<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>O.Stets);</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Face anti-spoofing systems optimal threshold selection criteria</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ostap Stets</string-name>
          <email>ostap.stets@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ihor Konovalenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tomasz Gancarczyk</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artur Mykytyshyn</string-name>
          <email>mykytyshyn21@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Ternopil Ivan Puluj National Technical University</institution>
          ,
          <addr-line>Ruska str., 56, Ternopil, 46001</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Bielsko-Biala</institution>
          ,
          <addr-line>Willowa St. 2, Bielsko-Biala, 43-300</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2024</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>This article is devoted to the problem of criteria definition for optimal threshold selection in face anti-spoofing systems based on common conventional metrics in the area. Analysis of previous studies has shown that live applications of presentation attack detection methods most often rely on common methods of threshold selection while tending to ignore domain and problem-specific requirements. Therefore, the main purpose of this research is to determine the criteria for optimal threshold selection in production-applied biometric authentication systems. To address these limitations, the paper proposes an approach for automated threshold selection that incorporates an “Environmental Adjustment” factor. This factor takes into account the specific context of the PAD system's deployment, including security needs and user experience considerations.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Face anti-spoofing</kwd>
        <kwd>presentation attack</kwd>
        <kwd>person identification 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>domains. Among those some security-critical areas relying on biometric authentication
are facing heightened risks, due to a wide set of possible attacks, e.g. videos, printed
pictures, masks, and especially from sophisticated attacks like morphing, where fake
identities can be generated by blending images of genuine and fraudulent subjects. These
attacks pose significant threats requiring robust countermeasures to ensure secure and
reliable identification processes.</p>
      <p>In less security-critical environments, such as social media platforms or online
shopping websites, the problem of presentation attack detection (PAD) still holds
importance but is approached differently. Here, the focus is more on general user
experience and convenience rather than stringent security measures. This imposes a
problem of balancing security measures with user friction at least until the moment when
used PAD solution performs perfectly on relevant datasets.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Problem formulation</title>
      <p>While no face anti-spoofing system is error-prone, researchers and developers are forced
to select the optimal error threshold. Setting thresholds too high for biometric
authentication may result in increased user frustration and abandonment of the
authentication process where it is not critical to him. On the other hand, setting thresholds
too low may compromise security by allowing unauthorized access which is unacceptable
in certain cases.</p>
      <p>Another consideration is the trade-off between security and computational resources.
Higher thresholds often require more computational power for accurate authentication,
potentially increasing processing times and costs. Balancing the need for security with
resource efficiency is crucial in these environments to provide a seamless user experience
without compromising on security standards.</p>
      <p>
        Whenever a person passes a face recognition-enabled biometrical identification
system, their biometrical data is passed to the PAD subsystem. This data is most
commonly analyzed in a pre-trained convolutional neural network (CNN) to distinguish
real identity from attackers. The result of the PAD subsystem is a confidence score on
whether this data was genuine or fraudulent. The final decision is made by comparing this
score with a classification threshold. This value depends on special metrics described by
ISO/IEC 30107-3:2023 on training datasets [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Two central parameters to ensure that
test results are accurate are:


      </p>
      <p>Attack presentation classification error rate (APCER). It measures the error rate in
classifying attack presentations as genuine.</p>
      <p>Bona fide presentation classification error rate (BPCER). It measures the error rate
in classifying genuine presentations as spoofed.</p>
      <p>
        This metric's purpose is to assess the PAD subsystem's ability to identify bona fide
presentation attacks, its instruments, attack frequency, and error rate [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. They cover such
factors as presentation attack instruments and species (PAIS), artifacts and present
nonwhere  
is the number of attack presentations for given PAI species; 
 takes value
1 if the corresponding presentation is classified as an attack presentation and value 0 if
classified as a bona fide presentation [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
      </p>
      <p>
        As mentioned in the papers [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ], performance metrics for the set of bona fide
presentations captured with the evaluation target shall be calculated and reported as
BPCER using the formula:
=
∑  
 =1
 

conformant characteristics, and description of output information provided by the PAD
subsystem.
      </p>
      <p>The APCER for a given PAIS is calculated using the formula:
(1)
(2)
(3)

