EP4690141A1 - Image morphing detection - Google Patents

Image morphing detection

Info

Publication number
EP4690141A1
EP4690141A1 EP24743354.3A EP24743354A EP4690141A1 EP 4690141 A1 EP4690141 A1 EP 4690141A1 EP 24743354 A EP24743354 A EP 24743354A EP 4690141 A1 EP4690141 A1 EP 4690141A1
Authority
EP
European Patent Office
Prior art keywords
image
user device
location information
locations
landmarks
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP24743354.3A
Other languages
German (de)
French (fr)
Inventor
Andreas Wilke
Oliver Muth
Lars SIMON
Holger Eble
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Bundesdruckerei GmbH
Original Assignee
Bundesdruckerei GmbH
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Bundesdruckerei GmbH filed Critical Bundesdruckerei GmbH
Publication of EP4690141A1 publication Critical patent/EP4690141A1/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/10Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
    • G06V40/16Human faces, e.g. facial parts, sketches or expressions
    • G06V40/172Classification, e.g. identification
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N3/00Computing arrangements based on biological models
    • G06N3/02Neural networks
    • G06N3/04Architecture, e.g. interconnection topology
    • G06N3/045Combinations of networks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N3/00Computing arrangements based on biological models
    • G06N3/02Neural networks
    • G06N3/08Learning methods
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V10/00Arrangements for image or video recognition or understanding
    • G06V10/70Arrangements for image or video recognition or understanding using pattern recognition or machine learning
    • G06V10/764Arrangements for image or video recognition or understanding using pattern recognition or machine learning using classification, e.g. of video objects
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V10/00Arrangements for image or video recognition or understanding
    • G06V10/70Arrangements for image or video recognition or understanding using pattern recognition or machine learning
    • G06V10/77Processing image or video features in feature spaces; using data integration or data reduction, e.g. principal component analysis [PCA] or independent component analysis [ICA] or self-organising maps [SOM]; Blind source separation
    • G06V10/7715Feature extraction, e.g. by transforming the feature space, e.g. multi-dimensional scaling [MDS]; Mappings, e.g. subspace methods
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V10/00Arrangements for image or video recognition or understanding
    • G06V10/70Arrangements for image or video recognition or understanding using pattern recognition or machine learning
    • G06V10/82Arrangements for image or video recognition or understanding using pattern recognition or machine learning using neural networks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V10/00Arrangements for image or video recognition or understanding
    • G06V10/94Hardware or software architectures specially adapted for image or video understanding
    • G06V10/95Hardware or software architectures specially adapted for image or video understanding structured as a network, e.g. client-server architectures
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/10Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
    • G06V40/16Human faces, e.g. facial parts, sketches or expressions
    • G06V40/168Feature extraction; Face representation
    • G06V40/171Local features and components; Facial parts ; Occluding parts, e.g. glasses; Geometrical relationships
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N10/00Quantum computing, i.e. information processing based on quantum-mechanical phenomena
    • G06N10/60Quantum algorithms, e.g. based on quantum optimisation, quantum Fourier or Hadamard transforms
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V10/00Arrangements for image or video recognition or understanding
    • G06V10/70Arrangements for image or video recognition or understanding using pattern recognition or machine learning
    • G06V10/77Processing image or video features in feature spaces; using data integration or data reduction, e.g. principal component analysis [PCA] or independent component analysis [ICA] or self-organising maps [SOM]; Blind source separation
    • G06V10/774Generating sets of training patterns; Bootstrap methods, e.g. bagging or boosting
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/40Spoof detection, e.g. liveness detection

Definitions

  • the disclosure relates to training image morphing, and particularly to a method for image morphing detection.
  • Morphing may be a special effect in motion pictures and animations that morphs one training image into another through a seamless transition.
  • Computer software may be used to create morphed training images.
  • DAS Document “Towards Detection of Morphed Face Training images in Electronic Travel Documents” published in 201813th IAPR International Workshop on Document Analysis Systems (DAS) discloses automated morph detection algorithms based on general purpose pattern recognition algorithms.
  • Example embodiments provide a method (also referred to as first morphing detection method) for morphed image detection, the method comprising: receiving by a user device an image of an object; identifying by the user device a set of landmarks of the object in accordance with a landmark pattern; determining by the user device locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending by the user device a location information to a remote server, the location information indicating the set of locations, the remote server comprising a trained machine learning model; receiving the location information by the remote server; inputting by the remote server the location information to the trained machine learning model; receiving by the remote server an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image; sending the output by the remote server to the user device; receiving the output by the user device; using by the user device the output for rejecting or accepting the received image.
  • Example embodiments provide a method (also referred to as second morphing detection method) for morphed image detection, the method comprising: receiving by a user device an image of an object; sending by the user device the image to a remote server, the remote server comprising a training machine learning model; receiving the image by the remote server; identifying by the remote server a set of landmarks of the object in accordance with a landmark pattern; determining by the remote server locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting by the remote server a location information to the trained machine learning model, the location information indicating the set of locations; receiving by the remote server an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image; sending the output by the remote server to the user device; receiving the output by the user device; using by the user device the output for rejecting or accepting the received image.
  • a method also referred to as second morphing detection method for morphed image detection
  • Example embodiments provide a morphing detection system comprising a server and user device, the user device and the server being configured to perform the first morphing detection method or the second morphing detection method.
  • Example embodiments provide a computer program comprising instructions which, when the program is executed by a user device and a server, cause the user device and the server to perform the first morphing detection method or the second morphing detection method.
  • Example embodiments provide a method for morphed image detection comprising: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to the trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device.
  • Example embodiments provide a server being configured for: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to the trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device.
  • Example embodiments provide a computer program comprising instructions which, when the program is executed by a server, cause the server to perform at least the following: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to the trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device.
  • Example embodiments provide a method for morphed image detection, the method comprising: receiving by a user device an image of an object; identifying by the user device a set of landmarks of the object in accordance with a landmark pattern; determining by the user device locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending by the user device a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non-morphed image; using the output for rejecting or accepting the received image.
  • Example embodiments provide a user device for morphed image detection, the user device being configured for: receiving an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non-morphed image; using the output for rejecting or accepting the received image.
  • Example embodiments provide a computer program comprising instructions for causing a user device for performing at least the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non-morphed image; using the output for rejecting or accepting the received image.
  • Example embodiments provide a method for morphed image detection.
  • the method comprises: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device.
  • Example embodiments provide a server for morphed image detection.
  • the server is configured for: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device.
  • Example embodiments provide a computer program comprising instructions for causing a server for performing at least the following: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device.
  • Example embodiments provide a method (referred to as training data generation method) of generating a training dataset for training a machine learning model for morphed image detection.
  • the method comprises: receiving at least one landmark pattern; repeatedly performing the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with the received landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; and adding an entry to the training dataset, the entry indicating the set of locations and a label, wherein the label indicates whether the received image is a real image or morphed image.
  • Example embodiments provide a computer system of generating a training dataset for training a machine learning model for morphed image detection.
  • the computer system is configured for: receiving at least one landmark pattern; repeatedly performing the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with the received landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; and adding an entry to the training dataset, the entry indicating the set of locations and a label, wherein the label indicates whether the received image is a real image or morphed image.
  • Example embodiments provide a computer program comprising instructions for causing a computer system for performing at least the following: receiving at least one landmark pattern; repeatedly performing the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with the received landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; and adding an entry to the training dataset, the entry indicating the set of locations and a label, wherein the label indicates whether the received image is a real image or morphed image.
  • Example embodiments provide a computer implemented data structure comprising training data for a morphed image detection model, the data structure comprising entries, wherein the entry comprises location information indicating a set of landmark locations of an imaged object, and a label indicating a real image or morphed image, the landmark locations being relative locations.
  • Fig.1 is a schematic diagram of a morphing detection system in accordance with an example of the present subject matter.
  • Fig.2A is a diagram illustrating a machine learning model in accordance with an example of the present subject matter.
  • Fig.2B is a diagram illustrating a machine learning model in accordance with an example of the present subject matter.
  • Fig.3 is a signaling diagram illustrating a method for morphing detection in accordance with an example of the present subject matter.
  • Fig.4 is a signaling diagram illustrating a method for morphing detection in accordance with an example of the present subject matter.
  • Fig.5 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter.
  • Fig.5 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter.
  • FIG. 6A is a diagram illustrating a method for determining locations of landmarks in an image of a human face in accordance with an example of the present subject matter.
  • Fig. 6B is a diagram illustrating a method for determining locations of landmarks in an image of a human eyes in accordance with an example of the present subject matter.
  • Fig.7 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter.
  • Fig.8 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter.
  • Fig.32 Fig.
  • FIG. 9 is a flowchart of a method of determining landmarks of an imaged object in accordance with an example of the present subject matter.
  • Fig. 10 is a diagram of a data structure representing the training dataset generated in accordance with an example of the present subject matter.
  • Fig. 11 is a block diagram of an exemplary computer system for implementing at least part of the present method in accordance with an example of the present subject matter.
  • Fig.12 is a flowchart of a method for training a classical machine learning model in accordance with an example of the present subject matter.
