Pith. sign in

REVIEW 1 major objections 2 minor 82 references

CPG-PAD: Concept-Informed Prompts Guided Presentation Attack Detection

T0 review · 1 major / 2 minor · reviewed 2026-07-03 · grok-4.3

Pith's one-line read Concept-informed prompts guided by XAI heatmaps let presentation attack detectors capture transferable attack cues instead of dataset biases.

desk verdict CPG-PAD adds XAI concept discovery and injection to VLM prompt learning for PAD, a coherent design step that targets domain generalization but leaves the actual gains unverified in the abstract. read the letter →

arxiv 2607.01303 v1 pith:E6K4Z6BI submitted 2026-07-01 cs.CV cs.AI

classification cs.CVcs.AI
keywords presentationattackdetectioncross-domaingeneralizationvision-languagemodelsconceptpromptsexplainableAIpromptlearningfacerecognition
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper introduces CPG-PAD to solve poor generalization in face presentation attack detection across different sensors, lighting, and materials. It adds a Visual Concept-driven Enhancement module that uses explainable AI to find relevant visual concepts and produce localized heatmaps. These heatmaps then guide a Prompt-based Concept Injection process that aligns learned prompts with fine-grained attack semantics through a visual-prompt decoder and mapping loss. A reader would care because current systems overfit to training-domain artifacts and fail on new attacks or capture devices, while this approach claims to suppress those biases. Experiments across nine datasets under multi-source, limited-source, and single-source protocols show consistent gains over prior methods.

What carries the argument

The Visual Concept-driven Enhancement (VCE) module that employs XAI to discover PAD-relevant concepts and generate concept-associated heatmaps, paired with the Prompt-based Concept Injection (PCI) mechanism that integrates them via a Visual-Prompt Decoder and concept-mapping loss.

What would settle it

An ablation study showing that removing the concept guidance and heatmaps yields no gain or a drop in cross-domain accuracy on the nine datasets compared with standard prompt learning baselines.

Watch

Extended reading notes

Core claim

The central claim is that inserting model-level concept guidance into the prompt learning process enables the model to align prompts with PAD-relevant visual semantics rather than domain-specific artifacts, thereby capturing generalizable and domain-invariant attack cues while suppressing dataset biases.

Load-bearing premise

XAI techniques can automatically discover visual concepts that provide localized guidance aligned with transferable attack cues rather than domain-specific artifacts.

Editorial extensions

If this is right

  • The method achieves state-of-the-art cross-domain performance under multi-source, limited-source, and single-source training regimes across nine benchmark datasets.
  • Prompts become aligned with the model's internal concept space instead of overfitting to class-label supervision alone.
  • Dataset-specific biases are suppressed while domain-invariant attack cues such as those from printed photos, replayed videos, and 3D masks are retained.
  • Vision-language models can be adapted to PAD without the representations collapsing to training-domain artifacts.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same concept-injection pattern could be tested on other domain-shift problems in vision such as medical image classification across scanner types.
  • If the discovered concepts prove stable, the framework might reduce the need for collecting new labeled target-domain attack samples.
  • Deployment on edge devices would require checking whether the added XAI and decoder steps preserve real-time inference speed.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

1 major / 2 minor

Summary. The manuscript proposes CPG-PAD, a framework for presentation attack detection that introduces model-level concept guidance into prompt learning for vision-language models. A Visual Concept-driven Enhancement (VCE) module uses XAI techniques to discover PAD-relevant visual concepts and produce localized heatmaps; these guide a Prompt-based Concept Injection (PCI) mechanism that integrates the concepts via a Visual-Prompt Decoder (VPD) and a concept-mapping loss. The design is intended to favor transferable attack cues over dataset-specific biases. The abstract claims that extensive experiments across nine benchmark datasets show consistent state-of-the-art cross-domain performance under multi-source, limited-source, and single-source settings.

Significance. If the empirical claims hold, the integration of XAI-derived concept heatmaps with prompt learning offers a concrete mechanism for improving domain invariance in PAD, a persistent challenge in biometric security. The approach is logically consistent with the stated pipeline and could be extended to other fine-grained visual tasks that require suppression of spurious domain cues.

major comments (1)
  1. [Abstract] Abstract: the abstract asserts SOTA results from 'extensive experiments' across nine datasets under multiple settings but supplies no quantitative metrics, baselines, error analysis, or derivation details; without these it is impossible to verify whether the data or methods support the central claim of consistent cross-domain superiority.
minor comments (2)
  1. The description of how the concept-mapping loss interacts with the VPD could be expanded with a concrete formulation or pseudocode to clarify the alignment objective.
  2. The paper would benefit from an explicit statement of the nine datasets and the precise cross-domain protocols (e.g., which domains are held out) in the experimental section.

