MorphUNet: Alpha-Controlled Biometric Transport for Diffusion-Based Face Morphing Attacks

📅 2026-07-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the threat posed by face morphing attacks to identity verification systems by proposing MorphUNet, a novel diffusion-based face morphing framework. The method formulates morphing as a biometric trait transfer process governed by an alpha parameter and introduces a trainable, parent-separated dual cross-attention mechanism—termed the biometric transfer layer—within the U-Net architecture. By integrating DDIM inverse latent space interpolation with a weak-parent guidance strategy, MorphUNet effectively mitigates identity collapse. Further enhancements include CLIP and ArcFace feature disentanglement, an identity-aware token bank, and residual fusion. Evaluated on the FEI and FRLL datasets, MorphUNet achieves state-of-the-art attack performance (MAP: 0.919/0.886) and high visual quality (FID: 35.19/44.86), while substantially increasing cross-dataset detection difficulty (APCER: 0.996/0.946).
📝 Abstract
Face morphing attacks create synthetic images verifiable against multiple identities, threatening border control and identity verification systems. We introduce MorphUNet, a diffusion morphing framework formulating two-parent generation as alpha-controlled biometric transport: each parent is decomposed into CLIP appearance and ArcFace identity evidence, aligned into a CLIP-compatible token space, with the two contributors preserved as separate identity-aware token banks. To our knowledge, MorphUNet is the first diffusion-based morphing framework using trainable parent-separated dual cross-attention inside the denoising U-Net: a Biometric Transport Layer carrying parent-specific identity evidence through denoising, attending to each parent separately before combining residuals via the morphing parameter alpha. DDIM-inverted latent interpolation gives a coherent denoising start, while weaker-parent-guided selection favours morphs maximising the lower parent-similarity score, reducing collapse toward one contributor. We evaluate MorphUNet against three state-of-the-art baselines (StableMorph, MIPGAN-II, and MorDIFF) on FEI and FRLL using six recognition systems, and propose CFD-based unseen-identity stress testing across gender and ethnicity pairing, demographic shifts, and parent-similarity extremes. MorphUNet achieves the best Morphing Attack Potential (MAP) when at least three of six systems are fooled by one morph, reaching 0.919 on FEI and 0.886 on FRLL, and obtains the best FID on both datasets (35.19 FEI, 44.86 FRLL). It also gives the highest APCER at 5% BPCER in the same-dataset setting, and remains highly difficult to detect under cross-dataset transfer, with APCER 0.996 on FEI and 0.946 on FRLL. The full evaluation analyses MAP, MAD, per-system vulnerability, identity balance, image quality, top/bottom-similarity stress tests, and CFD unseen-identity robustness.
Problem

Research questions and friction points this paper is trying to address.

face morphing attacks
biometric transport
identity verification
diffusion-based generation
morphing attack potential
Innovation

Methods, ideas, or system contributions that make the work stand out.

diffusion-based morphing
alpha-controlled biometric transport
dual cross-attention
identity-aware token banks
morphing attack potential
🔎 Similar Papers
2024-01-21IEEE International Conference on Automatic Face & Gesture RecognitionCitations: 4