  • Fig.13 is a flowchart of a method for training a quantum machine learning model in accordance with an example of the present subject matter.
  • Fig. 10 is a diagram of a data structure representing the training dataset generated in accordance with an example of the present subject matter.
  • Fig. 11 is a block diagram of an exemplary computer system for implementing at least part of the present method in accordance with an example of the present subject matter.
  • FIG. 14 is a flowchart of a method for training a hybrid classical-quantum machine learning model in accordance with an example of the present subject matter.
  • Fig.15 is a flowchart of a method for automatic morphed image detection in accordance with an example of the present subject matter.
  • DETAILED DESCRIPTION [0039] In the following description, for purposes of explanation and not limitation, specific details are set forth such as particular architectures, interfaces, techniques, etc., in order to provide a thorough understanding of the examples. However, it will be apparent to those skilled in the art that the disclosed subject matter may be practiced in other illustrative examples that depart from these specific details.
  • Authentication may be a process for verifying the identity of persons. This may, for example, enable to keep unauthorized persons from accessing sensitive information or services. For example, based on the authentication result of a user, access control signals may be generated to enable the user to access controlled services or controlled areas.
  • the authentication may be performed using an image of the user. For example, an automated border control system or eGate may use the image to verify the user's identity. After the user's identity is verified, a physical barrier such as a gate opens to permit passage. The image may provide a visual representation of the user.
  • the image of the user may be obtained by imaging the user’s face e.g., using a camera.
  • the image of the user may be a reproduced version that is captured from an identity token of the user.
  • the image may be stored in a memory as a digital image.
  • the identity token may, for example, be an identification (ID) card, visa, driver's license, vehicle registration document, health card, company ID card, bank card, or another ID document which carries an identity-linked field comprising a photo of the user.
  • the identity token may be provided in the form of an ID application installed on a user's mobile portable terminal. In this case, the user's image may be provided, for example, on a display of the user's mobile portable terminal.
  • the images may be morphed.
  • Morphing refers to the changing of one image to obtain a morphed image.
  • the morphing may, for example, modify an image of a given object such that the resulting object resembles the given object.
  • the morphing may be misused to, for example, create a double–identity face image, a double–identity fingerprint or a double–identity iris, or to perform cyberattacks by creating hoax images.
  • a misuse of the morphing can enable two individuals to use one identity document.
  • a fake fingerprint may be created using morphing so that it can be used to identify two different fingers.
  • the detection of such morphed images may prevent cyberattacks and fake identities.
  • Different techniques may be used to detect morphed images.
  • machine learning models may be used to detect morphed images.
  • Inference phase The present subject matter may detect morphed images by inferring the machine learning model. This may enable a secure execution of tasks which are based on imaged objects, the tasks being, for example, authentication tasks or access control tasks.
  • the inference image may be an image of a human face, wherein the first morphing detection method or the second morphing detection method may be used for passport image verification during the passport application process or during check of the passports.
  • the first morphing detection method may be advantageous as it may enable a full processing of the image on the server side. This may enable to use user devices with less computing power.
  • the second morphing detection method may save network resources e.g., bandwidth, by transmitting the location information instead of the whole image.
  • the user device and the server may be provided.
  • the user device may be a device that is operable by a human operator to originate or receive user communication data including, for example, text and images.
  • the user device may include, but is not limited to, a cellular telephone, smartphone, personal computer, desktop computer, laptop or PDA.
  • the user device may, for example, be configured to communicate with the server using one or more networks.
  • the user device may, for example, be configured to communicate wirelessly with the server using one or more networks.
  • the network may, for example, comprise a mobile network, a local area network (LAN), a general wide area network (WAN), the Internet or a combination thereof.
  • the server may thus be referred to as remote server.
  • the remote server (also referred to as server computer) may refer to a computer system.
  • the remote server may comprise a quantum processing unit (QPU).
  • the quantum processing unit may be a component that may be used to perform quantum computations by operating one or more qubits.
  • the quantum processing unit may, for example, be a chip that contains a number of (interconnected) qubits.
  • the server may further comprise a classical processing component.
  • the classical processing component may, for example, control the qubit(s) to perform quantum operations on the qubits in order to execute the machine learning model.
  • the classical processing component may, for example, comprise a CPU, a memory and a FPGA.
  • the classical processing component may, for example, generate and provide as output one or more control signals to the qubits in the quantum processing unit.
  • the control signals may, for example, comprise electromagnetic signals, electrical signals, magnetic signals, optical signals (such as laser pulses), or a combination thereof.
  • the user device may comprise an application that when executed may display a user interface on the user device.
  • the user interface may, for example, comprise one or more interface elements that enable to upload the inference image, wherein the receiving of the inference image by the user device comprises uploading the inference image by a user through the user interface element.
  • the user device may automatically receive the inference image e.g., from another device using a communication protocol such as File Transfer Protocol (FTP) protocol.
  • FTP File Transfer Protocol
  • the image received by the user device may be referred to as inference image.
  • the server may comprise the (whole) machine learning model for enabling execution of the first morphing detection method. However, for the execution of the second morphing detection method, the server may or may not comprise the whole machine learning model.
  • the machine learning model may comprise a quantum machine learning model or a classical machine learning model or a hybrid classical-quantum machine learning model.
  • the location information that is input to the machine learning model may be the determined set of locations of the set of landmarks or may be a feature vector that is generated from the set of locations.
  • the machine learning model comprises a first sub- model and a second sub-model, wherein the first sub-model is configured to receive the set of locations and to predict a feature vector that represents the inference image, wherein the second sub-model is configured to receive the feature vector and to predict the output.
  • the server may comprise the second sub- model while the user device may comprise the first sub-model.
  • the second sub-model is a classical machine learning model (e.g., a CNN) or a quantum machine learning model or a hybrid classical-quantum machine learning model.
  • the quantum machine learning model may, for example, be a quantum neural network (QNN), a quantum convolutional neural network (QCNN), or a quantum support vector machine (QSVM).
  • QNN quantum neural network
  • QCNN quantum convolutional neural network
  • QSVM quantum support vector machine
  • the output of the quantum machine learning model may be provided as the measurement of one or more qubits of the quantum processing unit.
  • the first sub-model is a neural network.
  • the first sub-model may, for example, be a deep neural network such as a CNN or a support vector machine.
  • the first sub-model is comprised in the user device or in the server, wherein the second sub-model is comprised in the server.
  • the machine learning model may comprise a third sub-model that is configured to receive the output or measurement(s) of the second-sub model and provide a prediction of the inference image being morphed or not morphed image.
  • the third sub-model is a neural network.
  • the third sub-model may, for example, be a deep neural network such as a CNN or a support vector machine.
  • the third sub-model is comprised in the server.
  • the user device and/or the server are provided as cloud services.
  • the server may, for example, be a cloud server which is deployed on a public cloud, a private cloud or a hybrid cloud.
  • the first morphing detection method may be implemented by a mobile app.
  • the second morphing detection method may be implemented by a mobile app.
  • the mobile app may be launched on the user device in order to perform the first morphing detection method or the second morphing detection method.
  • the launching of the mobile app may, for example, display a user interface for uploading the inference image to the user device.
  • the inference image may, for example, be a visual representation of an object or subject.
  • the inference image of the object may be obtained by imaging the object e.g., using a camera.
  • the inference image of the object may be a reproduced version that is captured from a document comprising the image of the object.
  • the set of landmarks may be identified in the inference image in accordance with a landmark pattern.
  • the landmark pattern may be a predefined landmark pattern or a dynamically created landmark pattern.
  • the landmark may refer to a specific point of the object.
  • the locations of the set of landmarks may, for example, be determined with respect to a coordinate system defined relative the object.
  • the locations of the set of landmarks may, thus, be relative locations.
  • the landmarks are located relative to the object using a local coordinate system. This may, thus, enable a faster inference of the machine learning model.
  • the object that is represented in the inference image may refer to a tangible, physical object capable of being rendered in an image.
  • the object may be any object whose visual representation in an image may be morphed.
  • the object may be of a specific object type.
  • the object type may be an individual, a body part, a human face, human eyes, fingerprints, animal face etc. Covering different object types may enable a wider application of the present subject matter e.g., the machine learning model may be used in face recognition systems, fingerprint recognition systems, and iris recognition systems to detect morphed images. [0060] According to one example, the machine learning model may be trained to detected morphed images of human faces. According to one example, the object in the inference image is a human face. [0061] In one example, a pre-processing of the inference image may be performed before using the pre-processed image to determine whether it is morphed. The pre- processing may, for example, comprise the reduction of the size of the inference image.
  • the inference image may be pre-processed in order to have one size that is common to other inference images.
  • pixels of the inference image may be represented by a vector (e.g., tensor).
  • the vector may have fields, wherein the fields may include the pixel width, the pixel height, and pixel value(s) such as red, green, blue (RGB) values. This may enable a uniform representation of the inference image.
  • a set of landmarks may be used to represent the inference image.
  • the landmark may refer to a specific point of the object.
  • the set of landmarks may be defined as points bearing key information on the geometry of the object.