Simulated Author's Rebuttal

1 responses · 0 unresolved

We thank the referee for the detailed and constructive review. The single major comment is addressed point-by-point below. We agree that the abstract would be strengthened by the inclusion of quantitative highlights and will revise accordingly.

read point-by-point responses
  1. Referee: [Abstract] Abstract: the abstract asserts SOTA results from 'extensive experiments' across nine datasets under multiple settings but supplies no quantitative metrics, baselines, error analysis, or derivation details; without these it is impossible to verify whether the data or methods support the central claim of consistent cross-domain superiority.

    Authors: We acknowledge that the current abstract is purely qualitative and does not report any numerical results. While the full experimental evidence (including all baselines, HTER/AUC values, statistical significance, and cross-domain protocols) appears in Sections 4–5 and the supplementary material, we agree that embedding a concise set of key metrics in the abstract will improve verifiability. In the revised version we will add one or two representative quantitative statements (e.g., average cross-domain HTER reduction) while preserving the abstract’s length limit. revision: yes

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity identified

full rationale

The provided abstract and description outline a methodological pipeline (VCE module using XAI for concept discovery, followed by PCI via VPD and concept-mapping loss) without any equations, parameter fitting, or self-citations. No load-bearing step reduces a claimed prediction or result to its own inputs by construction, self-definition, or imported uniqueness. The central claim of domain-invariant cues is presented as an intended design outcome rather than a derived quantity forced by fitting or renaming. This is the most common honest finding for a purely descriptive methods paper with no visible mathematical or empirical circularity in the given text.

Assumptions & free parameters 0 free parameters · 0 assumptions · 0 invented entities

Abstract provides no equations, implementation details, or parameter descriptions, so no free parameters, axioms, or invented entities can be identified.

how reviews work

0 comments
Cite this review

Pith. "Pith review of CPG-PAD: Concept-Informed Prompts Guided Presentation Attack Detection." pith.science (2026). https://pith.science/paper/E6K4Z6BI

@misc{pith2026260701303,
  author       = {Pith},
  title        = {Pith review of: CPG-PAD: Concept-Informed Prompts Guided Presentation Attack Detection},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/E6K4Z6BI}},
  note         = {Machine review of arXiv:2607.01303}
}
read the original abstract

Presentation Attack Detection (PAD) serves as a crucial safeguard for face recognition systems against presentation attacks such as printed photos, replayed videos, and 3D masks. Despite significant progress, existing PAD models still struggle to generalize across unseen domains due to variations in sensors, lighting, and attack materials. Recent Vision-Language Models (VLMs) have shown strong generalization ability, yet their applications in PAD remain limited because learned prompts, typically optimized under class-label supervision, fail to explicitly align with fine-grained attack-relevant visual semantics. As a result, the learned representations often overfit domain-specific artifacts instead of capturing transferable attack cues. To address this, we propose Concept-Informed Prompts Guided Presentation Attack Detection (CPG-PAD), a framework that introduces model-level concept guidance into the prompt learning process. Specifically, we design a Visual Concept-driven Enhancement (VCE) module that employs eXplainable AI (XAI) techniques to automatically discover PAD-relevant visual concepts and generate concept-associated heatmaps providing localized fine-grained guidance. Guided by these heatmaps, a Prompt-based Concept Injection (PCI) mechanism integrates these concepts into the prompt space through a Visual-Prompt Decoder (VPD) and a concept-mapping loss, enabling prompts to align with the model's internal concept space. This design enables CPG-PAD to capture generalizable and domain-invariant attack cues while effectively suppressing dataset-specific biases. Extensive experiments across nine benchmark datasets demonstrate that CPG-PAD consistently achieves state-of-the-art cross-domain performance under multi-source, limited-source, and single-source settings.

Figures

Figures reproduced from arXiv: 2607.01303 by the authors.

Figure 1
Figure 1. Comparison with Existing CLIP-like PAD Methods. (a) Previous meth [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. Detailed information of Concept-informed Prompts Guided PAD (CPG-PAD). We first generate concept-associated heatmaps [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Detailed information of Visual Concept-driven Enhancement (VCE). [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figures from the paper (5 more)
Figure 4
Figure 4. Figure 4: Detailed structure of Visual-Prompt Decoder (VPD) module. MSA [PITH_FULL_IMAGE:figures/full_fig_p005_4.png]
Figure 5
Figure 5. Figure 5: Visualization of discovered visual concepts in CelebA-Spoof dataset. [PITH_FULL_IMAGE:figures/full_fig_p006_5.png]
Figure 6
Figure 6. Figure 6: Visualization of concept-associated heatmaps in CelebA-Spoof dataset. [PITH_FULL_IMAGE:figures/full_fig_p006_6.png]
Figure 7
Figure 7. Figure 7: DET curve comparison of P1 evaluation. with two datasets as source domains and one dataset as target domain. For P2, we establish a domain generalization bench￾mark focused on multimodal sensors, incorporating the CSW datasets, leading to 3 sub-experiments where two da…
Figure 8
Figure 8. Figure 8: T-SNE visualization of OCM → I in P1 benchmark. We show T-SNE visualization of CLIP+MLP baseline and our proposed method CPG-PAD. TABLE XV COMPUTATIONAL OVERHEAD. WE COMPARE CPG-PAD WITH CLIP. Model Training Time (batch=24) Inference Time (batch=64) Training Memory (ba…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