= 1 − (
 
1</p>
      <p>) ∑ 
where  
is the number of bona fide presentations; 
 takes value 1 if the
corresponding presentation is classified as an attack presentation and value 0 if classified
as a bona fide presentation.</p>
      <p>
        The overall accuracy of the PAD subsystem is measured by using the Average
Classification Error Rate (ACER) defined as [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]:
      </p>
      <p>As with all biometric identification systems, both error rates, APCER and BPCER, can’t
be minimized at the same time, as a decrease of one means an increase of another because
it is impossible to completely separate responses of bona fide presentations as
presentation attacks.</p>
      <p>As the outcome of the PAD system purpose, attack presentations tend to receive lower
scores while bona fide presentations receive higher scores. However, because these scores
overlap in most cases, a specific threshold should be selected. This paper is devoted to the
research of the selection method of this threshold value in different environments where
security importance can vary. The purpose of the analysis is to determine criteria, which
would allow easier balancing between PAD safety and general user experience and
convenience.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Comparative analysis of known solutions and suggested improvements</title>
      <p>
        In paper [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] followed by research [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] authors describe the pilot of a new Automatic
Border Control (ABC) system which was developed in the ABC4EU European project and
conforms to the laws established in the Schengen zone. These new ABCs have specific
characteristics, such as a structural configuration divided into two devices: self-enrolment
kiosk and biometric gate, one for enrolment and the other for verification, which entails
two capture stages and two weaknesses where it is possible to attack the system [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
Researchers describe three different presentation attack types in their experimental
setup:



“Enrolment PA, when a presentation attack occurs at the self-enrolment stage. For
example, an attacker provides the system with documentation that belongs to
someone else and therefore tries to impersonate the true holder of the documents”
[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
“Verification PA, when a presentation attack occurs at the verification stage. An
attacker tries to impersonate a traveler who has previously enrolled in the system.
For example, a correctly registered traveler loses or steals his/her documents
between the self-stage and the verification stage. Then an attacker uses those
documents to try to pass the verification” [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
“Enrolment and Verification PA. In this case, an impersonation has occurred at the
enrolment and the attacker continues impersonating the true traveler at the
verification stage (double attack). For example, an attacker presents travel
documentation that belongs to someone else and gets successfully enrolled. After
that, in the verification stage, the attacker continues to impersonate the true holder
of the documents to cross the e-gate” [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        As mentioned by the authors, security is a top priority in ABC systems while
convenience and user experience are secondary, so they decided to set a threshold value
that returns a low APCER value even if it increases the BPCER [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. In this case, it is not
critical as ABC systems are controlled by an agent, who can verify and correct bona fide
presentations which were considered as an attack. They came up with an experimental
setting of threshold values which led to a threshold of 80 at self-enrolment and a threshold
of 95 at the biometric gate. Results of these experiments are displayed in Table 1 and
Table 2.
      </p>
      <p>Even considering ABC4EU PAD as a security-critical subsystem, a BPCER value of
0.7333 is too high for the automatic system to be effective. This could indicate a
discrepancy between training datasets and real-life bona fide presentations.</p>
      <p>
        As displayed, BPCER value at the biometric gate is much better, however, the APCER of
0.206 at a threshold value of 95 is still too high to consider the system effective.
Considering article [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] we could assume that these values were improved since the first
project piloting, however latest data on PAD subsystem efficiency is not publicly available.
However optimal threshold selection remains an issue in ABC4EU because manual setting
during training with the dataset is imperfect for the following reasons:
1. The pre-trained model with a static dataset is limited from updates in bona fide
presentation changes happening due to passenger flow shuffling (because of
variable reasons, e.g. climate changes [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], economic reasons, infrastructural
changes or conflicts arising [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]) imposing shifting in genuine presentation age,
gender, and race. ethnicity, and other demographic PAD biases [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ].
2. Project scalability becomes challenging as different border control points would
require different training datasets due to the same demographic reasons [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
Additionally, specific domain considerations like different environments and
devices complicate optimal threshold selection in the scenario of ABC
reimplementation [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        Considering the above, we could conclude that the optimal threshold selection process
should be automated based on specific methods and parameters.
3.2. RIAPAR
The 2023 revision of ISO/IEC 30107-3:2023 [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] includes new metrics that provide better
insight into the real-world performance of a complete biometric system [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. One new
metric is called “RIAPAR”, used to measure how well a biometric system detects attacks
without interrupting legitimate users. It is calculated using the formula:
      </p>
      <p>
        =  +  +  (4)
where FNMR is the proportion of the completed biometric mated comparison trials that
result in a false non-match; IAPAR is the impostor Attack Presentation Accept Rate defined
as the proportion of impostor attack presentations using the same PAIS that result in an
accept [
        <xref ref-type="bibr" rid="ref10 ref11 ref2 ref4">2, 4, 10, 11</xref>
        ].
      </p>
      <p>The previously common approach used by most of the PAD subsystems selected
threshold minimizing equal error rate (EER), equalizing APCER and BPCER, which ignores
the PAD operational environment. While the RIAPAR metric which is mandatory for PAD
product certification places user experience and convenience higher in the process
selection optimal threshold it is not suitable for security-critical areas and not consider
the PAD system area of usage.</p>
      <p>To mitigate this problem, optimal threshold selection automation following formula
could be implemented:</p>
      <p>ℎ ℎ =  +  (5)
where BT is the Base Threshold defined during training with initial dataset APCER and
BPCER; EA is Environmental Adjustment is the factor that accounts for variations in
environmental conditions that may impact the performance of the face anti-spoofing
system.</p>
      <p>Environmental Adjustment can be expressed as a function of environmental
parameters such as general security conditions and requirements, availability of human
intervention to the identification process, biometric presentation-specific conditions, and
other PAD product-specific criteria. It can be further defined as:

