Skip to content
Snippets Groups Projects 6.71 KiB
Newer Older
Hatef OTROSHI's avatar
Hatef OTROSHI committed
# Comprehensive Vulnerability Evaluation of Face Recognition Systems to Template Inversion Attacks via 3D Face Reconstruction 

This package is part of the signal-processing and machine learning toolbox [Bob](
It contains the source code to reproduce the following paper:
    author    = {Hatef Otroshi Shahreza and S{\'e}bastien Marcel},
    title     = {Comprehensive Vulnerability Evaluation of Face Recognition Systems to Template Inversion Attacks Via 3D Face Reconstruction},
    journal   = {IEEE Transactions on Pattern Analysis and Machine Intelligence},
    year      = {2023},
    volume    = {45},
    number    = {12},
    pages     = {14248-14265},
    doi       = {10.1109/TPAMI.2023.3312123}
Hatef OTROSHI's avatar
Hatef OTROSHI committed
[Project page](
Hatef OTROSHI's avatar
Hatef OTROSHI committed

## Installation
The installation instructions are based on [conda]( and works on **Linux systems
only**. Therefore, please [install conda]( before continuing.

For installation, please download the source code of this paper and unpack it. Then, you can create a conda
environment with the following command:

$ git clone
$ cd bob.paper.tpami2023_face_ti

# create the environment
$ conda create --name bob.paper.tpami2023_face_ti --file package-list.txt
# or 
# $ conda env create -f environment.yml

# activate the environment
$ conda activate bob.paper.tpami2023_face_ti  

# install paper package
$ pip install ./ --no-build-isolation  
We use [EG3D]( as a pretrained face generator network based on generative neural radiance fields (GNeRF). Therefore, you need to clone its git repository and download [available pretrained model](
$ git clone
We use `ffhq512-128.pkl` [checkpoint]( in our experiments.

## Downloading the datasets
In our experiments, we use [FFHQ]( dataset for training our face reconstruction network.
Also we used [MOBIO]( and [LFW]( datasets for evaluation.
All of these datasets are publicly available. To download the datasets please refer to their websites:
- [FFHQ](
- [MOBIO](
- [LFW](

Hatef OTROSHI's avatar
Hatef OTROSHI committed
## Downloading Pretrained models
In our experiments, we used different face recognition models. Among which ArcFace and ElasticFace are integrated in Bob and the code automatically downloads the checkpoints. For other models (such AttentionNet, Swin, etc.) we used [FaceX-Zoo repository]( Therefore you need to download checkpoints from this repositpry ([this table]( and put in a folder with the following structure:
├── backbones
│   ├── AttentionNet92
│   │   └──
│   ├── HRNet
│   │   └──
│   ├── RepVGG_B1
│   │   └──
Hatef OTROSHI's avatar
Hatef OTROSHI committed
│   └── SwinTransformer_S
│       └──
Hatef OTROSHI's avatar
Hatef OTROSHI committed
└── heads
You can use other models from FaceX-Zoo and put in this folder with the aforementioned structure.

Hatef OTROSHI's avatar
Hatef OTROSHI committed
## Configuring the directories of the datasets
Now that you have downloaded the three databases. You need to set the paths to
those in the configuration files. [Bob]( supports a configuration file
(`~/.bobrc`) in your home directory to specify where the
databases are located. Please specify the paths for the database like below:
# Setup FFHQ directory
$ bob config set [YOUR_FFHQ_IMAGE_DIRECTORY]

# Setup MOBIO directories
$ bob config set  bob.db.mobio.annotation_directory [YOUR_MOBIO_ANNOTATION_DIRECTORY]

# Setup LFW directories
$ bob config set [YOUR_LFW_IMAGE_DIRECTORY]
Hatef OTROSHI's avatar
Hatef OTROSHI committed
If you use FaceX-Zoo models you need to define the paths to the checkpoints of FaceX-Zoo models too:
# Setup LFW directories
Hatef OTROSHI's avatar
Hatef OTROSHI committed

## Running the Experiments
### Step 1: Training face reconstruction model
You can train the face reconstruction model by running ``. For example, for blackbox attack against `ElasticFace` using `ArcFace` in loss function, you can use the following commands:
python --path_eg3d_repo <path_eg3d_repo>  --path_eg3d_checkpoint <path_eg3d_checkpoint>       \
                --FR_system ElasticFace   --FR_loss  ArcFace  --path_ffhq_dataset <path_ffhq_dataset>  \
Hatef OTROSHI's avatar
Hatef OTROSHI committed

#### Pre-trained models (GaFaR Mapping Network)
[Checkpoints]( of trained models of the mapping network for whitebox and blackbox attacks are available in the [project page](

Hatef OTROSHI's avatar
Hatef OTROSHI committed
### Step 2: Evaluation (Template Inversion)
After the model is  trained, you can use it to run evaluation.
For evaluation, you can use `evaluation_pipeline` script and evaluate on an evaluation dataset (MOBIO/LFW). For example, for evaluation of a face reconstruction of ElasticFace to attack the same system on MOBIO dataset, you can use the following commands:
python --path_eg3d_repo <path_eg3d_repo>  --path_eg3d_checkpoint <path_eg3d_checkpoint>    \
                --FR_system ElasticFace  --FR_target  ElasticFace --attack GaFaR  --checkpoint <path_checkpoint>  \
                --dataset MOBIO
After you ran the evaluation pipeline, you can use `` to caluclate the vulnaribility in terms of Sucess Attack Rate (SAR).  

## Other Materials
### Project Page
You can find general information about this work, including general block diagarm of the proposed method and experiments in the [project page](
### Dataset of Presebtation Attacks
As described in the paper, we used the reconstructed face images from MOBIO dataset and performed practical presentation attack
The captured images from our presentation attacks are [publicly available](

## Contact
For questions or reporting issues to this software package, please contact the first author ( or our development [mailing list](