ZeroHour
arXiv cs.CRpublished ()ingested Athanasios Angelakis

Compact Vision Models for Iris Presentation Attack Detection under Presentation Attack Instrument Shift and Environmental Degradation

infoResearchimportance 20
AI summary · glm-5.3-flash

Compact iris presentation-attack detection models under 0.3M parameters show APCER rising 17-30 percentage points against unseen attack instruments, indicating limited deployment readiness.

Three scratch-trained compact vision models, each with at most roughly 0.26 million trainable parameters, were benchmarked on the Notre Dame subset of LivDet-Iris 2017 under presentation attack instrument shift and environmental degradation, trained without pretraining or augmentation and evaluated over five seeds. Moving from known to unknown attack presentations raises APCER by 17.11-30.47 percentage points and D-EER by 7.38-12.73 points. ZACH-ViT achieves the lowest unknown-attack APCER (47.69% +/- 4.84%) and D-EER (38.87% +/- 0.93%), while Compact-TransMIL yields the lowest bona fide classification error rate; high absolute errors show none are deployment-ready.

  • Three compact models, at most ~0.26M parameters, trained from scratch without pretraining or augmentation.
  • Unknown-attack APCER rises 17.11-30.47 percentage points versus known attacks on LivDet-Iris 2017 Notre Dame data.
  • ZACH-ViT achieves the lowest unknown-attack APCER of 47.69% and D-EER of 38.87%.
  • High absolute error rates show no compact model is deployment-ready under unknown presentation attack instruments.
Full article184 words · extracted from arxiv.org · click to collapse

Iris presentation attack detection (PAD) is security-critical when a subsystem that appears reliable during development encounters presentation attack instruments (PAIs) or acquisition conditions absent from validation data. We benchmark three compact scratch-trained computer-vision models, each with at most approximately 0.26 million trainable parameters, on the Notre Dame subset of LivDet-Iris 2017 under PAI-driven domain shift and environmental degradation. All models are trained without external pretraining or data augmentation and evaluated over five seeds. A validation-selected threshold is transferred unchanged to the known-attack, unknown-attack, corrupted, and pooled test partitions. From known to unknown attack presentations, Attack Presentation Classification Error Rate (APCER) increases by 17.11-30.47 percentage points and Detection Equal Error Rate (D-EER) increases by 7.38-12.73 percentage points. At the validation-selected threshold, ZACH-ViT obtains the lowest unknown-attack APCER (47.69 +/- 4.84%) and D-EER (38.87 +/- 0.93%), while Compact-TransMIL obtains the lowest Bona Fide Presentation Classification Error Rate (BPCER). ZACH-ViT also gives the lowest unknown-attack BPCER at an APCER limit of 10% (81.29 +/- 1.95%). The high absolute errors show that the comparative advantage of the best compact model does not constitute deployment readiness under unknown PAIs.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.20386