Deep learning has significantly improved the performance of fingerprint liveness detection, while susceptibility to adversarial attacks remains a critical security challenge. Existing input transformation–based defense methods, including JPEG compression, total variance minimization (TVM), high‐level representation guided denoiser (HGD), and Defed, are typically designed for specific attacks, resulting in limited generalization across diverse adversarial scenarios. Experimental analysis indicates that among the four defense methods based on input transformation, Defed achieves the best overall performance when evaluated against both momentum iterative fast gradient sign method (MI‐FGSM) and DeepFool attacks. However, Defed exhibits strong robustness against MI‐FGSM attacks but demonstrates insufficient defense effectiveness against DeepFool attacks. To address this issue, an improved method of Defed has been proposed by integrating a learnable Gaussian noise module into the core structure to enable adaptive suppression of adversarial perturbations, and by employing 1 × 1 convolutions to allow cross‐channel information interaction, thereby enhancing feature consistency and overall robustness. Experimental results on the LivDet 2015 dataset demonstrate that the defense success rate against DeepFool attacks has increased by 3%–5%, while strong robustness against MI‐FGSM attacks has been maintained, substantially improving the security and reliability of fingerprint liveness detection systems.
Sun et al. (Thu,) studied this question.