Generative Adversarial Network for Face Recognition Attack Samples
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing human face recognition technologies face challenges in obtaining sufficient attack samples, which affects the training effectiveness of classification models and subsequent living body detection results, particularly in securing the authenticity and safety of user information, especially in remote account openings and social insurance verification.
Innovation Solution
A method and apparatus utilizing a generative network, specifically a generative adversarial network, to generate attack samples by transforming real person's pictures into attack pictures while maintaining the human face ID, thereby overcoming the scarcity of attack samples. This involves training a generative network to produce attack pictures that are indistinguishable from real person's pictures, using noise and supervision to ensure the generated attack pictures are realistic and effective.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods are used to obtain attack samples, then the classification model can be trained, but the attack samples are insufficient leading to poor training效果和detection accuracy
Solution Approach 1:
The patent uses a generative network to copy and transform real person pictures into attack samples. The generative network learns the distribution of real pictures and generates synthetic attack pictures that mimic real attack patterns, thereby creating sufficient training data without needing to physically collect numerous real attack samples.
Solution Approach 2:
The system uses its own real person pictures as input to the generative network, which then produces corresponding attack samples. This self-service approach allows the system to generate attack samples from its existing data resources, eliminating the need for external attack sample collections.
2Quantity of substance
If more attack samples are collected from real sources, then training data sufficiency improves, but the complexity and difficulty of obtaining diverse attack samples increases
Solution Approach 1:
Instead of physically collecting diverse attack samples from multiple sources (photos, videos, printed materials, curved surfaces), the patent uses the generative network to copy and transform real pictures into various attack sample forms. This digital copying approach eliminates the complexity of physical sample collection while generating sufficient diverse training data.
Solution Approach 2:
The generative network acts as an intermediary between real person pictures and attack samples. Rather than directly collecting attack samples from various sources, the system uses the generative network as a mediator to transform real pictures into attack samples, simplifying the entire sample acquisition process.
3Productivity
If attack samples are generated without proper supervision, then generation speed increases, but the quality and realism of generated attack pictures deteriorates
Solution Approach 1:
The patent employs a discriminative network that provides feedback to the generative network. The discriminative network evaluates the generated attack pictures and provides feedback signals that guide the generative network to improve the realism and quality of generated samples, ensuring high detection training effectiveness.
Solution Approach 2:
The system performs preliminary training of both the generative and discriminative networks before actual attack sample generation. This preliminary action ensures that the generative network is properly trained to produce high-quality attack samples that maintain the necessary realism for effective detection model training.
Data Source
AI summary
The present disclosure provides an attack sample generating method and apparatus, a device and a storage medium, wherein the method comprises: training a generative network which is used to generate an attack picture with a real person's picture; upon completion of training, using the generative network to generate an attack picture, and regarding the generated attack picture as the attack sample. The solution of the present disclosure can be applied to overcome the problem of insufficiency of the attack samples.