=
∑</p>
      <p>×  

where n is the number of environmental factors considered;   is the weight assigned to
each environmental factor based on its importance and impact on the system's
performance;   is the value of the environmental factor (positive or negative) at a given
moment.</p>
      <p>By incorporating environmental conditions into the threshold definition, the face
antispoofing system can dynamically adapt its threshold to optimize performance under
varying conditions, enhancing overall accuracy and robustness.</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusion</title>
      <p>requirements
This article is devoted to the research of the aspect of selecting the optimal threshold in
face anti-spoofing systems to bolster security while ensuring user convenience. While
common methods often prioritize minimizing equal error rates (EER) [12, 13, 14], this
approach fails to consider the diverse operational environments and varying security</p>
      <p>Most existent production-ready PAD systems use metrics defined in ISO/IEC
301073:2023, which makes them compliant with principles and methods of performance
assessment of biometric presentation attack detection. Metrics like APCER, BPCER, and
ACER described in the article are essential for the successful utilization of any face
antispoofing system. When testing biometric systems for security vulnerabilities, the sheer
number and variety of potential tools used to spoof the system (PAIS) can be
overwhelming. It's often impractical, if not impossible, to create a model that encompasses
every possible spoofing method. Consequently, leveraging between these and fine-tuning
the PAD system becomes a challenge.</p>
      <p>The analysis of existing solutions like ABC4EU demonstrates the limitations of static
threshold selection based on pre-trained datasets. Therefore, this paper proposes a
formula for automated threshold</p>
      <p>selection that incorporates an “Environmental
Adjustment” factor (EA). This factor accounts for the specific context of the PAD system’s
deployment, including security needs, and user experience considerations. By dynamically
adjusting the threshold based on these environmental parameters, the face anti-spoofing
system can function more effectively and securely when deployed in real-world settings.
[12] Y. Brice Wandji Piugie. Performance and Security Evaluation of Behavioral Biometric
Systems. Computer Science. Université de Caen Normandie, 2023. URL:
https://hal.science/tel-04397160/document.
[13] L. J. Gonzalez-Soler, M. Gomez-Barrero, C. Busch: Toward Generalizable Facial
Presentation Attack Detection Based on the Analysis of Facial Regions. IEEE Access,
vol. 11, pp. 68512-68524, 2023, doi: 10.1109/ACCESS.2023.3292407. URL:
https://ieeexplore.ieee.org/document/10173519.
[14] Yevseiev, S., Ponomarenko, V., Laptiev, O., Milov, O., Korol, O., Milevskyi, S. Synergy of
building cybersecurity systems. Kharkiv: РС ТЕСHNOLOGY СЕNTЕR, 2021, 188.
doi: http://doi.org/10.15587/978-617-7319-31-2</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <article-title>[1] ISO/IEC JTC1 SC37 Biometrics</article-title>
          .
          <source>ISO/IEC 30107-3. Information Technology - Biometric presentation attack detection - Part</source>
          <volume>3</volume>
          : Testing and Reporting.
          <source>International Organization for Standardization</source>
          ,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>D.</given-names>
            <surname>Ortega-Delcampo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Conde</surname>
          </string-name>
          , Á. Serrano,
          <string-name>
            <given-names>I. M.</given-names>
            <surname>Diego</surname>
          </string-name>
          , E. Cabello:
          <article-title>Face Recognitionbased Presentation Attack Detection in a Two-step Segregated Automated Border Control e-Gate - Results of a Pilot Experience at Adolfo Suárez Madrid-Barajas Airport</article-title>
          .
          <volume>10</volume>
          .5220/0006426901290138 URL: https://www.scitepress.org/papers/2017/64269/64269.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>D.</given-names>
            <surname>Ortega-Delcampo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Conde</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Palacios-Alonso</surname>
          </string-name>
          ,
          <string-name>
            <surname>E.</surname>
          </string-name>
          <article-title>Cabello: Border Control Morphing Attack Detection with a Convolutional Neural Network De-Morphing Approach</article-title>
          . IEEE Access, vol.
          <volume>8</volume>
          , pp.
          <fpage>92301</fpage>
          -
          <lpage>92313</lpage>
          ,
          <year>2020</year>
          , doi: 10.1109/ACCESS.
          <year>2020</year>