82 extracted references · 82 canonical work pages

  1. [3]

    Contrastive context-aware learning for 3d high- fidelity mask face presentation attack detection,

    A. Liu, C. Zhao, Z. Yu, J. Wan, A. Su, X. Liu, Z. Tan, S. Escalera, J. Xing, Y . Lianget al., “Contrastive context-aware learning for 3d high- fidelity mask face presentation attack detection,”IEEE Transactions on Information Forensics and Security, vol. 17, pp. 2497–2507, 2022

  2. [4]

    Face liveness detection based on texture and frequency analyses,

    G. Kim, S. Eum, J. K. Suhr, D. I. Kim, K. R. Park, and J. Kim, “Face liveness detection based on texture and frequency analyses,” in2012 5th IAPR international conference on biometrics (ICB). IEEE, 2012, pp. 67–72

  3. [5]

    Face liveness detection with component dependent descriptor,

    J. Yang, Z. Lei, S. Liao, and S. Z. Li, “Face liveness detection with component dependent descriptor,” in2013 international conference on biometrics (ICB). IEEE, 2013, pp. 1–6

  4. [6]

    Face liveness detection by learning multispectral reflectance distributions,

    Z. Zhang, D. Yi, Z. Lei, and S. Z. Li, “Face liveness detection by learning multispectral reflectance distributions,” in2011 IEEE International Conference on Automatic Face & Gesture Recognition (FG). IEEE, 2011, pp. 436–441

  5. [7]

    Flip: Cross-domain face anti-spoofing with language guidance,

    K. Srivatsan, M. Naseer, and K. Nandakumar, “Flip: Cross-domain face anti-spoofing with language guidance,” inProceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), October 2023, pp. 19 685–19 696

  6. [8]

    Cfpl-fas: Class free prompt learning for generalizable face anti- spoofing,

    A. Liu, S. Xue, J. Gan, J. Wan, Y . Liang, J. Deng, S. Escalera, and Z. Lei, “Cfpl-fas: Class free prompt learning for generalizable face anti- spoofing,” inProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 222–232

  7. [9]

    Instance-aware domain generalization for face anti-spoofing,

    Q. Zhou, K.-Y . Zhang, T. Yao, X. Lu, R. Yi, S. Ding, and L. Ma, “Instance-aware domain generalization for face anti-spoofing,” inPro- ceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2023, pp. 20 453–20 463

  8. [10]

    Gradient alignment for cross-domain face anti- spoofing,

    B. M. Le and S. S. Woo, “Gradient alignment for cross-domain face anti- spoofing,” inProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 188–199

Show all 82 references
  1. [11]

    Deep reconstruction-classification networks for unsupervised domain adap- tation,

    M. Ghifary, W. B. Kleijn, M. Zhang, D. Balduzzi, and W. Li, “Deep reconstruction-classification networks for unsupervised domain adap- tation,” inComputer Vision–ECCV 2016: 14th European Conference, Amsterdam, The Netherlands, October 11–14, 2016, Proceedings, Part IV 14. Spri...

  2. [12]

    Learning transferable visual models from natural language supervision,

    A. Radford, J. W. Kim, C. Hallacy, A. Ramesh, G. Goh, S. Agarwal, G. Sastry, A. Askell, P. Mishkin, J. Clarket al., “Learning transferable visual models from natural language supervision,” inInternational conference on machine learning. PmLR, 2021, pp. 8748–8763

  3. [13]

    Grad-cam: Visual explanations from deep networks via gradient-based localization,

    R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-cam: Visual explanations from deep networks via gradient-based localization,” inProceedings of the IEEE international conference on computer vision, 2017, pp. 618–626

  4. [14]

    Towards automatic concept-based explanations,

    A. Ghorbani, J. Wexler, J. Y . Zou, and B. Kim, “Towards automatic concept-based explanations,”Advances in neural information processing systems, vol. 32, 2019

  5. [15]