  • the landmark may be a right eyebrow lateral point, right eyebrow medial point, left eyebrow lateral point, left eyebrow medial point, right eye lateral canthus etc.
  • the set of landmarks may be identified using a landmark pattern.
  • the landmark pattern may indicate features of the object which enable to identify the object and its structure.
  • the landmark pattern may indicate a maximum number of landmarks and/or the landmarks per feature and/or the densities of landmarks and/or distances between landmarks.
  • the landmark pattern may be a user defined pattern or may be defined by a computer- implemented tool. For example, the landmark pattern may be determined using distinctive features of the object in the inference image.
  • a landmark pattern may be provided per object type.
  • the identification of the set of landmarks in the inference image may be performed by: determining the object type represented by the inference image, selecting from predefined landmark patterns the landmark pattern associated with the determined object type and using the selected landmark pattern to identify the set of landmarks in the inference image.
  • the object represented in the inference image may be detected in the image. The object may, for example, be detected using a computer vision technique that identifies and locates objects within an image. An area of the inference image defined by the detected object may be cropped. This may result in a cropped image.
  • the set of landmarks are then identified in the cropped image and the locations are determined using the cropped image. This may enable to determine the landmarks after the object is detected and cropped. Thus, the landmarks may not depend on the location of the object within the inference image or on the distance of the object to the camera. This may significantly reduce the amount of data necessary to infer the machine learning model.
  • the present subject matter may use different advantageous techniques to provide the landmark pattern(s). In one example, for each object type a reference image that represents the object type may be provided. The landmark pattern(s) may be determined using the respective reference image(s). In one example, a feature extraction tool may be used to extract the features that identify the object structure from the reference image.
  • the landmark pattern may be defined by assigning to each feature of the extracted features zero or more landmarks that would represent the feature.
  • the landmark pattern may indicate the position of the landmarks with respect to the respective feature e.g., it may indicate 10 landmarks surrounding the eye of a human face etc. This example may enable to define a priori landmark patterns which may be used during the inference.
  • a trained machine learning model may be used to create the landmark pattern that identifies the structure of the object in the inference image. This may enable to create the landmark pattern dynamically or automatically during the inference.
  • the creation of the landmark pattern may enable an automatic identification of the landmarks in the inference image e.g., the creation of the landmark pattern implicitly includes the step of identification of the landmarks.
  • the set of locations (or positions) of the identified set of landmarks may be determined.
  • the steps of identifying the set of landmarks of the inference image and the determination of their locations may be performed, e.g., in one step, concurrently or in parallel. This may speedup the inference.
  • the set of locations of each identified set of landmarks may be determined after the set of landmarks is identified.
  • the set of locations of the set of landmarks of the inference image may be provided as relative locations e.g., which do not depend on the image size. For that, a coordinate system which is defined relative to the object in the inference image may be used to determine the locations of the set of landmarks.
  • the coordinate system may be a local coordinate system associated with the object.
  • the coordinate system may refer to a frame of reference defined by orthogonal directions and an origin.
  • the origin may be a reference point that is part of the object.
  • the origin may be used as a fixed point of reference for the geometry of the surrounding space.
  • the local coordinate system may be defined per object type. Using a fixed point per object type as origin may provide locations which accurately reflect the shape of the object.
  • the location of each landmark may be provided as coordinates relative to the point of origin.
  • the location may be a direction vector in the local coordinate system.
  • the location of the landmark may, for example, refer to a three-dimensional measurement from a position of the landmark to the origin.
  • initial locations of the set of landmarks of the inference image may be determined in a first coordinate system (e.g., an absolute coordinate system).
  • a transformation of the first coordinate system to the local coordinate system may be applied to the initial locations. This may result in the locations of the set of landmarks of the inference image which are determined in the local coordinate system.
  • the local coordinate system may be a three-dimensional, 3D, coordinate system.
  • the set of landmark locations may be provided as 3D coordinates.
  • the set of locations of the set of landmarks may thus describe the three-dimensional geometry of the object. This may provide an accurate position of the landmarks and accurate distinction between the set of landmarks in three dimensions. This may enable more efficient morphed image detection, because the morphing algorithms may generate specific patterns in the three-dimensional geometry of the thusly created objects.
  • the local coordinate system may be a two-dimensional, 2D, coordinate system.
  • the set of landmark locations may thus be provided as 2D coordinates. Compared to 3D coordinates, this may save processing resources such as storage resources while still providing reliable results.
  • each entry of the training dataset may comprise the tuple (3D coordinates, label) or (2D coordinates, label).
  • the present subject matter may further reduce the size of the input data while still providing accurate representation of the input data.
  • the set of locations of the set of landmarks of the inference image may be represented by a feature vector in a predefined k-dimensional feature space having the dimension k which is smaller than the number of landmarks identified in the inference image.
  • the location information which is input to the machine learning model may be the feature vector.
  • the feature space may refer to a k-dimensional space spanned up by k different features used to characterize the set of landmark locations e.g., a feature may be the number of locations, location density etc.
  • the k different features may be determined, and the set of locations of the set of landmarks of the inference image may be used to evaluate the k different features, and the resulting evaluations may be provided as the feature vector.
  • the k different features may be user determined features or automatically determined features e.g., using machine learning techniques.
  • the feature vector may be determined using transfer learning. The transfer learning may be used to apply knowledge gained while solving another task which is related to the morphing detection task.
  • the linear transformation may, for example, be user defined e.g., the weight matrix may be a user defined matrix.
  • the weight matrix may comprise learnable weights which may be provided using the transfer learning.
  • another machine learning model having the weight matrix W as a trainable weight matrix may have been trained to generate the feature vector from a set of landmark locations (e.g., for object recognition).
  • the weight matrix W may thus be transferred from this other machine learning model in order to be used with the present example.
  • the set of landmark locations of the set of landmarks of the inference image may be represented with the feature vector using a trained neural network (referred to herein as first neural network or first sub-model) comprising a fully connected layer having nodes representing the set of locations and an output layer representing the feature vector.
  • the first neural network is configured to receive the set of locations of the set of landmarks of the inference image and to output the feature vector.
  • the size k of the feature vector that represents the object of the inference image may be defined based on the number of qubits in a quantum processing unit (QPU) that enables to train a quantum machine learning model to detect morphed images.
  • the size of the feature vector may, for example, be provided based on the encoding scheme used by the quantum machine learning model for encoding classical data into quantum states.
  • the size k of the feature vector may be equal to the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the angle encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states.
  • the size k of the feature vector may be smaller than the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the amplitude encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states.
  • the output of the trained machine learning model may be used to perform authentication of a user. If the image of the user is not morphed this may indicate that the user’s identity is authentic. The authenticated user may be allowed to get access to services.
  • the computer system may, for example, be configured to generate a control signal for enabling access to the services by the authenticated user.
  • an electric gate may be provided.
  • the electric gate comprises an electric gate motor that enables it to automatically open and close.
  • the user may be enabled access to an area by sending a control signal to the electric gate motor to open the electric gate.
  • the electric gate may, for example, be a sliding door.
  • the machine learning model was trained using a training dataset.
  • the training dataset may, for example, be obtained by the training data generation method.
  • the machine learning model may be retrained in response to any one of: the training dataset is updated, or a validity time is expired, wherein the retraining is performed using an updated training dataset.
  • the training dataset may be updated by adding entries to and/or removing entries from the training dataset.
  • the training dataset may be updated and the machine learning model may be retrained using the updated training dataset.
  • This may enable an up-to-date model which may improve the morphed image detection efficiency.
  • the training or retraining of the machine learning model may comprise for each entry of the training dataset: the location information of the entry may be input (b1) to the machine learning model.
  • the machine learning model may output (b2) a value indicating whether the training image represented by the location information is morphed or not.
  • a loss function may be evaluated (b3) using the value and the label of the entry.
  • the learnable weights of the machine learning model may be updated and steps b1 to b3 may be repeated for a next entry of the training dataset; otherwise, the trained machine learning model may be provided.
  • the update of the weights may, for example, be performed using gradient descent.
  • Training phase The present subject matter may provide optimal training data for training and/or retraining the machine learning model which may subsequently be used in the inference phase.
  • the resulting trained model may have a higher detection efficiency of morphed image. The efficiency may be defined as the ration of the number of detected morphed images and the total number of morphed images which are input to the model.
  • a training dataset may be generated in order to train the machine learning model to detect morphed images.
  • the training dataset may be created using a set of images.
  • the image used for creating the training dataset may be referred to as training image.
  • the training image may, for example, be a visual representation of an object or subject.
  • the training image of the object may be obtained by imaging the object e.g., using a camera.
  • the training image of the object may be a reproduced version that is captured from a document comprising the training image of the object.
  • a set of landmarks of the object that is represented in the training image may be identified.
  • the set of landmarks may be identified in the training image in accordance with a landmark pattern.
  • the landmark pattern may be a predefined landmark pattern or a dynamically created landmark pattern.
  • the landmark may refer to a specific point of the object.
  • the locations of the set of landmarks may, for example, be determined with respect to a coordinate system defined relative the object. The locations of the set of landmarks may, thus, be relative locations.
