemented by the module for obtaining a first model of the electronic system 1.

[0083] The method then comprises a step of obtaining modified data (step E200), during which the electronic system 1 obtains modified data from the input data, by modification, for example by compression, of at least one characteristic of the input data.

[0084] Typically, the modification of at least one characteristic of the input data is by applying to the input data a bilateral filter and / or a median filter and / or a reduction of the color depth.

[0085] A bilateral filter is a nonlinear, edge-preserving, noise-reducing smoothing filter for images. It replaces the intensity of each pixel with a weighted average of the intensity values ​​of neighboring pixels. This weight can be based on a Gaussian distribution.

[0086] A median filter replaces a value of the input data with the median value of its neighborhood.

[0087] Color depth, usually measured in bits per pixel (bpp), is the number of bits used to represent the color of a pixel in an image.

[0088] The feature modification methods remove or decrease the high frequency signal in the input data and thus decrease the power of the adversary attack.

[0089] This step of obtaining modified data is typically implemented by the module for obtaining modified data of the electronic system 1.

[0090] The method then comprises a step of obtaining a second model (step E300), during which the electronic system 1 obtains a second model encoding the modified data, by applying a second neural network to the modified data. The second neural network is a smaller, and consequently faster, neural network than the first neural network, and trained by distilling the knowledge of the first neural network.

[0091] This is possible because knowledge distillation allows a student network (here the second neural network) to react similarly to a teacher network (here the first neural network) for a given adversarial attack. Thus, if an adversarial attack is effective on the first neural network, said adversarial attack is effective on the second neural network, see the document Micah Goldblum, Liam Fowl, Soheil Feizi, Tom Goldstein: Adversarially Robust Distillation, AAAI Conference on Artificial Intelligence, 2020.

[0092] The second model is the output of the second neural network when the input of said second neural network is the modified data.

[0093] This step of obtaining a second model is typically implemented by the module for obtaining a second model of the electronic system 1.

[0094] The method then comprises a step of calculating a similarity score (step E400), during which the electronic system 1 calculates a similarity score between the first model and the second model.

[0095] According to a first example, the similarity score may be a distance between the first model and the second model. Thus the calculation of a similarity score may be the calculation of a polynomial between the components of the first model and the second model.

[0096] Typically, the similarity score may be calculated by applying a dot product to the first model and the second model, the similarity score being the result of said application of the dot product to the first model and the second model.

[0097] In the case where the input data is an iris image, the similarity score used to compare the first model and the second model may be the Hamming distance.

[0098] In the case where the input data is an image of an individual's face, the similarity score can be the Euclidean distance.

[0099] The similarity score can also be any score calculated from a distance between the first model and the second model, for example a discrete “level” of distance to limit the amount of information, or a normalized, or even slightly noisy, version of the distance.

[0100] According to a first possibility, the similarity score is all the greater as the first model and the second model are similar.

[0101] According to a second possibility, the similarity score is all the smaller as the first model and the second model are similar.

[0102] In the remainder of this description, the similarity score is greater the more similar the first model and the second model are.

[0103] A person skilled in the art will understand that the method described below can be adapted for a similarity score which is all the smaller as the first model and the second model are similar.

[0104] The method then comprises a verification step (step E500), during which the electronic system 1 verifies that the first model and the second model coincide by comparing the similarity score to a predetermined threshold.

[0105] If the input data is clean (no antagonistic perturbation added), the similarity score between the first model and the second model will be higher than if the input data was attacked.

[0106] Whether or not the input image has been fraudulently manipulated, applying at least one feature modification method will reduce the similarity between the first model and the second model.

[0107] However, in the case where the input data has been attacked, the change of the input data into the modified data by modification of at least one characteristic of the input data, will be greater than if the input image has not been attacked.

[0108] The predetermined threshold thus makes it possible to separate the attacked input data and the clean input data, i.e. the input data which has not been attacked.

[0109] If the similarity score calculated between the first model and the second model is lower than the predetermined threshold, the first model and the second model do not coincide and an adversarial attack is detected, in which case an error can be raised in an error step (step E600). The input data is considered to have been the subject of an adversarial attack. This error step may consist of not transmitting the first model and / or the input data, typically to an electronic device external to the electronic system 1. This error step may also consist of not providing the first model and / or the input data to another module of the electronic system 1. This error step may finally comprise sending the second model and / or the modified data and / or a simple error code, typically to an electronic device external to the electronic system 1 or to another module of the electronic system 1.

[0110] If the similarity score calculated between the first model and the second model is greater than the predetermined threshold, the first model and the second model coincide and the method continues with a finalization step (step E700).

[0111] The input data is considered clean, that is to say as not having been the subject of an adversarial attack.

[0112] During the finalization step (step E700), the electronic system 1 can transmit the first model and / or the input data, typically to an electronic device external to the electronic system 1.

[0113] Alternatively, during the finalization step (step E700), the first model, and / or the input data, can be provided to another module of the electronic system 1.