    Craft: Concept recursive activation factor- ization for explainability,

    T. Fel, A. Picard, L. Bethune, T. Boissin, D. Vigouroux, J. Colin, R. Cad `ene, and T. Serre, “Craft: Concept recursive activation factor- ization for explainability,” inProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 2711–2721

  6. [16]

    Lbp- top based countermeasure against face spoofing attacks,

    T. de Freitas Pereira, A. Anjos, J. M. De Martino, and S. Marcel, “Lbp- top based countermeasure against face spoofing attacks,” inAsian conference on computer vision. Springer, 2012, pp. 121–132

  7. [17]

    Face spoofing detec- tion using colour texture analysis,

    Z. Boulkenafet, J. Komulainen, and A. Hadid, “Face spoofing detec- tion using colour texture analysis,”IEEE Transactions on Information Forensics and Security, vol. 11, no. 8, pp. 1818–1830, 2016

  8. [18]

    Context based face anti- spoofing,

    J. Komulainen, A. Hadid, and M. Pietik ¨ainen, “Context based face anti- spoofing,” in2013 IEEE sixth international conference on biometrics: theory, applications and systems (BTAS). IEEE, 2013, pp. 1–8

  9. [19]

    Secure face unlock: Spoof detection on smartphones,

    K. Patel, H. Han, and A. K. Jain, “Secure face unlock: Spoof detection on smartphones,”IEEE transactions on information forensics and security, vol. 11, no. 10, pp. 2268–2283, 2016

  10. [20]

    Learning deep models for face anti- spoofing: Binary or auxiliary supervision,

    Y . Liu, A. Jourabloo, and X. Liu, “Learning deep models for face anti- spoofing: Binary or auxiliary supervision,” inProceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 389– 398. JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021 13

  11. [21]

    Searching central difference convolutional networks for face anti- spoofing,

    Z. Yu, C. Zhao, Z. Wang, Y . Qin, Z. Su, X. Li, F. Zhou, and G. Zhao, “Searching central difference convolutional networks for face anti- spoofing,” inProceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2020, pp. 5295–5305

  12. [22]

    Deep spatial gradient and temporal depth learning for face anti-spoofing,

    Z. Wang, Z. Yu, C. Zhao, X. Zhu, Y . Qin, Q. Zhou, F. Zhou, and Z. Lei, “Deep spatial gradient and temporal depth learning for face anti-spoofing,” inProceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2020, pp. 5042–5051

  13. [23]

    Face anti-spoofing using transformers with relation-aware mechanism,

    Z. Wang, Q. Wang, W. Deng, and G. Guo, “Face anti-spoofing using transformers with relation-aware mechanism,”IEEE Transactions on Biometrics, Behavior, and Identity Science, vol. 4, no. 3, pp. 439–450, 2022

  14. [24]

    On the effectiveness of vision transformers for zero-shot face anti-spoofing,

    A. George and S. Marcel, “On the effectiveness of vision transformers for zero-shot face anti-spoofing,” in2021 IEEE international joint conference on biometrics (IJCB). IEEE, 2021, pp. 1–8

  15. [26]

    Unsupervised adversarial domain adaptation for cross-domain face presentation attack detection,

    G. Wang, H. Han, S. Shan, and X. Chen, “Unsupervised adversarial domain adaptation for cross-domain face presentation attack detection,” IEEE Transactions on Information Forensics and Security, vol. 16, pp. 56–69, 2020

  16. [27]

    Self-domain adaptation for face anti-spoofing,

    J. Wang, J. Zhang, Y . Bian, Y . Cai, C. Wang, and S. Pu, “Self-domain adaptation for face anti-spoofing,” inProceedings of the AAAI conference on artificial intelligence, vol. 35, no. 4, 2021, pp. 2746–2754

  17. [28]

    Towards unsupervised domain generalization for face anti-spoofing,

    Y . Liu, Y . Chen, M. Gou, C.-T. Huang, Y . Wang, W. Dai, and H. Xiong, “Towards unsupervised domain generalization for face anti-spoofing,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, 2023, pp. 20 654–20 664

  18. [29]

    Dual reweighting domain generalization for face presentation attack detection,

    S. Liu, K.-Y . Zhang, T. Yao, K. Sheng, S. Ding, Y . Tai, J. Li, Y . Xie, and L. Ma, “Dual reweighting domain generalization for face presentation attack detection,”arXiv preprint arXiv:2106.16128, 2021

  19. [30]

    Regularized fine-grained meta face anti-spoofing,

    R. Shao, X. Lan, and P. C. Yuen, “Regularized fine-grained meta face anti-spoofing,” inProceedings of the AAAI conference on artificial intelligence, vol. 34, no. 07, 2020, pp. 11 974–11 981

  20. [31]