  • an entry may be included in the training dataset.
  • the entry may comprise a location information (which may be referred to as ⁇ ⁇ , where the subscript ⁇ refers to the training image) indicating the set of locations and a label indicating whether the training image is a real training image (i.e., non-morphed training image) or morphed training image.
  • each entry of the training dataset may comprise a tuple ( ⁇ ⁇ , ⁇ ⁇ ), where ⁇ ⁇ is the location information determined for the ⁇ -th training image of the set of training images and the ⁇ ⁇ is the label of the ⁇ -th training image.
  • the training dataset may be stored in a storage system of the computer system.
  • the computer system may control access to the training dataset.
  • the computer system may define permissions, such as read permission and execute permissions, for access to the training dataset.
  • One or more users may use the training dataset based on permissions which are assigned to the users.
  • the landmarks are located relative to the object using a local coordinate system.
  • the training data may, thus, enable a faster training of machine learning models.
  • the resulting trained model may efficiently detect morphed training images.
  • the object that is represented in each training image of the set of training images may refer to a tangible, physical object capable of being rendered in a training image.
  • the object may be any object whose visual representation in a training image may be morphed.
  • the object may be of a specific object type. In one example, the object type may be an individual, a body part, a human face, human eyes, fingerprints, animal face etc.
  • the resulting trained model may be used in face recognition systems, fingerprint recognition systems, and iris recognition systems to detect morphed training images.
  • the present subject matter may advantageously control the number and types of the objects in the set of training images in order to find a desired balance between efficiency of the resulting trained model and the extent of application of the trained model.
  • the set of training images used to generate the training dataset may be a homogeneous set of training images or a heterogeneous set of training images.
  • the homogenous set of training images may represent objects of the same object type, while the heterogeneous set of training images may represent objects of different object types.
  • the homogeneous set of training images may be advantageous for the following reasons.
  • the homogeneous set of training images may enable a systematic and faster generation of the training dataset compared to training images of different object types e.g., with the homogenous set of training images a smaller number e.g., one, of landmark patterns may be sufficient to find the landmarks in all set of training images.
  • the homogeneous set of training images may provide homogeneous training samples, wherein the homogeneous training samples may have higher affinity among them enabling a fast convergence of the training process when applied on the created training dataset.
  • the homogeneous set of training images may enable a trained model that is more efficient in detecting any other morphed training image of the object type represented by the set of training images.
  • the homogenous set of training images may be training images of one object type e.g., the set of training images may be training images of human faces, wherein the human faces may be of a same or different individuals.
  • the heterogeneous set of training images may be advantageous for the following reasons.
  • the heterogeneous set of training images may provide a larger training dataset due to the availability of a higher number of training images.
  • the heterogeneity may allow to build a robust learning system by leveraging the intrinsic knowledge among data.
  • the model may learn different morphing techniques, and may thus enable a morphing detection that works well not only for one specific type of morphing (e.g., face morphing) but also for other types of morphing.
  • the heterogeneous set of training images may thus enable a wider application of the present subject matter while still providing reliable detection results.
  • the heterogeneous set of training images may be training images of different object types.
  • the different object types may be human face, human eyes, animal face, fingerprints etc.
  • the present subject matter may advantageously control the set of training images in order to balance the training dataset with respect to a set of training image attributes.
  • the set of training image attributes may, for example, comprise at least one of lighting conditions, background color, skin tone, facial expression and any other attribute descriptive of a training image or of the object represented in the training image.
  • Each training image of the set of training images may have a specific set of values of the set of training image attributes respectively.
  • the set of training images may comprise multiple subsets of training images, each subset having a distinct set of values of the set of training image attributes.
  • the number of subsets of the training images may be higher than a threshold. This may enable to control the level of diversity of the set of training images.
  • the first subset training images may have a first set of values of the set of training image attributes
  • the second subset training images may have a second set of values of the set of training image attributes
  • Each pair of sets of values (e.g., the first set and second set of values) of the training image attributes may differ in at least one training image attribute.
  • Using different attribute values in the set of training images may enable landmarks which are independent from background, lighting conditions, skin tone etc. This may significantly reduce the amount of data necessary to train the machine learning model.
  • the set of training images may be provided as the homogeneous set of training images comprising the multiple subsets.
  • the set of training images may be provided as the heterogeneous set of training images comprising the multiple subsets.
  • the set of training images may, for example, comprise training images of different resolutions.
  • the set of training images may comprise scanned training images of the objects and/or training images of the objects which are captured directly from the objects e.g., by a digital camera.
  • the set of training images may comprise a minimum fraction of training images which are scanned training images.
  • a scanned training image may, for example, be obtained using a photo scanner or a camera for capturing a training image in an identity token.
  • the scanned training images may provide accurate detection in spite of containing only smaller part of data.
  • the resulting trained machine learning model may, for example, be useful for passport image verification during the passport application process or during check of the passports.
  • the present subject matter may control the process of generation of the training dataset by using different access methods to access the set of training images.
  • at least part of the set of training images (named retrieved training images) may be retrieved or received from one or more existing database systems.
  • the retrieved training images may be the whole set of training images or a subset of the set of training images.
  • the computer system may be configured to connect to the database systems and request or retrieve the at least part of the set of training images. This may speed up the generation of the training data compared to a local generation of the set of training images.
  • at least part of the set of training images (named produced training images) may be produced locally by the computer system.
  • the produced training images may be the whole set of training images or a subset of the set of training images.
  • the set of training images may comprise retrieved training images and/or produced training images.
  • the produced training images may comprise morphed training images and/or non-morphed training images.
  • the retrieved training images may comprise morphed training images and/or non-morphed training images. This example may provide a flexible and controllable access to the training images e.g., if one access method is not available, the present subject matter can still use alternative access methods to produce the training data. This may improve the process of generation of the training dataset.
  • the produced training images of the set of training images may, for example, be obtained as follows.
  • the computer system may receive non-morphed training images.
  • a subset of the received non-morphed training images may be used to generate morphed training images by the computer system in order to obtain said produced training images.
  • the morphed training images may, for example, be generated using one or more morphing algorithms.
  • the morphing algorithm may, for example, be a Generative Adversary Networks (GANs) or landmark-based morphing algorithm.
  • the morphing algorithm may, for example, be a face morphing algorithm that extracts feature points on the face, and based on these feature points training images are partitioned and face morphing is performed.
  • a pre-processing of the set of training images may be performed before using the pre-processed training images to generate the training dataset.
  • the pre-processing may, for example, comprise the reduction of the size of the set of training images. This may save processing resources required for determining the set of landmarks.
  • the set of training images may be pre-processed in order to have one size.
  • pixels of each training image of the set of training images may be represented by a vector (e.g., tensor).
  • the vector may have fields, wherein the fields may include the pixel width, the pixel height, and pixel value(s) such as red, green, blue (RGB) values. This may enable a uniform representation of the set of training images.
  • At least part of the set of training images may be processed in parallel in order to generate the training dataset. This may speed up the process of generating the training dataset. Additionally, or alternatively, at least part of the set of training images may be processed sequentially. This may enable a simplified implementation of the training image processing.
  • the set of training images may be processed in batches, wherein each batch may have a size smaller than a maximum size.
  • the training dataset may be produced in a distributed computing system e.g., each system component of the distributed computing system may process its respective batches of training images, and the resulting training data entries may be combined in one training dataset.
  • a set of landmarks may be used to represent each training image of the set of training images.
  • the landmark may refer to a specific point of the object.
  • the set of landmarks may be defined as points bearing key information on the geometry of the object.
  • the object is a human face, for example, the landmark may be a right eyebrow lateral point, right eyebrow medial point, left eyebrow lateral point, left eyebrow medial point, right eye lateral canthus etc.
  • the set of landmarks may be identified using a landmark pattern.
  • the landmark pattern may indicate features of the object which enable to identify the object and its structure.
  • the landmark pattern may indicate a maximum number of landmarks and/or the landmarks per feature and/or the densities of landmarks and/or distances between landmarks.
  • the landmark pattern may be a user defined pattern or may be defined by a computer-implemented tool.
  • the landmark pattern may be determined using distinctive features of the object in the training image. In case the object is a human face, the distinctive features may include eye spacing, nose length, mouth width, head eccentricity etc. [0098]
  • a landmark pattern may be provided per object type of the set of training images.
  • one landmark pattern may be used to generate the set of landmarks of each training image of the set training images.
  • one landmark pattern may be predefined for the whole set of training images so that during the generation of the training dataset the landmark pattern may automatically be used to identify the set of landmarks in each training image of the set of training images.
  • a distinct landmark pattern may be used per object type to generate the set of landmarks of each training image of that object type.
  • multiple landmark patterns may be predefined for the set of training images.
  • the identification of the set of landmarks in the training image may be performed by: determining the object type represented by the training image, selecting from the predefined landmark patterns the landmark pattern associated with the determined object type and using the selected landmark pattern to identify the set of landmarks in the training image.
  • the object represented in each training image of the set of training images may be detected in the training image.
  • the object may, for example, be detected using a computer vision technique that identifies and locates objects within a training image.
