A2D-BIOM: Attack to Defense in Biometrics
April 26-30 2027, Marrakesh, Morocco
April 26-30 2027, Marrakesh, Morocco
Face and body biometric systems nowadays face a much broader range of physical, digital, video-based, adversarial, and capture-channel attacks as they are increasingly deployed in unconstrained real-world settings. Recent advances in diffusion models, avatar generation, and open-weight video tools have made convincing attacks far easier to produce, while existing detectors and evaluation protocols often struggle with previously unseen attack types. A2D-BIOM (Attack to Defense in Biometrics) is a special session organized jointly with the 21st IEEE International Conference on Automatic Face and Gesture Recognition (FG 2027) and aims to bring together research on presentation attacks, morphing, deepfakes, video forensics, and adversarial robustness within a single focused forum.
Topics of interest include, but are not limited to:
Presentation Attack Detection: Presentation attack detection for face and ocular or periocular biometrics, covering print, replay, 3D masks, silicone, cosmetic and surgical alteration
Video Identity Attacks: Video-level identity attacks and their detection: talking-head deepfakes, reenactment, puppeteering and avatar-driven impersonation
Gesture & Body Spoofing: Gesture and body motion as both attack surface and defence, including challenge–response liveness, motion replay, and spoofing of gait and body-movement recognition
Face Morphing & Manipulation: Face morphing, demorphing and digital manipulation of face images in identity documents
Synthetic Attack Generation: Diffusion- and GAN-based generation of face and body attack samples, both for vulnerability assessment and as training data for detectors
Zero/Few-Shot Attack Detection: Zero-shot and few-shot detection of unseen face attacks using vision-language and large multimodal models
Explainable Attack Detection: Explainable and interpretable attack-detection decisions, including evidence that is meaningful to a human operator or examiner
Adversarial Robustness: Adversarial attacks on, and adversarial robustness of, deep face and body recognition models
Injection & Capture Attacks: Injection and capture-channel attacks in remote face verification and onboarding, including virtual-camera and replay-into-stream attacks
Template Reconstruction Attacks: Face image reconstruction from templates, and the recognition-level consequences of such reconstruction
Evaluation, Standards & Governance: Datasets, benchmarks, evaluation protocols, standards and certification for face and body attack detection, together with the regulatory and ethical dimension of large-scale deployment
Download the full Call for Papers HERE.
Download the A2D-BIOM flyer HERE.
Find details about paper submission HERE.