Trustworthy Biometric Verification under Spoofing Attacks: Application to the Face Mode

Research outputs
  • Ivana Chingovska, Nesli Erdogmus, André Anjos and Sébastien Marcel. Face Recognition Systems Under Spoofing Attacks. Face Recognition Systems Under Spoofing Attacks, 2016. Book Chapter · doi:10.1007/978-3-319-28501-6_8 · Related Dataset doi:10.34777/payf-vb10
  • Ivana Chingovska and André Anjos. On the use of client identity information for face anti-spoofing. IEEE Transactions on Information Forensics and Security, Special Issue on Biometric Anti-spoofing, 2015. Journal Article · doi:10.1109/tifs.2015.2400392
  • Ivana Chingovska, André Anjos and Sébastien Marcel. Biometrics Evaluation Under Spoofing Attacks. IEEE Transactions on Information, Forensics and Security, 2014. Journal Article · doi:10.1109/tifs.2014.2349158
  • Ivana Chingovska, André Anjos and Sébastien Marcel. Evaluation Methodologies. Handbook of Biometric Anti-Spoofing, 2014. Book Chapter · doi:10.1007/978-1-4471-6524-8_10
  • André Anjos, Ivana Chingovska and Sébastien Marcel. Anti-Spoofing: Face Databases. Encyclopedia of Biometrics, 2014. Book Chapter · doi:10.1007/978-3-642-27733-7_9212-2
  • Ivana Chingovska, André Anjos and Sébastien Marcel. Anti-spoofing in action: joint operation with a verification system. Computer Vision and Pattern Recognition Conference - Biometrics Workshop, 2013. Conference Paper · doi:10.1109/cvprw.2013.22
  • I. Chingovska, J. Yang, Z. Lei, D. Yi, S. Z. Li, O. Kähm, C. Glaser, N. Damer, … André Anjos et al. The 2nd Competition on Counter Measures to 2D Face Spoofing Attacks. International Conference on Biometrics 2013, 2013. Conference Paper · doi:10.1109/icb.2013.6613026
  • Ivana Chingovska, André Anjos and Sébastien Marcel. On the Effectiveness of Local Binary Patterns in Face Anti-spoofing. IEEE International Conference of the Biometrics Special Interest Group, 2012. Conference Paper · PDF · Related Dataset doi:10.34777/cwcg-7r82
  • Ivana Chingovska, André Anjos and Sébastien Marcel. Replay-Attack. Idiap Research Institute, 2012. Dataset · doi:10.34777/cwcg-7r82 · Related Conference Paper link
  • Bob. A free signal-processing and machine-learning toolbox developed at Idiap: a comprehensive, Python-first framework to build, experiment with, and reproduce pattern-recognition and machine-learning workflows. Software BSD-3-Clause archived · Docs · PyPI · conda-forge · Source
Degree
Doctoral thesis (Ph.D.)
Role
De facto co-supervisor
University
EPFL, Electrical Engineering (doctoral programme, with Idiap)
Partnerships
Idiap Research Institute🇨🇭 Switzerland

Biometric verification promises to recognise a person by who they are rather than by what they remember, and face recognition is among its most convenient forms. That convenience comes with a weakness: a system can be fooled by a presentation attack, a printed photograph or a replayed video of the legitimate user. As face verification spread into everyday devices, this thesis asked how such systems can be made trustworthy in the presence of spoofing, and how that trustworthiness can even be measured.

At the time, presentation-attack detection was a young and fragmented field, with countermeasures evaluated on private data and no agreed way to report how vulnerable a verification system really was. The thesis took the position that resistance to spoofing must be treated as a first-class property of verification, addressed both by designing effective face countermeasures and by building an evaluation methodology that quantifies a system’s behaviour when it is actually attacked.

The integration was pursued at three distinct points. At the input, the identity the verification system already knows was made available to the detector, producing client-specific countermeasures in both generative and discriminative form that outperformed their client-independent equivalents and, more importantly, held up better against attacks unseen during training. At the output, the two systems’ scores were fused as a multiple-expert problem, with several fusion rules compared on verification accuracy and robustness together. At the evaluation stage, the thesis proposed the Expected Performance and Spoofability framework, which treats the system as facing three kinds of input — genuine clients, zero-effort impostors and deliberate attacks — and its accompanying curve, which allows two systems to be compared without the bias that follows from tuning on the test set. All of it was released as free software alongside the public Replay-Attack database and a family of texture and motion countermeasures.

The hypothesis is borne out at every one of the three points, and the answer to the opening question is that trustworthiness is not a property of the detector at all but of the pair. A countermeasure evaluated alone can look strong and still leave the system it protects vulnerable, because the relevant error rates only exist once attacks are admitted as a third class of input. The database, the software and the metrics became widely used reference points in presentation-attack detection, and the framing — evaluate the protected system, not the protection — is the thesis’s most durable contribution to how the community reports biometric trustworthiness.