          .2994112. URL: https://ieeexplore.ieee.org/document/9091520.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>N.</given-names>
            <surname>Matei</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. Garcia</given-names>
            <surname>Leon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dosio</surname>
          </string-name>
          ,
          <string-name>
            <surname>F. Batista E Silva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. Ribeiro</given-names>
            <surname>Barranco</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.C.</given-names>
            <surname>Ciscar</surname>
          </string-name>
          <article-title>Martinez: Regional impact of climate change on European tourism demand</article-title>
          ,
          <source>EUR 31519 EN, Publications Office of the European Union, Luxembourg</source>
          ,
          <year>2023</year>
          , ISBN 978- 92-68-03925-0, doi:10.2760/899611, JRC131508. URL: https://publications.jrc.ec.europa.eu/repository/bitstream/JRC131508/JRC131508_ 01.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>L.</given-names>
            <surname>Gabrielli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Deutschmann</surname>
          </string-name>
          ,
          <string-name>
            <surname>F.</surname>
          </string-name>
          <article-title>Natale: Dissecting global air traffic data to discern different types and trends of transnational human mobility</article-title>
          .
          <source>EPJ Data Sci. 8</source>
          ,
          <issue>26</issue>
          (
          <year>2019</year>
          ). https://doi.org/10.1140/epjds/s13688-019-0204-x.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>ChaLearn</surname>
          </string-name>
          <article-title>: 2020 Looking at People Fair Face Recognition challenge ECCV</article-title>
          . URL: https://chalearnlap.cvc.uab.cat/challenge/38/description.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>N.</given-names>
            <surname>Alshareef</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Yuan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Roy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Atay</surname>
          </string-name>
          .:
          <article-title>A Study of Gender Bias in Face Presentation Attack</article-title>
          and
          <string-name>
            <given-names>Its</given-names>
            <surname>Mitigation</surname>
          </string-name>
          .
          <source>Future Internet</source>
          <year>2021</year>
          ,
          <volume>13</volume>
          ,
          <fpage>234</fpage>
          . URL: https://doi.org/10.3390/fi13090234.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Srivatsan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Naseer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Nandakumar</surname>
          </string-name>
          . FLIP:
          <article-title>Cross-domain Face Anti-spoofing with Language Guidance</article-title>
          . URL: https://arxiv.org/pdf/2309.16649v1.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>IDR</surname>
          </string-name>
          &amp;
          <article-title>D: What's New in the Recent Update of ISO/IEC 30107 for Biometric Presentation Attack Detection</article-title>
          . URL: https://www.idrnd.ai/iso-30107-2023-livenessupdates.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M.</given-names>
            <surname>Ibsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. J.</given-names>
            <surname>Gonzalez-Soler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Rathgeb</surname>
          </string-name>
          ,
          <string-name>
            <surname>C.</surname>
          </string-name>
          <article-title>Busch: TetraLoss: Improving the Robustness of Face Recognition against Morphing Attacks</article-title>
          , da/sec - Biometrics and Security Research Group, Hochschule Darmstadt,
          <volume>64295</volume>
          , Germany. URL: https://arxiv.org/pdf/2401.11598v1.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>H.</given-names>
            <surname>Lypak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Rzheuskyi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Kunanets</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Pasichnyk</surname>
          </string-name>
          ,
          <article-title>"Formation of a consolidated information resource by means of cloud technologies"</article-title>
          , 5th International ScientificPractical Conference Problems of Infocommunications.
          <source>Science and Technology PIC S&amp;T'</source>
          <year>2018</year>
          , October 9-
          <issue>12</issue>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>