  • An area of the training image defined by the detected object may be cropped. This may result in a cropped training image.
  • the set of landmarks are then identified in the cropped training image and the locations are determined using the cropped training image.
  • the present subject matter may use different advantageous techniques to provide the landmark pattern(s).
  • a reference training image of the set of training images that represents the object type may be selected.
  • the selected reference training image may be a randomly selected training image or a training image whose training image attribute values fulfil a predefined selection criterion.
  • the selection criterion may require that the value of each training image attribute of the set of training image attributes has a specific value or is within a specific range of values.
  • the landmark pattern(s) may be determined using the respective reference training image(s).
  • a feature extraction tool may be used to extract the features that identify the object structure from the reference training image.
  • the landmark pattern may be defined by assigning to each feature of the extracted features zero or more landmarks that would represent the feature.
  • the landmark pattern may indicate the position of the landmarks with respect to the respective feature e.g., it may indicate 10 landmarks surrounding the eye of a human face etc. This example may enable to define a priori landmark patterns which may be used during the generation of the training dataset.
  • a trained machine learning model may be used to create the landmark pattern that identifies the structure of the object in each training image of the set of training images.
  • the creation of the landmark pattern may enable an automatic identification of the landmarks in the training image e.g., the creation of the landmark pattern implicitly includes the step of identification of the landmarks.
  • the set of locations (or positions) of each identified set of landmarks may be determined.
  • the steps of identifying the set of landmarks of a training image and the determination of their locations may be performed, e.g., in one step, concurrently or in parallel. This may speedup the generation of the training dataset.
  • the set of locations of each identified set of landmarks may be determined after the set of landmarks is identified.
  • the set of locations of the set of landmarks of each training image of the set of training images may be provided as relative locations e.g., which do not depend on the training image size.
  • a coordinate system which is defined relative to the object in the training image may be used to determine the locations of the set of landmarks.
  • the coordinate system may be a local coordinate system associated with the object.
  • the coordinate system may refer to a frame of reference defined by orthogonal directions and an origin.
  • the origin may be a reference point that is part of the object.
  • the origin may be used as a fixed point of reference for the geometry of the surrounding space.
  • the local coordinate system may be defined per object type.
  • Using a fixed point per object type as origin may provide locations which accurately reflect the shape of the object.
  • the location of each landmark may be provided as coordinates relative to the point of origin.
  • the location may be a direction vector in the local coordinate system.
  • the location of the landmark may, for example, refer to a three-dimensional measurement from a position of the landmark to the origin.
  • initial locations of the set of landmarks of a training image may be determined in a first coordinate system (e.g., an absolute coordinate system).
  • a transformation of the first coordinate system to the local coordinate system may be applied to the initial locations. This may result in the locations of the set of landmarks of the training image which are determined in the local coordinate system.
  • the local coordinate system may be a three-dimensional, 3D, coordinate system.
  • the set of landmark locations may be provided as 3D coordinates.
  • the set of locations of the set of landmarks may thus describe the three-dimensional geometry of the object. This may provide an accurate position of the landmarks and accurate distinction between the set of landmarks in three dimensions. This may enable more efficient morphed training image detection, because the morphing algorithms may generate specific patterns in the three- dimensional geometry of the thusly created objects.
  • the local coordinate system may be a two-dimensional, 2D, coordinate system.
  • the set of landmark locations may thus be provided as 2D coordinates. Compared to 3D coordinates, this may save processing resources such as storage resources while still providing reliable results.
  • each entry of the training dataset may comprise the tuple (3D coordinates, label) or (2D coordinates, label).
  • a set landmarks may be identified and a set locat ⁇ ⁇ ⁇ ions ⁇ ⁇ , ...., ⁇ may be determined respectively, ⁇ 2.
  • the present subject matter may further reduce the size of the input data while still providing accurate representation of the input data.
  • the set of locations of the set of landmarks of the training image may be represented by a feature vector in a predefined ⁇ - dimensional feature space having the dimension ⁇ which is smaller than the number of landmarks identified in the training image.
  • the location information of each entry of the training dataset may be a feature vector.
  • the feature space may refer to a ⁇ -dimensional space spanned up by ⁇ different features used to characterize the set of landmark locations e.g., a feature may be the number of locations, location density etc.
  • the ⁇ different features may be determined, and for each training image of the set of training images, the set of locations of the set of landmarks of the training image may be used to evaluate the ⁇ different features, and the resulting evaluations may be provided as the feature vector.
  • the ⁇ different features may be user determined features or automatically determined features e.g., using machine learning techniques.
  • the feature vectors may be determined using transfer learning. The transfer learning may be used to apply knowledge gained while solving another task which is related to the morphing detection task. For example, knowledge gained while learning to recognize the objects may be applied when trying to detect morphing of the objects.
  • the linear transformation may, for example, be user defined e.g., the weight matrix may be a user defined matrix.
  • the weight matrix may comprise learnable weights which may be provided using the transfer learning.
  • another machine learning model having the weight matrix W as a trainable weight matrix may have been trained to generate the feature vector from a set of landmark locations (e.g., for object recognition). The weight matrix W may thus be transferred from this other machine learning model in order to be used with the present example.
  • the set of landmark locations of the set of landmarks of the training image may be represented with the feature vector using a trained neural network (referred to herein as first neural network) comprising a fully connected layer having nodes representing the set of locations and an output layer representing the feature vector.
  • the first neural network is configured to receive the set of locations of the set of landmarks of the training image and to output the feature vector.
  • the size ⁇ of the feature vector that represents the object of each training image of the set of training images may be defined based on the number of qubits in a quantum processing unit (QPU) that enables to train a quantum machine learning model to detect morphed training images.
  • QPU quantum processing unit
  • the size of the feature vector may, for example, be provided based on the encoding scheme used by the quantum machine learning model for encoding classical data into quantum states.
  • the size ⁇ of the feature vector may be equal to the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the angle encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states.
  • the size ⁇ of the feature vector may be smaller than the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the amplitude encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states.
  • a feature vector that represents the object in the training image may be provided.
  • the feature vector comprises ⁇ feature values ⁇ ⁇ ⁇ , .... ⁇ ⁇ .
  • the size of the present entry may be smaller than the entry of the previous example as the size of the feature vector ⁇ ⁇ , ...., ⁇ may be smaller than the size of the set of locations ⁇ , ⁇ ⁇ ⁇ ⁇ ...., ⁇ ⁇ .
  • the training dataset may be provided as a data structure.
  • the data structure may, for example, comprise a table comprising a column representing the label and one or more columns representing the location information.
  • the data structure may be an Extensible Markup Language (XML) file or JavaScript Object Notation (JSON) file.
  • the training dataset may advantageously be used to train a machine learning model for training image morphing detection.
  • the machine learning model may comprise a quantum machine learning model or a classical machine learning model or a hybrid classical-quantum machine learning model.
  • the quantum machine learning model may, for example, be a quantum neural network (QNN), a quantum convolutional neural network (QCNN), or a quantum support vector machine (QSVM).
  • the classical machine learning model may, for example, comprise a deep neural network such as a CNN or a support vector machine.
  • the document arXiv:2009.09423 provides an example implementation of CNNs in a quantum environment for training image classification.
  • the quantum machine learning model may comprise an encoding layer.
  • the encoding layer may be configured to encode the feature vector into a quantum state using a set of qubits.
  • the quantum state may refer to a mathematical entity that provides a probability distribution for the outcomes of each possible measurement on the system of the set of qubits. This may, for example, be performed using an encoding scheme, wherein the encoding scheme may be an angle encoding or amplitude encoding.
  • the encoding of the feature vector into a quantum state may, for example, be done using single qubit Pauli rotation gates (R_X, R_Y, R_Z) which are applied to individual qubits.
  • the encoding layer may or may not entangle the resulting quantum state. That is, the encoding layer may provide for a given feature vector a quantum state which may be an entangled quantum state or unentangled quantum state.
  • the entangling may not involve any input data or trainable parameters as it may be implemented using multi-qubit entangling gates.
  • the entangling may enable to access a higher dimensional state space.
  • the quantum machine learning model may further comprise a learning layer having one or more trainable or free parameters.
  • the learning layer may be configured to change the quantum state by applying one or more unitary transformations.
  • the learnable parameters may, for example, be the rotation angles of single qubit Pauli rotation gates e.g., the Pauli rotation angle may be applied on each qubit of the set of qubits after the quantum state has been created.
  • the learnable parameters may, for example, comprise a number of rotation angles which is applied to the set of qubits respectively.
  • the quantum machine learning model may further comprise a measurement layer for measuring the set of qubits after the change is applied. This set of measurements may provide an indication whether the training image represented by the feature vector is morphed or not morphed.
  • a loss function may be evaluated using the set of measurements and the label of the training image.
  • the quantum machine learning model may be trained by backpropagation using the loss function and an optimization technique that is performed by a classical computer. The backpropagation may enable to update of the learnable parameters using gradient descent. The convergence criterion may, for example, require that the loss function exceeds a threshold.
  • the trained quantum machine learning model may be used to determine whether a training image is a morphed training image or not.
