偽造から基盤モデルへ:身分証明書攻撃と検出に関する体系的なサーベイ
From Forgeries to Foundation Models: A Systematic Survey of Identity Document Attack and Detection
生成AIによる身分証明書偽造の新たな脅威に対し、提示攻撃・デジタル注入・生成合成を統合した初の脅威モデルを提案し、検出手法の変遷とデータセットの現実ギャップを体系的に分析したサーベイ論文。
著者: Gourab Das, Pavan Kumar C, Raghavendra Ramachandra
分類: cs.CR, cs.CV
原文アブストラクト
Identity document forgery has undergone a fundamental capability shift: generative AI tools now enable high-fidelity document synthesis and field-level manipulation with minimal technical expertise, while detection methods remain constrained by benchmarks that do not reflect this threat. The resulting attack surface spans physical presentation, digital injection, and fully generative synthesis, introducing distinct forensic failure modes that require a unified threat model and evaluation framework. This survey provides, to our knowledge, the first unified treatment of Presentation Attacks, Digital Injection Attacks, and GenAI-driven synthesis within a single identity verification threat model. We trace detection methodologies from rule-based heuristics through forensic localisation, injection-aware pipelines, foundation models, and few-shot frameworks. A systematic audit of public datasets from 2019--2025 exposes a persistent Reality Gap between benchmark conditions and operational deployment. We further analyse large multimodal models for identity document manipulation, identifying Script-Dependent Generative Instability (SDGI) as a recurring typographic failure mode in non-Latin script inpainting. Finally, zero-shot benchmarking on unseen synthesised ID cards shows that even the strongest publicly available models achieve APCER values above 25% under security-oriented operating conditions, highlighting substantial limits in cross-domain generalisation. We conclude by outlining future directions toward forensically grounded, privacy-preserving, and legally accountable identity verification systems.