Robust Face Recognition and Morphing Defense Through Hyperspherical Manifold Hardening
Abstract Modern face recognition systems are widely deployed in high-security environments, such as automated border control and mobile authentication. However, these systems remain vulnerable to two primary security threats: adaptive adversarial perturbations, where minor pixel modifications cause misidentification, and structural face morphing, where blended composite images deceive biometric scanners. In this paper, we address the limitations of traditional lightweight models that suffer from spatial manifold crowding and decision boundary collapse under multi-step attack pressures. We propose a unified defense framework that integrates Adversarial Geodesic Loss with Smooth Softplus Margin regularization on a high-capacity pre-trained IResNet-100 backbone. By forcing the network to dynamically defend against online Projected Gradient Descent trajectories during training, our approach reshapes the latent hypersphere without sacrificing feature separability. Empirical evaluations demonstrate that our hardened pipeline achieves an absolute zero-percent bypass rate against landmark-aligned Delaunay triangulation morphing and restricts white-box adaptive attack success, while maintaining a pristine one-hundred-percent verification true acceptance rate for genuine users. This study establishes a robust, scalable defense mechanism that satisfies strict transaction standards for high-security biometric deployments. Keywords—Biometric security, face recognition, face morphing attacks, adversarial robustness, hyperspherical embeddings, geodesic distance, deep learning defense.
Authors
- Ishmat Fatima T.P.
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-09
- DOI
- https://doi.org/10.5281/zenodo.23261655
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00