  • the quantum machine learning model and the first neural network may be jointly trained. For example, in each iteration of the training, a set of locations may be input to the first neural network to generate the feature vector, the feature vector is provided as input to the quantum machine learning model, and the resulting set of measurements may provide an indication whether the training image represented by the feature vector is morphed or not morphed.
  • a loss function may be evaluated using the set of measurements and the label of the training image. In case the loss function does not fulfill a convergence criterion, the backpropagation is performed in order to update both the learnable parameters of the quantum machine learning model as well as the weights of the first neural network.
  • the update of the first neural network weights and the learnable parameters may be performed using gradient descent.
  • the loss function fulfills the convergence criterion
  • the resulting trained first neural network and quantum machine learning model may be provided.
  • the convergence criterion may, for example, require that the loss function exceeds a threshold.
  • the trained first neural network and quantum machine learning model may be used to determine whether a training image is a morphed training image or not.
  • the training of the quantum machine learning model may be performed jointly with the first neural network and a second neural network, wherein the second neural network is configured to receive as input the set of measurements and to provide as output a value indicating whether the training image is morphed or not.
  • a set of locations may be input to the first neural network to generate the feature vector which is provided as input to the quantum machine learning model which provide in turn the set of measurements as input to the second neural network, the second neural network provides a value indicating whether the training image is morphed or not.
  • a loss function may be evaluated using the set of measurements and the label of the training image. In case the loss function does not fulfill a convergence criterion, the backpropagation is performed in order to update the learnable parameters of the quantum machine learning model the weights of the first neural network and the weights of the second neural network. In case the loss function fulfills the convergence criterion, the resulting trained first neural network, second neural network and quantum machine learning model may be provided.
  • the convergence criterion may, for example, require that the loss function exceeds a threshold.
  • the trained first neural network and quantum machine learning model and second neural network may be used to determine whether a training image is a morphed training image or not.
  • the present subject matter may, for example, use the trained machine learning model for determining whether a training image is a morphed training image or not morphed training image. For that, a training image of an object may be received.
  • the training image may, for example, be captured from an identity token or may be read from a storage device where the training image is stored.
  • a set of landmarks of the object may be identified in accordance with a landmark pattern.
  • Fig. 1 is a schematic diagram of a morphing detection system 10 in accordance with an example of the present subject matter.
  • the morphing detection system 10 may comprise one or more user devices 11.1 through 11.N.
  • the morphing detection system 10 may further comprise one or more servers 13.1 through 13.M.
  • Each user device of the user devices 11.1 through 11.N may be configured to communicate with one or more of the servers 13.1 through 13.M using one or more networks 12.
  • the network 12 may, for example, comprise a mobile network, a local area network (LAN), a general wide area network (WAN), the Internet or a combination thereof.
  • Each server of the servers 13.1 through 13.M may be configured to communicate with one or more of the user devices 11.1 through 11.N through the network 12.
  • the user device may be of different types such as desktop computer, laptop, user equipment or smartphone 11.3.
  • Each server of the servers 13.1 through 13.M may comprise (a copy or instance of) the trained machine learning model 14.1 through 14.M.
  • the machine learning model 14.1 through 14.M may be configured to receive location information representing an image of an object and predict whether the image is morphed or not morphed images.
  • the machine learning model is fully contained in the server, but it is not limited to, because it may be split over the server and the user device as exemplified in Fig.2A and Fig.2B.
  • the location information that represents an imaged object may be generated at the sever or at the user device.
  • the user device may send to a respective server the whole image to be inferred by the ML model or send the location information to the respective server.
  • Fig.2A is a diagram illustrating a machine learning model in accordance with an example of the present subject matter.
  • the machine learning model 20 comprises a first sub-model 21 and a second sub-model 22.
  • the first sub-model 21 may be a neural network.
  • the second sub-model 22 may be a quantum machine learning model.
  • the quantum machine learning model may comprise quantum layers such as encoding layer, learning layer and measurement layer.
  • the machine learning model 20 may be configured to receive as input a set of locations 26 and provide an output 27.
  • the set of locations 26 may be locations of a set of landmarks of an object (e.g., human face) in an image.
  • Figs.6A and 6B provide an example of the image and a method to obtain the set of locations.
  • the output may indicate whether the image is morphed or not morphed.
  • the first sub-model may output a feature vector in response to receiving the set of locations.
  • the feature vector may be input to the quantum machine learning model.
  • the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector.
  • the quantum state may be changed using the learning layer of the quantum machine learning model.
  • the set of measurements of the qubits of the quantum machine learning model may be provided by the measurement layer.
  • the set of measurements may be used as an indication whether the image represented by the set of locations is morphed or not morphed.
  • the first sub-model may be deployed on the user device e.g., 11.1 while the second sub-model may be deployed on the server e.g., 13.1.
  • Fig.2B is a diagram illustrating a machine learning model in accordance with an example of the present subject matter.
  • the machine learning model 20 comprises a first sub-model 21, a second sub-model 22 and a third sub-model 23.
  • the first sub-model 21 may be a neural network.
  • the second sub-model 22 may be a quantum machine learning model.
  • the second sub-model 23 may be a neural network.
  • the quantum machine learning model may comprise quantum layers such as encoding layer, learning layer and measurement layer.
  • the machine learning model 20 may be configured to receive as input a set of locations 26 and provide an output 27.
  • the set of locations 26 may be locations of a set of landmarks of an object (e.g., human face) in an image.
  • the output may indicate whether the image is morphed or not.
  • the first sub-model may output a feature vector in response to receiving the set of locations.
  • the feature vector may be input to the quantum machine learning model.
  • the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector.
  • the quantum state may be changed using the learning layer of the quantum machine learning model.
  • the set of measurements of the qubits of the quantum machine learning model may be provided by the measurement layer.
  • the third sub-model may receive as input the set of measurements and output a value indicating whether the image represented by the location information is morphed or not.
  • the first sub-model may be deployed on the user device e.g., 11.1 while the second and third sub-models may be deployed on the server e.g., 13.1.
  • Fig.3 is a signaling diagram illustrating a method for morphing detection in accordance with an example of the present subject matter. For the purpose of explanation, the method described in Fig.
  • the user device 11.N may receive (31) an image 30 of an object.
  • the user device 11.N may identify a set of landmarks of the object in accordance with a landmark pattern.
  • the user device 11.N may determine (33) location information representing locations of the set of landmarks with respect to a coordinate system defined relative to the object.
  • the location information may be provided as a feature vector, but it is not limited to, that is generated from the set of locations of the landmarks of the object.
  • the user device 11.N may send (34) the location information to the server 13.1.
  • the location information may be received by the server 13.1.
  • the server 13.1 may input (35) the location information to the trained machine learning model.
  • the server 13.1 may receive (36) an output of the trained machine learning model indicating whether the image 30 is a morphed image or non-morphed image.
  • the output may be sent (37) by the server 13.1 to the user device 11.N.
  • the output may be received by the user device 11.N.
  • the user device 11.N may use (38) the output for rejecting or accepting the received image 30.
  • Fig.4 is a signaling diagram illustrating a method for morphing detection. For the purpose of explanation, the method described in Fig.4 may be implemented in the system illustrated in Fig.1, but is not limited to this implementation.
  • the user device 11.N may receive (41) an image 40 of an object.
  • the user device 11.N may send (42) the image to the server 13.1.
  • the server 13.1 may identify a set of landmarks of the object in accordance with a landmark pattern.
  • the server 13.1 may determine (43) location information representing locations of the set of landmarks with respect to a coordinate system defined relative to the object.
  • the location information indicates the set of locations.
  • the location information may be provided as a feature vector, but it is not limited to, that is generated from the set of locations of the landmarks of the object.
  • the server 13.1 may input (45) the location information to the trained machine learning model.
  • the server 13.1 may receive (46) an output of the trained machine learning model indicating whether the image 30 is a morphed image or non-morphed image.
  • the output may be sent (47) by the server 13.1 to the user device 11.N.
  • the output may be received by the user device 11.N.
  • Fig.5 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed training image detection in accordance with an example of the present subject matter.
  • the training dataset may be generated using a set of training images.
  • a training image of an object may be received in step 101.
  • the training image may be received from a local storage of the computer system.
  • the training image may be received from a remote database system in which the training image is stored e.g., step 101 may be performed in response to sending a request to the database system.
  • a set of landmarks of the object may be identified in step 103 in accordance with a landmark pattern.
  • Locations of the set of landmarks may be determined in step 105 with respect to a coordinate system defined relative to the object.
  • Figs.6A and 4B provide an example implementation of step 105.
  • An entry may be added in step 107 to the training dataset. The entry indicates the set of locations and a label, wherein the label indicates whether the received training image is a real training image or morphed training image.
  • the real training image refers to a non-morphed training image.
  • steps 101 to 107 may be repeated for each further training image of the set of training images.
  • the repetition may be performed until a stopping criterion is fulfilled.
  • the stopping criterion may require that all the set of training images are processed or that a maximum number of repetitions is reached.
