Biometrics and Presentation-Attack Detection
Earlier work with the Idiap Biometrics group on robust recognition and presentation-attack detection that generalises to unseen attacks.
Partnerships

Earlier-career work in the Idiap Biometrics Security & Privacy Group (2010 to 2018).
Biometric systems are exposed to presentation attacks, and most detectors of the time worked discriminatively, which meant they struggled the moment they met an attack they had not seen in training. Much of my work in this period looked for ways to make that generalisation better.
Major achievements
The work began by giving the field what it lacked: public data, shared protocols, and honest baselines. We released the PRINT-ATTACK database, 200 genuine and 200 attack videos over 50 identities, with a baseline correlating a person’s head movement against the scene background, then organised the first international Competition on Counter-Measures to 2-D Facial Spoofing Attacks, where six teams established that motion, texture and liveness cues separate simple printed-photo attacks cleanly enough to justify designing harder ones. Texture proved powerful on the richer REPLAY-ATTACK data that followed: a local binary pattern baseline and its spatio-temporal extension LBP-TOP cut the half-total error rate from 15.16% to 7.60%, while a counter-measure resting purely on foreground/background optical-flow correlation reached a 1.52% equal-error rate on the printed-photo set — near-perfect on that data, and telling precisely because the motion-based methods published before it failed there.
The harder problems were generalisation and fair evaluation. We argued that an anti-spoofing
module should never be judged alone: it acquires meaning only when fused with the verification
system it protects, as a ternary decision over genuine clients, impostors and attacks, and we
built an open framework to study that joint operation, together with the Expected
Performance and Spoofability Curve to report recognition accuracy and vulnerability to
spoofing on one plot. For robustness to attacks absent from training we exploited the identity
the recogniser already knows: client-specific detectors, generative and discriminative alike,
improved on client-independent ones by up to 50% relative and generalised better to unseen
attack types. The final phase moved to deep learning and beyond the visible spectrum, where
Domain-Specific Units adapted only the low-level layers of a visual-spectra network to
match faces across near-infrared, thermal and sketch domains, surpassing the state of the art
on most benchmarks, and a multi-channel network fusing colour, depth, near-infrared and
thermal detected sophisticated 2D and 3D attacks, silicone masks included, at a 0.3% average
classification error. Much of the lasting value lies in the datasets: PRINT-ATTACK,
REPLAY-ATTACK, MSSpoof, which carried the threat model into the near-infrared, and
WMCA, which brought all four channels together, remain standard benchmarks, shipped with
reproducible protocols and open implementations through the bob framework so that others can
both repeat our results and compete against them on equal terms.
Select publications
- Biometric Face Presentation Attack Detection with Multi-Channel Convolutional Neural Network. IEEE Transactions on Information Forensics and Security, 2019. Journal Article · doi:10.1109/tifs.2019.2916652 · Related Dataset doi:10.34777/8zdh-v182
- Heterogeneous Face Recognition Using Domain Specific Units. IEEE Transactions on Information Forensics and Security, 2019. Journal Article · doi:10.1109/tifs.2018.2885284
- Face Recognition Systems Under Spoofing Attacks. Face Recognition Systems Under Spoofing Attacks, 2016. Book Chapter · doi:10.1007/978-3-319-28501-6_8 · Related Dataset doi:10.34777/payf-vb10
- On the use of client identity information for face anti-spoofing. IEEE Transactions on Information Forensics and Security, Special Issue on Biometric Anti-spoofing, 2015. Journal Article · doi:10.1109/tifs.2015.2400392
- Biometrics Evaluation Under Spoofing Attacks. IEEE Transactions on Information, Forensics and Security, 2014. Journal Article · doi:10.1109/tifs.2014.2349158
- Anti-spoofing in action: joint operation with a verification system. Computer Vision and Pattern Recognition Conference - Biometrics Workshop, 2013. Conference Paper · doi:10.1109/cvprw.2013.22
- Motion-Based Counter-Measures to Photo Attacks in Face Recognition. IET Biometrics, 2013. Journal Article · doi:10.1049/iet-bmt.2012.0071
- On the Effectiveness of Local Binary Patterns in Face Anti-spoofing. IEEE International Conference of the Biometrics Special Interest Group, 2012. Conference Paper · PDF · Related Dataset doi:10.34777/cwcg-7r82
- LBP-TOP based countermeasure against facial spoofing attacks. International Workshop on Computer Vision With Local Binary Pattern Variants, 2012. Conference Paper · doi:10.1007/978-3-642-37410-4_11
- Competition on Counter Measures to 2-D Facial Spoofing Attacks. International Joint Conference on Biometrics 2011, 2011. Conference Paper · doi:10.1109/ijcb.2011.6117509
- Counter-Measures to Photo Attacks in Face Recognition: a public database and a baseline. International Joint Conference on Biometrics 2011, 2011. Conference Paper · doi:10.1109/ijcb.2011.6117503
Supervised theses

Trustworthy Biometric Verification under Spoofing Attacks: Application to the Face Mode
A face-recognition system can be fooled by a photo or video of its target. This doctoral thesis built defences against such spoofing and, just as importantly, a principled way to measure how trustworthy a system is under attack.
Software
- Bob. A free signal-processing and machine-learning toolbox developed at Idiap: a comprehensive, Python-first framework to build, experiment with, and reproduce pattern-recognition and machine-learning workflows. Software BSD-3-Clause archived · Docs · PyPI · conda-forge · Source
Datasets
- WMCA (Wide Multi-Channel presentation Attack). Idiap Research Institute, 2019. Dataset · doi:10.34777/8zdh-v182 · Related Journal Article doi:10.1109/tifs.2019.2916652
- MSSpoof (Multispectral-Spoof). Idiap Research Institute, 2015. Dataset · doi:10.34777/payf-vb10 · Related Book Chapter doi:10.1007/978-3-319-28501-6_8
- Replay-Attack. Idiap Research Institute, 2012. Dataset · doi:10.34777/cwcg-7r82 · Related Conference Paper link
- Print-Attack. Idiap Research Institute, 2011. Dataset · Related Conference Paper doi:10.1109/ijcb.2011.6117503