Research & Papers

MorphUNet: New diffusion model creates undetectable face morphs, beating six recognition systems

This attack fools 3 of 6 top face recognition systems with 92% success on FEI dataset

Deep Dive

MorphUNet represents a significant advancement in face morphing attack research, introducing a diffusion-based framework that can create synthetic faces verifiable against two different identities. The method, developed by Taimoor Rizwan and colleagues at the University of Surrey, employs a novel Biometric Transport Layer inside the denoising U-Net. This layer uses trainable parent-separated dual cross-attention, attending to each parent's identity evidence separately before combining them via the morphing parameter alpha. The approach also incorporates DDIM-inverted latent interpolation for coherent denoising and a weaker-parent-guided selection strategy that prevents morph collapse toward one contributor.

Evaluated against three state-of-the-art baselines (StableMorph, MIPGAN-II, and MorDIFF) on FEI and FRLL datasets using six different face recognition systems, MorphUNet consistently outperforms all baselines. It achieves a Morphing Attack Potential (MAP) of 0.919 on FEI and 0.886 on FRLL when at least three systems are fooled. The attack is particularly dangerous because it remains highly effective under cross-dataset transfer, with APCER (attack presentation classification error rate) reaching 0.996 on FEI and 0.946 on FRLL at 5% BPCER. The paper also introduces CFD-based unseen-identity stress testing across gender and ethnicity pairings, showing robustness to demographic shifts.

Key Points
  • First diffusion-based morphing framework using trainable parent-separated dual cross-attention in the denoising U-Net (Biometric Transport Layer)
  • Achieves 0.919 MAP on FEI (fooling ≥3 of 6 systems with one morph) and best FID of 35.19
  • Cross-dataset attack success rate of 99.6% (APCER at 5% BPCER) on FEI, making detection extremely difficult

Why It Matters

Face morphing attacks threaten border control and identity verification; MorphUNet shows existing systems are vulnerable to diffusion-generated morphs.

📬 Get the top 10 AI stories daily