  • steps 103 and 105 may be performed concurrently, e.g., the location of the landmark may be determined in response to identifying the landmark.
  • the method may be repeated for each further set of training images, wherein the training dataset is updated/increased with new entries obtained for each further set of training images.
  • FIG. 6A is a diagram illustrating a method for determining locations of landmarks in a training image (or inference image) 130 of a human face 134 in accordance with an example of the present subject matter.
  • a local coordinate system 131 may be used.
  • Fig.6A further shows an absolute coordinate system 135.
  • the absolute coordinate system 135 may be a world coordinate system.
  • the local coordinate system 131 may be defined by an origin 132 and three orthogonal directions.
  • the origin may be a specific point of the human face 134. In one example, the origin may be a user defined point. Alternatively, the origin may be a randomly selected point of the human face. Alternatively, the origin may be a center point of the human face or center of mass point of the human face.
  • the locations of the landmarks of the human face 134 may be determined with respect to the local coordinate system 131 e.g., the location may be provided by a direction vector between the landmark and the origin 132. The locations may be provided as 3D coordinates representing the three directions. [0149] In one example, initial locations of the landmarks of the human face 134 may first be determined with respect to the absolute coordinate system 135 and then a transformation from the absolute coordinate system 135 to the local coordinate system 131 may be applied to the initial locations in order to obtain locations in the local coordinate system 131. [0150] Fig.
  • FIG. 6B is a diagram illustrating a method for determining locations of landmarks in a training image (or inference image) 150 of human eyes 154 in accordance with an example of the present subject matter.
  • a local coordinate system 151 may be used.
  • Fig.6B further shows an absolute coordinate system 155.
  • the absolute coordinate system 155 may be a world coordinate system.
  • the local coordinate system 151 may be defined by an origin 152 and two orthogonal directions.
  • the origin may be a specific point of the eyes 154. In one example, the origin may be a user defined point. Alternatively, the origin may be a randomly selected point of the eyes. Alternatively, the origin may be a center point of the eyes.
  • the locations of the landmarks of the eyes 154 may be determined with respect to the local coordinate system 151 e.g., the location may be provided as a direction vector between the landmark and the origin 152. The locations may be provided as 2D coordinates representing the two directions. [0153] In one example, initial locations of the landmarks of the eyes 154 may first be determined with respect to the absolute coordinate system 155 and then a transformation from the absolute coordinate system 155 to the local coordinate system 151 may be applied to the initial locations in order to obtain locations in the local coordinate system 151.
  • Fig.7 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed training image detection in accordance with an example of the present subject matter.
  • the training dataset may be generated using a set of training images of one specific object type such as the human face.
  • the set of training images may represent faces of different individuals (objects) or of the same individual.
  • a training image of the specific object type of the set of training images may be received in step 201.
  • the training image may be received from a local storage of the computer system.
  • the training image may be received from a remote database system in which the training image is stored e.g., step 201 may be performed in response to sending a request to the database system.
  • a set of landmarks of the object may be identified in step 203 in accordance with a landmark pattern.
  • the landmark pattern may be provided in advance for the specific object type of the set of training images. Alternatively, the landmark pattern may be determined in step 203 for the object type of the training image.
  • Locations of the set of landmarks may be determined in step 205 with respect to a coordinate system defined relative to the object.
  • An entry may be added in step 207 to the training dataset. The entry indicates the set of locations and a label, wherein the label indicates whether the received training image is a real training image or morphed training image.
  • steps 201 to 207 may be repeated for each further training image of the set of training images.
  • Fig.8 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed training image detection in accordance with an example of the present subject matter.
  • the training dataset may be generated using a set of training images of different object types such as the human face, human hand, eyes etc.
  • a training image of the set of training images may be received in step 301.
  • the training image may be received from a local storage of the computer system.
  • the training image may be received from a remote database system in which the training image is stored e.g., step 301 may be performed in response to sending a request to the database system.
  • the object type represented by the training image may be determined in step 303. The determination of the object type may, for example, be performed using a computer vision technique.
  • a landmark pattern of the determined object type may be created or selected among provided landmark patterns.
  • a set of landmarks of the object may be identified in step 307 in accordance with the landmark pattern.
  • Locations of the set of landmarks may be determined in step 309 with respect to a coordinate system defined relative to the object in the training image.
  • An entry may be added in step 311 to the training dataset. The entry indicates the set of locations and a label, wherein the label indicates whether the received training image is a real training image or morphed training image.
  • steps 301 to 311 may be repeated for each further training image of the set of training images. The repetition may be performed until a stopping criterion is fulfilled.
  • the stopping criterion may require that all the set of training images are processed or that a maximum number of repetitions is reached.
  • steps 307 and 309 may be performed concurrently, e.g., the location of the landmark may be determined as the landmark is identified.
  • the method may be repeated for each further set of training images, wherein the training dataset is updated/increased with new entries obtained for each further set of training images.
  • Fig. 9 is a flowchart of a method of determining landmarks of a training imaged object in accordance with an example of the present subject matter. [0173] A training image of an object may be received in step 401.
  • the object may be detected in the training image in step 403. This detection may, for example, be performed using a computer vision technique.
  • the received training image may be cropped in step 405 in an area of the training image defined by the detected object. This may result in a cropped training image.
  • a set of landmarks of the object may be identified in the cropped training image in step 407 in accordance with a landmark pattern. Locations of the set of landmarks may be determined in step 409 with respect to a coordinate system defined relative to the object in the cropped training image.
  • Fig. 10 is a diagram of a data structure representing the training dataset generated in accordance with an example of the present subject matter.
  • the data structure 500 comprises n entries 501.1 through 501.n.
  • FIG. 11 is a block diagram of an exemplary computer system for implementing at least part of the present method in accordance with an example of the present subject matter.
  • the computer system may provide an exmaple implemenation of the user device e.g., shown in Fig.1, Fig.3 or Fig.4.
  • the components of the computer system 602 may include, but are not limited to, one or more processors or processing units 603, a storage system 611, a memory unit 605, and a bus 607 that couples various system components including memory unit 605 to processor 603.
  • the storage system 611 may include for example a hard disk drive (HDD).
  • the memory unit 605 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and/or cache memory.
  • the computer system 602 may also communicate with one or more external devices such as a keyboard, a pointing device, a display 613, etc.; one or more devices that enable a user to interact with computer system 602; and/or any devices (e.g., network card, modem, etc.) that enable the computer system 602 to communicate with one or more other computing devices. Such communication can occur via I/O interface(s) 619. Still yet, the computer system 602 can communicate with one or more networks such as a local area network (LAN), a general wide area network (WAN), and/or a public network (e.g., the Internet) via a network adapter 609.
  • LAN local area network
  • WAN wide area network
  • public network e.g., the Internet
  • the network adapter 609 communicates with the other components of the client system 602 via bus 607.
  • the memory unit 605 is configured to store applications that are executable on the processor 603.
  • the memory unit 605 may comprise an operating system as well as one or more application programs.
  • the application programs comprise instructions that when executed enable to perform at least part of the method described with reference to Fig.3, 4, 5, 7, 8, 9, 12, 13, 14 or 15.
  • Fig.12 is a flowchart of a method for training a classical machine learning model in accordance with an example of the present subject matter. The training may be performed using the training dataset as generated e.g., by the method of Fig. 5. For simplification, Fig. 12 may be described with reference to the data structure of Fig.10.
  • the entries 501.1-n may be processed one by one using the method.
  • the classical machine learning model may, for example, be a deep neural network such as a CNN or a support vector machine.
  • the location information ⁇ ⁇ of the current i-th entry 501.i may be input to the classical machine learning model.
  • the machine learning model may ouput in step 703 a value ⁇ ⁇ indicating whether the training image represented by the location information ⁇ ⁇ is morphed or not.
  • a loss function may be evaluated in step 705 using the value ⁇ ⁇ and the label ⁇ ⁇ of the current entry 501.i.
  • the leanrable weights of the machine learning model may be updated in step 709 and steps 701 to 707 may be repeated for a next entry of the training dataset 500; otherwise, the trained machine learning model may be provided in step 711.
  • the update of the neural network weights may be performed using gradient descent.
  • Fig.13 is a flowchart of a method for training a quantum machine learning model in accordance with an example of the present subject matter. The training may be performed using the training dataset as generated e.g., by the method of Fig. 5. For simplification, Fig.
  • the entries 501.1-n may be processed one by one using the method.
  • the location information ⁇ ⁇ of the current i-th entry 501.i may be input to the quantum machine learning model.
  • the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector in step 803.
  • the quantum state may be changed in step 805 using the learning layer of the quantum machine learning model.
  • the set of measurements of the qubits may be provided in step 807 as an indication whether the training image represented by the location information ⁇ ⁇ is morphed or not.
  • a loss function may be evaluated by a classical computer in step 809 using the output of the model and the label ⁇ ⁇ of the current entry 501.i. In case (811) the loss function does not fulfill a convergence criterion the learnable parameters of the learning layer may be updated in step 813 and steps 801 to 811 may be repeated for a next entry of the training dataset 500, otherwise, the trained quantum machine learning model may be provided in step 815.