[0114] As mentioned above, the method can be adapted for a similarity score which is all the smaller as the first model and the second model are similar. In this case, during the verification step (step E500), if the similarity score calculated between the first model and the second model is greater than the predetermined threshold, the first model and the second model do not coincide and an adversarial attack is detected, in which case an error can be raised in the error step (step E600), if the similarity score calculated between the first model and the second model is less than the predetermined threshold, the first model and the second model coincide and the method continues with the finalization step (step E700).

[0115] The step of calculating a similarity score, the verification step, the error step and / or the finalization step are typically implemented by the verification module of the electronic system 1.

[0116] The input data may be an image of a biometric feature, typically a face, and the first neural network encodes its input, typically the input data, into a template (a vector) of a fixed size in a vector space. The second neural network also encodes its input, typically the modified data, into a template (a vector) of the fixed size in this vector space.

[0117] A person skilled in the art will understand that the steps of this method can be executed in other orders, to the extent that each step has the elements (typically the input data, the modified data, the first model, the second model, the similarity score) necessary for its execution.

[0118] According to a first example, the step of obtaining modified data (step E200) can be executed before the step of obtaining a first model (step E100).

[0119] According to a second example, the step of obtaining a second model (step E300) can be executed before the step of obtaining a first model (step E100) and after the step of obtaining modified data (step E200).

[0120] [Fig.3] schematically represents the steps of a second embodiment of the method according to the invention.

[0121] As for the first embodiment, this method is implemented by the electronic system 1 and detects adversary attacks.

[0122] In this embodiment, the input data is an image of a biometric trait.

[0123] According to a step of recovering an input data item (step E010), the electronic system 1 recovers the input data item from an identity document of an individual.

[0124] According to a first example, the electronic system 1 retrieves the input data from an electronic chip, typically an RFID type radiofrequency chip, contained in the identity document. In this first example, the electronic system 1 has a reader, not shown in [Fig.l], to read the content of the electronic chip.

[0125] According to a second example, the electronic system 1 retrieves the input data from a physical medium of the identity document on which the input data is represented, typically printed or engraved. In this second example, the electronic system 1 has the first image sensor to acquire, i.e. retrieve, the input data from the physical medium of the identity document.

[0126] This step of recovering an input data item is typically implemented by the module for recovering an input data item of the electronic system 1.

[0127] The method then comprises a step of obtaining a first model (step E100), a step of obtaining modified data (step E200), a step of obtaining a second model (step E300), a step of calculating a similarity score (step E400) and a verification step (step E500), identical to those described for the first implementation mode.

[0128] The method then comprises a step of acquiring reference data (step E800), during which the electronic system 1 acquires reference data on the biometric trait of an individual, typically using the second image sensor and the image processing module.

[0129] This step of acquiring reference data is typically implemented by the reference data acquisition module of the electronic system 1.

[0130] The method then comprises a step of obtaining a third model (step E900), during which the electronic system 1 obtains a third model encoding the reference data, by applying the first neural network to the reference data.

[0131] The third model is the output of the first neural network when the input of said first neural network is the reference data.

[0132] This step of obtaining a third model is typically implemented by the module for obtaining a third model of the electronic system 1.

[0133] The method then comprises a step of calculating another similarity score (step E1000), during which the electronic system 1 calculates another similarity score between the first model and the third model.

[0134] According to a first example, the other similarity score may be a distance between the first model and the third model. Thus the calculation of the other similarity score may be the calculation of a polynomial between the components of the first model and the third model.

[0135] Typically, the other similarity score may be calculated by applying a dot product to the first model and the third model, the other similarity score being the result of said application of the dot product to the first model and the third model.

[0136] In the case where the input data and the reference data are iris images, the other similarity score used to compare the first model and the third model can be the Hamming distance.

[0137] In the case where the input data and the reference data are face images, the other similarity score can be the Euclidean distance.

[0138] The other similarity score can also be any score calculated from a distance between the first model and the third model, for example a discrete "level" of distance to limit the amount of information, or a normalized, or even slightly noisy, version of the distance.

[0139] According to a first possibility, the other similarity score is all the greater as the first model and the third model are similar.

[0140] According to a second possibility, the other similarity score is all the smaller as the first model and the third model are similar.

[0141] Preferably, the other similarity score is calculated in a similar manner to the calculation of the similarity score.

[0142] Typically, when the similarity score is calculated by applying a scalar product to the first model and the second model, the other similarity score is calculated by applying a scalar product to the first model and the third model, the other similarity score being the result of said application of the scalar product to the first model and the third model.

[0143] This step of calculating another similarity score is typically implemented by the module for calculating another similarity score of the electronic system 1.

[0144] The method then comprises another verification step (step E1 100) during which the electronic system 1 verifies that the first model and the third model coincide, by comparing the other similarity score to another predetermined threshold.

[0145] When the other similarity score, calculated during the step of calculating another similarity score (step E1000), is all the greater as the first model and the third model are similar, the first model and the third model do not coincide if the other similarity score is lower than the other predetermined threshold, but the first model and the third model coincide if the other similarity score is higher than the other predetermined threshold.

[0146] When the other similarity score, calculated during the step of calculating another similarity score (step E1000), is all the smaller as the first model and the third model are similar, the first model and the third model do not coincide if the other similarity score is greater than the other predetermined threshold, but the first model and the third model coincide if the other similarity score is less than the other predetermined threshold.