    Test-time domain generalization for face anti-spoofing,

    Q. Zhou, K.-Y . Zhang, T. Yao, X. Lu, S. Ding, and L. Ma, “Test-time domain generalization for face anti-spoofing,” inProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 175–187

  21. [32]

    Rethinking general- izable face anti-spoofing via hierarchical prototype-guided distribution refinement in hyperbolic space,

    C. Hu, K.-Y . Zhang, T. Yao, S. Ding, and L. Ma, “Rethinking general- izable face anti-spoofing via hierarchical prototype-guided distribution refinement in hyperbolic space,” inProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 1032–1041

  22. [33]

    Exploiting temporal and depth information for multi-frame face anti- spoofing,

    Z. Wang, C. Zhao, Y . Qin, Q. Zhou, G. Qi, J. Wan, and Z. Lei, “Exploiting temporal and depth information for multi-frame face anti- spoofing,”arXiv preprint arXiv:1811.05118, 2018

  23. [34]

    Face anti-spoofing via robust auxiliary estimation and discriminative feature learning,

    P.-K. Huang, M.-C. Chin, and C.-T. Hsu, “Face anti-spoofing via robust auxiliary estimation and discriminative feature learning,” inAsian Conference on Pattern Recognition. Springer, 2021, pp. 443–458

  24. [35]

    Learning multiple explainable and generalizable cues for face anti-spoofing,

    Y . Bian, P. Zhang, J. Wang, C. Wang, and S. Pu, “Learning multiple explainable and generalizable cues for face anti-spoofing,” inICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 2022, pp. 2310–2314

  25. [36]

    An attention-guided framework for explainable biometric presentation attack detection,

    S. Pan, S. Hoque, and F. Deravi, “An attention-guided framework for explainable biometric presentation attack detection,”Sensors, vol. 22, no. 9, p. 3365, 2022

  26. [37]

    Are foundation models all you need for zero-shot face presentation attack detection?

    L. J. Gonzalez-Soler, J. E. Tapia, and C. Busch, “Are foundation models all you need for zero-shot face presentation attack detection?” in2025 IEEE 19th International Conference on Automatic Face and Gesture Recognition (FG). IEEE, 2025, pp. 1–10

  27. [38]

    Foundpad: Foundation models reloaded for face presentation attack detection,

    G. Ozgur, E. Caldeira, T. Chettaoui, F. Boutros, R. Ramachandra, and N. Damer, “Foundpad: Foundation models reloaded for face presentation attack detection,” inProceedings of the Winter Conference on Applica- tions of Computer Vision, 2025, pp. 745–755

  28. [39]

    Style-conditional prompt token learning for generalizable face anti- spoofing,

    J. Guo, H. Liu, Y . Luo, X. Hu, H. Zou, Y . Zhang, H. Liu, and B. Zhao, “Style-conditional prompt token learning for generalizable face anti- spoofing,” inProceedings of the 32nd ACM International Conference on Multimedia, 2024, pp. 994–1003

  29. [40]

    Domain generalization for face anti-spoofing via content- aware composite prompt engineering,

    J. Guo, A. Liu, Y . Diao, J. Zhang, H. Ma, B. Zhao, R. Hong, and M. Wang, “Domain generalization for face anti-spoofing via content- aware composite prompt engineering,”IEEE Transactions on Multime- dia, 2025

  30. [41]

    Tf-fas: twofold-element fine-grained semantic guidance for generaliz- able face anti-spoofing,

    X. Wang, K.-Y . Zhang, T. Yao, Q. Zhou, S. Ding, P. Dai, and R. Ji, “Tf-fas: twofold-element fine-grained semantic guidance for generaliz- able face anti-spoofing,” inEuropean Conference on Computer Vision. Springer, 2024, pp. 148–168

  31. [42]

    Dgpdl: Domain-guided prompt distribution learning for generalizable face anti-spoofing,

    A. Liu, X. Lin, R. Zhi, Y . Liang, X. Zhu, Z. Cai, J. Wan, S. Escalera, and Z. Lei, “Dgpdl: Domain-guided prompt distribution learning for generalizable face anti-spoofing,”IEEE Transactions on Pattern Analysis and Machine Intelligence, 2026

  32. [43]

    Icpe-fas: Instance and category prompts engineering for generalizable face anti-spoofing: A. liu et al

    A. Liu, X. Lin, H. Ma, X. Yu, J. Guo, Z. Yu, J. Wan, Z. Cai, Z. Lei, and Y . Liang, “Icpe-fas: Instance and category prompts engineering for generalizable face anti-spoofing: A. liu et al.”International Journal of Computer Vision, vol. 134, no. 6, p. 292, 2026

  33. [44]

    Ablation-cam: Visual explanations for deep convolutional network via gradient-free localization,

