Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

CPG-PAD: Concept-Informed Prompts Guided Presentation Attack Detection

About

Presentation Attack Detection (PAD) serves as a crucial safeguard for face recognition systems against presentation attacks such as printed photos, replayed videos, and 3D masks. Despite significant progress, existing PAD models still struggle to generalize across unseen domains due to variations in sensors, lighting, and attack materials. Recent Vision-Language Models (VLMs) have shown strong generalization ability, yet their applications in PAD remain limited because learned prompts, typically optimized under class-label supervision, fail to explicitly align with fine-grained attack-relevant visual semantics. As a result, the learned representations often overfit domain-specific artifacts instead of capturing transferable attack cues. To address this, we propose Concept-Informed Prompts Guided Presentation Attack Detection (CPG-PAD), a framework that introduces model-level concept guidance into the prompt learning process. Specifically, we design a Visual Concept-driven Enhancement (VCE) module that employs eXplainable AI (XAI) techniques to automatically discover PAD-relevant visual concepts and generate concept-associated heatmaps providing localized fine-grained guidance. Guided by these heatmaps, a Prompt-based Concept Injection (PCI) mechanism integrates these concepts into the prompt space through a Visual-Prompt Decoder (VPD) and a concept-mapping loss, enabling prompts to align with the model's internal concept space. This design enables CPG-PAD to capture generalizable and domain-invariant attack cues while effectively suppressing dataset-specific biases. Extensive experiments across nine benchmark datasets demonstrate that CPG-PAD consistently achieves state-of-the-art cross-domain performance under multi-source, limited-source, and single-source settings.

Haoyuan Zhang, Xiangyu Zhu, Li Gao, Ajian Liu, Siran Peng, Zhen Lei• 2026

Related benchmarks

TaskDatasetResultRank
Face Anti-SpoofingReplay-Attack I (test)
HTER0.71
72
Face Anti-SpoofingMSU-MFSD M (test)
HTER1.67
58
Face Anti-SpoofingOULU-NPU O (test)
HTER0.0149
53
Face Anti-SpoofingCASIA-FASD C (test)
HTER0.78
25
Face Presentation Attack DetectionOULU-NPU Target (test)
HTER2.25
23
Face Anti-SpoofingOULU-NPU CASIA-MFSD Idiap MSU-MFSD Average (test)--
19
Face Presentation Attack DetectionStep 4 MSU-MFSD -> CASIA-MFSD -> Idiap Replay-Attack -> OULU-NPU
HTER (MSU-MFSD)1.67
15
Face Presentation Attack DetectionSiW-M P5 Protocol v2
Error Rate (FunE)2.3
14
Face Anti-SpoofingCSW CASIA-MFSD, SiW, W-FAS
HTER (CS → W)6.99
14
Face Presentation Attack DetectionCASIA-MFSD P3 Protocol (test)
HTER2.67
8
Showing 10 of 10 rows

Other info

Follow for update