[0147] This other verification step is typically implemented by the other verification module of the electronic system 1.

[0148] The method then comprises a step of authorizing the individual to access a secure access zone (step E1200) during which the electronic system 1 authorizes the individual to access a secure zone if the first model and the third model coincide and if the first model and the second model coincide.

[0149] The electronic system 1 therefore uses the result of the verification step (step E500).

[0150] If the first model and the second model coincide, the input data is considered clean, i.e. not having been the subject of an adversarial attack.

[0151] Furthermore, if the first model and the second model coincide, the input data and the reference data are considered to correspond to the same biometric trait of the same individual.

[0152] This step of authorizing the individual to access a secure access zone is typically implemented by the authorization module of the electronic system 1.

[0153] A person skilled in the art will understand that the steps of this method can be executed in other orders, to the extent that each step has the elements (typically the input data, the modified data, the reference data, the first model, the second model, the third model, the similarity score, the other similarity score) necessary for its execution.

[0154] According to a first example, the step of obtaining modified data (step E200) can be executed before the step of obtaining a first model (step E100).

[0155] According to a second example, the step of obtaining a second model (step E300) can be executed before the step of obtaining a first model (step E100) and after the step of obtaining modified data (step E200).

[0156] According to a third example, the step of acquiring a reference data item (step E800) and the step of obtaining a third model (step E900) can be executed before the step of recovering an input data item (step E010) and / or the step of obtaining a first model (step E100) and / or the step of obtaining a modified data item (step E200) and / or the step of obtaining a second model (step E300) and / or the step of calculating a similarity score (step E400) and / or the verification step (step E500).

[0157] According to a fourth example, the step of calculating another similarity score (step E1000) can be executed after the step of obtaining a third model (step E900) and the step of obtaining a first model (step E100), and before the step of obtaining modified data (step E200) and / or the step of obtaining a second model (step E300) and / or the step of calculating a similarity score (step E400) and / or the verification step (step E500).

[0158] According to a fifth example, the other verification step (step E1 100) can be executed after the step of calculating another similarity score (step E1000), and before the step of obtaining modified data (step E200) and / or the step of obtaining a second model (step E300) and / or the step of calculating a similarity score (step E400) and / or the verification step (step E500).

Claims

Claims

1. A method for processing an input data item, the input data item being an image of a biometric trait, said method being implemented by an electronic system (1) and comprising the following steps: - Obtaining (E100) a first model of a fixed size in a vector space encoding the input data item, by applying a first neural network to the input data item, - Obtaining (E200) a modified data item from the input data item, by modifying at least one characteristic of the input data item, - Obtaining (E300) a second model of the fixed size in the vector space encoding the modified data item, by applying a second neural network to the modified data item, - Calculating (E400) a similarity score between the first model and the second model, - Verifying (E500) that the first model and the second model coincide, by comparing the similarity score to a predetermined threshold,the method being characterized in that the second neural network is a smaller neural network than the first neural network and trained by distilling the knowledge of the first neural network.,

2. Method for processing input data according to the preceding claim, characterized in that the similarity score is calculated by applying a scalar product to the first model and to the second model.

3. Method for processing an input data item according to any one of the preceding claims, characterized in that the modification of at least one characteristic of the input data item is by applying to the input data item a bilateral filter and / or a median filter and / or a reduction in the color depth.

4. Method for processing input data according to any one of the preceding claims, characterized in that the biometric feature is a face.

5. Method for processing input data according to any one of the preceding claims, characterized in that it further comprises the following steps: - retrieving (E010) the input data from an identity document, - acquiring (E800) a reference data item on the biometric trait of an individual, - obtaining (E900) a third model encoding the reference data item, by applying the first neural network to the reference data item, - Calculating (El000) another similarity score between the first model and the third model, - Verifying (El 100) that the first model and the third model coincide, by comparing the other similarity score to another predetermined threshold, - Authorizing (E1200) the individual to access a secure access area if the first model and the third model coincide and if the first model and the second model coincide.

6. Computer program characterized in that it comprises instructions executable by a processor and adapted to implement a method according to any one of the preceding claims when these instructions are executed by the processor.

7. A computer-readable storage medium characterized in that it stores a computer program comprising instructions for implementing, by a processor, the method according to any one of claims 1 to 5, when said program is executed by said processor.

8. Electronic system (1) for processing input data, the input data being an image of a biometric trait, the system comprising: - A module for obtaining a first model configured to obtain a first model of a fixed size in a vector space encoding the input data, by applying a first neural network to the input data, - A module for obtaining modified data configured to obtain modified data from the input data, by modifying at least one characteristic of the input data, - A module for obtaining a second model of the fixed size in the vector space configured to obtain a second model encoding the modified data, by applying a second neural network to the modified data, - A verification module configured to calculate a similarity score between the first model and the second model, and compare the similarity score to a predetermined threshold, the system being characterized in that the second neural network is a neural network smaller than the first neural network and trained by distilling the knowledge of the first neural network.

9. Electronic data processing system according to the preceding claim, characterized in that the electronic data processing system is a border access control system.