    H. G. Ramaswamyet al., “Ablation-cam: Visual explanations for deep convolutional network via gradient-free localization,” inproceedings of the IEEE/CVF winter conference on applications of computer vision, 2020, pp. 983–991

  34. [45]

    Grad-cam++: Generalized gradient-based visual explanations for deep convolutional networks,

    A. Chattopadhay, A. Sarkar, P. Howlader, and V . N. Balasubramanian, “Grad-cam++: Generalized gradient-based visual explanations for deep convolutional networks,” in2018 IEEE winter conference on applica- tions of computer vision (WACV). IEEE, 2018, pp. 839–847

  35. [46]

    On pixel-wise explanations for non-linear classifier deci- sions by layer-wise relevance propagation,

    S. Bach, A. Binder, G. Montavon, F. Klauschen, K.-R. M ¨uller, and W. Samek, “On pixel-wise explanations for non-linear classifier deci- sions by layer-wise relevance propagation,”PloS one, vol. 10, no. 7, p. e0130140, 2015

  36. [47]

    Rise: Randomized input sampling for explanation of black- box models,

    V . Petsiuk, “Rise: Randomized input sampling for explanation of black- box models,”arXiv preprint arXiv:1806.07421, 2018

  37. [48]

    Interpretability beyond feature attribution: Quantitative testing with concept activation vectors (tcav),

    B. Kim, M. Wattenberg, J. Gilmer, C. Cai, J. Wexler, F. Viegas et al., “Interpretability beyond feature attribution: Quantitative testing with concept activation vectors (tcav),” inInternational conference on machine learning. PMLR, 2018, pp. 2668–2677

  38. [49]

    Convex and semi-nonnegative ma- trix factorizations,

    C. H. Ding, T. Li, and M. I. Jordan, “Convex and semi-nonnegative ma- trix factorizations,”IEEE transactions on pattern analysis and machine intelligence, vol. 32, no. 1, pp. 45–55, 2008

  39. [50]

    A holistic approach to unifying automatic concept extraction and concept importance estimation,

    T. Fel, V . Boutin, L. B ´ethune, R. Cad `ene, M. Moayeri, L. And ´eol, M. Chalvidal, and T. Serre, “A holistic approach to unifying automatic concept extraction and concept importance estimation,”Advances in Neural Information Processing Systems, vol. 36, pp. 54 805–54 818, 2023

  40. [51]

    Attention is all you need,

    A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. Kaiser, and I. Polosukhin, “Attention is all you need,” inProceedings of the 31st International Conference on Neural Information Processing Systems, ser. NIPS’17. Red Hook, NY , USA: Curran Associates I...

  41. [52]

    The hungarian method for the assignment problem,

    H. W. Kuhn, “The hungarian method for the assignment problem,”Naval research logistics quarterly, vol. 2, no. 1-2, pp. 83–97, 1955

  42. [53]

    Celeba- spoof: Large-scale face anti-spoofing dataset with rich annotations,

    Y . Zhang, Z. Yin, Y . Li, G. Yin, J. Yan, J. Shao, and Z. Liu, “Celeba- spoof: Large-scale face anti-spoofing dataset with rich annotations,” in Computer Vision–ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part XII 16. Springer, 2020, pp. 70–85

  43. [54]

    Syn- thesizing the preferred inputs for neurons in neural networks via deep generator networks,

    A. Nguyen, A. Dosovitskiy, J. Yosinski, T. Brox, and J. Clune, “Syn- thesizing the preferred inputs for neurons in neural networks via deep generator networks,”Advances in neural information processing systems, vol. 29, 2016

  44. [55]

    Feature generation and hypothesis verification for reliable face anti-spoofing,

    S. Liu, S. Lu, H. Xu, J. Yang, S. Ding, and L. Ma, “Feature generation and hypothesis verification for reliable face anti-spoofing,” inProceed- ings of the AAAI Conference on Artificial Intelligence, vol. 36, no. 2, 2022, pp. 1782–1791

  45. [56]

    Generative domain adaptation for face anti-spoofing,

    Q. Zhou, K.-Y . Zhang, T. Yao, R. Yi, K. Sheng, S. Ding, and L. Ma, “Generative domain adaptation for face anti-spoofing,” inEuropean conference on computer vision. Springer, 2022, pp. 335–356

  46. [57]

    Domain generalization via shuffled style assembly for face anti-spoofing,

    Z. Wang, Z. Wang, Z. Yu, W. Deng, J. Li, T. Gao, and Z. Wang, “Domain generalization via shuffled style assembly for face anti-spoofing,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2022, pp. 4123–4133

  47. [58]

    Rethinking domain generalization for face anti-spoofing: Separability and alignment,

