Generative Adversarial Network for Face Recognition Attack Samples

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing human face recognition technologies face challenges in obtaining sufficient attack samples, which affects the training effectiveness of classification models and subsequent living body detection results, particularly in securing the authenticity and safety of user information, especially in remote account openings and social insurance verification.

Innovation Solution

A method and apparatus utilizing a generative network, specifically a generative adversarial network, to generate attack samples by transforming real person's pictures into attack pictures while maintaining the human face ID, thereby overcoming the scarcity of attack samples. This involves training a generative network to produce attack pictures that are indistinguishable from real person's pictures, using noise and supervision to ensure the generated attack pictures are realistic and effective.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods are used to obtain attack samples, then the classification model can be trained, but the attack samples are insufficient leading to poor training效果和detection accuracy

Engineering Contradiction:
Improveliving body detection accuracyVSAvoidattack sample quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses a generative network to copy and transform real person pictures into attack samples. The generative network learns the distribution of real pictures and generates synthetic attack pictures that mimic real attack patterns, thereby creating sufficient training data without needing to physically collect numerous real attack samples.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system uses its own real person pictures as input to the generative network, which then produces corresponding attack samples. This self-service approach allows the system to generate attack samples from its existing data resources, eliminating the need for external attack sample collections.

Inventive Principle:
Principle #25Self-service

2Quantity of substance

If more attack samples are collected from real sources, then training data sufficiency improves, but the complexity and difficulty of obtaining diverse attack samples increases

Engineering Contradiction:
Improveattack sample quantityVSAvoidsample collection complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

Instead of physically collecting diverse attack samples from multiple sources (photos, videos, printed materials, curved surfaces), the patent uses the generative network to copy and transform real pictures into various attack sample forms. This digital copying approach eliminates the complexity of physical sample collection while generating sufficient diverse training data.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The generative network acts as an intermediary between real person pictures and attack samples. Rather than directly collecting attack samples from various sources, the system uses the generative network as a mediator to transform real pictures into attack samples, simplifying the entire sample acquisition process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If attack samples are generated without proper supervision, then generation speed increases, but the quality and realism of generated attack pictures deteriorates

Engineering Contradiction:
Improveattack sample generation speedVSAvoidattack picture quality
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The patent employs a discriminative network that provides feedback to the generative network. The discriminative network evaluates the generated attack pictures and provides feedback signals that guide the generative network to improve the realism and quality of generated samples, ensuring high detection training effectiveness.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary training of both the generative and discriminative networks before actual attack sample generation. This preliminary action ensures that the generative network is properly trained to produce high-quality attack samples that maintain the necessary realism for effective detection model training.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10817707B2Attack sample generating method and apparatus, device and storage medium
Publication Date: 2020.10.27 BAIDU ONLINE NETWORK TECH (BEIJIBG) CO LTD
  • US10817707B2 patent drawing
  • US10817707B2 patent drawing
  • US10817707B2 patent drawing

AI summary

The present disclosure provides an attack sample generating method and apparatus, a device and a storage medium, wherein the method comprises: training a generative network which is used to generate an attack picture with a real person's picture; upon completion of training, using the generative network to generate an attack picture, and regarding the generated attack picture as the attack sample. The solution of the present disclosure can be applied to overcome the problem of insufficiency of the attack samples.