    Y . Sun, Y . Liu, X. Liu, Y . Li, and W.-S. Chu, “Rethinking domain generalization for face anti-spoofing: Separability and alignment,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2023, pp. 24 563–24 574

  48. [59]

    Domain invariant vision transformer learning for face anti-spoofing,

    C.-H. Liao, W.-C. Chen, H.-T. Liu, Y .-R. Yeh, M.-C. Hu, and C.-S. Chen, “Domain invariant vision transformer learning for face anti-spoofing,” inProceedings of the IEEE/CVF winter conference on applications of computer vision, 2023, pp. 6098–6107

  49. [60]

    Learning to prompt for vision-language models,

    K. Zhou, J. Yang, C. C. Loy, and Z. Liu, “Learning to prompt for vision-language models,”Int. J. Comput. Vision, vol. 130, no. 9, p. 2337–2348, Sep. 2022. [Online]. Available: https://doi.org/10.1007/ s11263-022-01653-1 JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021 14

  50. [61]

    Conditional prompt learning for vision-language models,

    ——, “Conditional prompt learning for vision-language models,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2022, pp. 16 816–16 825

  51. [62]

    Adaptive transformers for robust few-shot cross- domain face anti-spoofing,

    H.-P. Huang, D. Sun, Y . Liu, W.-S. Chu, T. Xiao, J. Yuan, H. Adam, and M.-H. Yang, “Adaptive transformers for robust few-shot cross- domain face anti-spoofing,” inEuropean conference on computer vision. Springer, 2022, pp. 37–54

  52. [63]

    Fine-grained prompt learning for face anti-spoofing,

    X. Hu, H. Liu, H. Yuan, Z. Fu, Y . Luo, N. Zhang, H. Zou, J. Gan, and Y . Zhang, “Fine-grained prompt learning for face anti-spoofing,” in Proceedings of the 32nd ACM International Conference on Multimedia, 2024, pp. 7619–7628

  53. [64]

    Interpretable face anti-spoofing: Enhancing gener- alization with multimodal large language models,

    G. Zhang, K. Wang, H. Yue, A. Liu, G. Zhang, K. Yao, E. Ding, and J. Wang, “Interpretable face anti-spoofing: Enhancing gener- alization with multimodal large language models,”arXiv preprint arXiv:2501.01720, 2025

  54. [65]

    Information Tech- nology - Biometric presentation attack detection - Part 3: Testing and Reporting, International Organization for Standardization, 2023

    ISO/IEC JTC1 SC37 Biometrics,ISO/IEC 30107-3. Information Tech- nology - Biometric presentation attack detection - Part 3: Testing and Reporting, International Organization for Standardization, 2023

  55. [66]

    Face spoof detection with image distortion analysis,

    D. Wen, H. Han, and A. K. Jain, “Face spoof detection with image distortion analysis,”IEEE Transactions on Information Forensics and Security, vol. 10, no. 4, pp. 746–761, 2015

  56. [67]

    A face anti- spoofing database with diverse attacks,

    Z. Zhang, J. Yan, S. Liu, Z. Lei, D. Yi, and S. Z. Li, “A face anti- spoofing database with diverse attacks,” in2012 5th IAPR international conference on Biometrics (ICB). IEEE, 2012, pp. 26–31

  57. [68]

    On the effectiveness of local binary patterns in face anti-spoofing,

    I. Chingovska, A. Anjos, and S. Marcel, “On the effectiveness of local binary patterns in face anti-spoofing,” in2012 BIOSIG-proceedings of the international conference of biometrics special interest group (BIOSIG). IEEE, 2012, pp. 1–7

  58. [69]

    Oulu-npu: A mobile face presentation attack database with real-world variations,

    Z. Boulkenafet, J. Komulainen, L. Li, X. Feng, and A. Hadid, “Oulu-npu: A mobile face presentation attack database with real-world variations,” in2017 12th IEEE international conference on automatic face & gesture recognition (FG 2017). IEEE, 2017, pp. 612–618

  59. [70]

    Casia-surf: A large-scale multi-modal benchmark for face anti-spoofing,

    S. Zhang, A. Liu, J. Wan, Y . Liang, G. Guo, S. Escalera, H. J. Escalante, and S. Z. Li, “Casia-surf: A large-scale multi-modal benchmark for face anti-spoofing,”IEEE Transactions on Biometrics, Behavior, and Identity Science, vol. 2, no. 2, pp. 182–193, 2020

  60. [71]

    Casia-surf cefa: A benchmark for multi-modal cross-ethnicity face anti-spoofing,

    A. Liu, Z. Tan, J. Wan, S. Escalera, G. Guo, and S. Z. Li, “Casia-surf cefa: A benchmark for multi-modal cross-ethnicity face anti-spoofing,” inProceedings of the IEEE/CVF winter conference on applications of computer vision, 2021, pp. 1179–1187

  61. [72]

    Biometric face presentation attack detection with multi- channel convolutional neural network,

    A. George, Z. Mostaani, D. Geissenbuhler, O. Nikisins, A. Anjos, and S. Marcel, “Biometric face presentation attack detection with multi- channel convolutional neural network,”IEEE transactions on informa- tion forensics and security, vol. 15, pp. 42–55, 2019

  62. [73]

    Multi-domain learning for updating face anti-spoofing models,

    X. Guo, Y . Liu, A. Jain, and X. Liu, “Multi-domain learning for updating face anti-spoofing models,” inEuropean conference on computer vision. Springer, 2022, pp. 230–249

  63. [74]

    Adversarial discrim- inative domain adaptation,

    E. Tzeng, J. Hoffman, K. Saenko, and T. Darrell, “Adversarial discrim- inative domain adaptation,” inProceedings of the IEEE conference on computer vision and pattern recognition, 2017, pp. 7167–7176

  64. [75]

    Duplex generative adversarial network for unsupervised domain adaptation,

    L. Hu, M. Kan, S. Shan, and X. Chen, “Duplex generative adversarial network for unsupervised domain adaptation,” inProceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 1498–1507

  65. [76]

    Unsuper- vised domain adaptation for face anti-spoofing,

    H. Li, W. Li, H. Cao, S. Wang, F. Huang, and A. C. Kot, “Unsuper- vised domain adaptation for face anti-spoofing,”IEEE Transactions on Information Forensics and Security, vol. 13, no. 7, pp. 1794–1809, 2018

  66. [77]

    Unified unsupervised and semi-supervised domain adaptation network for cross-scenario face anti- spoofing,

    Y . Jia, J. Zhang, S. Shan, and X. Chen, “Unified unsupervised and semi-supervised domain adaptation network for cross-scenario face anti- spoofing,”Pattern Recognition, vol. 115, p. 107888, 2021

  67. [78]

    Cyclically disentangled feature translation for face anti-spoofing,

    H. Yue, K. Wang, G. Zhang, H. Feng, J. Han, E. Ding, and J. Wang, “Cyclically disentangled feature translation for face anti-spoofing,” in Proceedings of the AAAI conference on artificial intelligence, vol. 37, no. 3, 2023, pp. 3358–3366

  68. [79]

    Single-side domain generaliza- tion for face anti-spoofing,

    Y . Jia, J. Zhang, S. Shan, and X. Chen, “Single-side domain generaliza- tion for face anti-spoofing,” inProceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2020, pp. 8484–8493

  69. [80]

    Learning meta pattern for face anti-spoofing,

    R. Cai, Z. Li, R. Wan, H. Li, Y . Hu, and A. C. Kot, “Learning meta pattern for face anti-spoofing,”IEEE Transactions on Information Forensics and Security, vol. 17, pp. 1201–1213, 2022

  70. [81]

    Causal interven- tion for generalizable face anti-spoofing,

    Y . Liu, Y . Chen, W. Dai, C. Li, J. Zou, and H. Xiong, “Causal interven- tion for generalizable face anti-spoofing,” in2022 IEEE International Conference on Multimedia and Expo (ICME). IEEE, 2022, pp. 01–06

  71. [82]

    Domain- generalized face anti-spoofing with unknown attacks,

    Z.-W. Hong, Y .-C. Lin, H.-T. Liu, Y .-R. Yeh, and C.-S. Chen, “Domain- generalized face anti-spoofing with unknown attacks,” in2023 IEEE International Conference on Image Processing (ICIP). IEEE, 2023, pp. 820–824

  72. [83]

    Bottom-up domain prompt tuning for generalized face anti-spoofing,

    S.-Q. Liu, Q. Wang, and P. C. Yuen, “Bottom-up domain prompt tuning for generalized face anti-spoofing,” inEuropean Conference on Computer Vision. Springer, 2024, pp. 170–187

  73. [84]

    From intuition to investigation: A tool-augmented reasoning mllm framework for generalizable face anti- spoofing,

    H. Zhang, K. Wang, G. Zhang, H. Yue, Z. Tan, S. Peng, T. Zhang, X. Tan, K. Chen, W. Heet al., “From intuition to investigation: A tool-augmented reasoning mllm framework for generalizable face anti- spoofing,” inProceedings of the IEEE/CVF Conference on Computer Vision and Pat...

  74. [85]

    Visualizing data using t-sne

    L. Van der Maaten and G. Hinton, “Visualizing data using t-sne.”Journal of machine learning research, vol. 9, no. 11, 2008

Pith tools

Reviewed July 3, 2026 · model on record in the stance chip above.