  • the update of the learnable parameters may be performed using gradient descent.
  • Fig.14 is a flowchart of a method for training a hybrid classical-quantum machine learning model in accordance with an example of the present subject matter.
  • the training may be performed using the training dataset as generated e.g., by the method of Fig.5.
  • Fig.14 may be described with reference to the data structure of Fig.10.
  • the entries 501.1-n may be processed one by one using the method.
  • the location information stored in each entry of the training dataset may be the set of locations of the set of landmarks of the training image, [0184]
  • the location information ⁇ ⁇ of the current i-th entry 501.i may be input to a first neural network.
  • the first neural network may output a feature vector in response to receiving the location information.
  • the feature vector may be input to the quantum machine learning model.
  • the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector in step 903.
  • the quantum state may be changed in step 905 using the learning layer of the quantum machine learning model.
  • the set of measurements of the qubits may be provided in step 906.
  • a second neural network may receive as input the set of measurements and output in step 907 a value ⁇ ⁇ indicating whether the training image represented by the location information ⁇ ⁇ is morphed or not.
  • a loss function may be evaluated in step 909 using the value ⁇ ⁇ and the label ⁇ ⁇ of the current entry 501.i.
  • Fig.15 is a flowchart of a method for morphed training image detection e.g., by a server, in accordance with an example of the present subject matter.
  • An image of an object may be received by the server in step 1001. The image may be received from a user device through one or more networks.
  • the user device may, for example, be configured to communicate wirelessly with the server using one or more networks.
  • the network may, for example, comprise a mobile network, a local area network (LAN), a general wide area network (WAN), the Internet or a combination thereof.
  • a set of landmarks of the object my be identified in step 1003 in accordance with a landmark pattern. Locations of the set of landmarks may be determined in step 1005 with respect to a coordinate system defined relative to the object. Location information may be input in step 1007 to a trained machine learning model (e.g., which is obtained in Fig. 12, 13 or 14). The location information indicates the set of locations. An output of the trained machine learning model may be received in step 1009 from the trained machine learning model.
  • aspects of the present invention may be embodied as an apparatus, method, computer program or computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit,” “module” or “system.” Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer executable code embodied thereon.
  • a computer program comprises the computer executable code or "program instructions”.
  • the term “computer system” refers to data processing hardware and encompasses all kinds of apparatus, devices, and machines for processing data, including by way of example, a programmable processor, a computer, or multiple processors or com-puters.
  • the apparatus can also be or further include special purpose logic circuitry, e.g., a central processing unit (CPU), a FPGA (field programmable gate array), or an ASIC (application specific integrated circuit).
  • the data pro-cessing apparatus and/or special purpose logic circuitry may be hardware-based and/or software-based.
  • the apparatus can optionally include code that creates an execution environment for computer programs, e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them.
  • code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them.
  • the present disclosure contemplates the use of data processing apparatuses with or without conventional operating systems, for example LINUX, UNIX, WINDOWS, MAC OS, ANDROID, IOS or any other suitable conventional operating system.
  • Any combination of one or more computer readable medium(s) may be utilized.
  • the computer readable medium may be a computer readable storage medium.
  • a ‘computer-readable storage medium’ as used herein encompasses any tangible storage medium which may store instructions which are executable by a processor
  • the computer-readable storage medium may be referred to as a computer-readable non-transitory storage medium.
  • the computer- readable storage medium may also be referred to as a tangible computer readable medium.
  • a computer-readable storage medium may also be able to store data which is able to be accessed by the processor of the computing device.
  • ‘Computer memory’ or ‘memory’ is an example of a computer-readable storage medium.
  • Computer memory is any memory which is directly accessible to a processor.
  • ‘Computer storage’ or ‘storage’ is a further example of a computer- readable storage medium.
  • Computer storage is any non-volatile computer-readable storage medium. In some embodiments computer storage may also be computer memory or vice versa.
  • a ‘processor’ as used herein encompasses an electronic component which is able to execute a program or machine executable instruction or computer executable code.
  • References to the computing device comprising “a processor” should be interpreted as possibly containing more than one processor or processing core.
  • the processor may for instance be a multi-core processor.
  • a processor may also refer to a collection of processors within a single computer system or distributed amongst multiple computer systems.
  • the term computing device should also be interpreted to possibly refer to a collection or network of computing devices each comprising a processor or processors.
  • the computer executable code may be executed by multiple processors that may be within the same computing device or which may even be distributed across multiple computing devices.
  • Computer executable code may comprise machine executable instructions or a program which causes a processor to perform an aspect of the present invention.
  • Computer executable code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages and compiled into machine executable instructions.
  • the computer executable code may be in the form of a high level language or in a pre-compiled form and be used in conjunction with an interpreter which generates the machine executable instructions on the fly.
  • the program instructions can be executed on one processor or on several processors.
  • processors In the case of multiple processors, they can be distributed over several different entities. Each processor could execute a portion of the instructions intended for that entity. Thus, when referring to a system or process involving multiple entities, the computer program or program instructions are understood to be adapted to be executed by a processor associated or related to the respective entity. [0194] While the invention has been illustrated and described in detail in the drawings and foregoing description, such illustration and description are to be considered illustrative or exemplary and not restrictive; the invention is not limited to the disclosed examples.
  • REFERENCE SIGNS LIST 10 morphing detection system 12 one or more networks 11.1-N one or more user devices 13.1-M one or more servers 20 ML model 21 first sub-model 22 second sub-model 23 third sub-model 26 set of locations 27 output 30 image 31-38 method steps 40 image 41-48 method steps 101-107 method steps 130 image 131 local coordinate system 132 origin 135 absolute coordinate system 150 image 151 local coordinate system 152 origin 155 absolute coordinate system 201-207 method steps 301-311 method steps 401-409 method steps 500 data structure 501.1-n entries 603 processing units 605 memory unit 607 bus 609 network adapter 611 storage system 613 display 619 I/O interface 701-711 method steps 801-815 method steps 901-915 method steps 1001-1009 method steps

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Evolutionary Computation (AREA)
  • Multimedia (AREA)
  • Software Systems (AREA)
  • Computing Systems (AREA)
  • Artificial Intelligence (AREA)
  • Computer Vision & Pattern Recognition (AREA)
  • Oral & Maxillofacial Surgery (AREA)
  • Medical Informatics (AREA)
  • Databases & Information Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Biomedical Technology (AREA)
  • Mathematical Physics (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Biophysics (AREA)
  • Data Mining & Analysis (AREA)
  • Computational Linguistics (AREA)
  • Molecular Biology (AREA)
  • Human Computer Interaction (AREA)
  • Image Analysis (AREA)

Abstract

Disclosed is a method comprising receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image, inputting the location information to the trained machine learning model, receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image, sending the output to the user device.

Description

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - IMAGE MORPHING DETECTION - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - FIELD OF THE INVENTION [0001] The disclosure relates to training image morphing, and particularly to a method for image morphing detection. BACKGROUND [0002] Morphing may be a special effect in motion pictures and animations that morphs one training image into another through a seamless transition. Computer software may be used to create morphed training images. However, there is a need for an improved processing of the morphed training images. [0003] Document “Towards Detection of Morphed Face Training images in Electronic Travel Documents” published in 201813th IAPR International Workshop on Document Analysis Systems (DAS) discloses automated morph detection algorithms based on general purpose pattern recognition algorithms. SUMMARY [0004] Example embodiments provide a method (also referred to as first morphing detection method) for morphed image detection, the method comprising: receiving by a user device an image of an object; identifying by the user device a set of landmarks of the object in accordance with a landmark pattern; determining by the user device locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending by the user device a location information to a remote server, the location information indicating the set of locations, the remote server comprising a trained machine learning model; receiving the location information by the remote server; inputting by the remote server the location information to the trained machine learning model; receiving by the remote server an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image; sending the output by the remote server to the user device; receiving the output by the user device; using by the user device the output for rejecting or accepting the received image. [0005] Example embodiments provide a method (also referred to as second morphing detection method) for morphed image detection, the method comprising: receiving by a user device an image of an object; sending by the user device the image to a remote server, the remote server comprising a training machine learning model; receiving the image by the remote server; identifying by the remote server a set of landmarks of the object in accordance with a landmark pattern; determining by the remote server locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting by the remote server a location information to the trained machine learning model, the location information indicating the set of locations; receiving by the remote server an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image; sending the output by the remote server to the user device; receiving the output by the user device; using by the user device the output for rejecting or accepting the received image. [0006] Example embodiments provide a morphing detection system comprising a server and user device, the user device and the server being configured to perform the first morphing detection method or the second morphing detection method. [0007] Example embodiments provide a computer program comprising instructions which, when the program is executed by a user device and a server, cause the user device and the server to perform the first morphing detection method or the second morphing detection method. [0008] Example embodiments provide a method for morphed image detection comprising: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to the trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device. [0009] Example embodiments provide a server being configured for: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to the trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device. [0010] Example embodiments provide a computer program comprising instructions which, when the program is executed by a server, cause the server to perform at least the following: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to the trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device. [0011] Example embodiments provide a method for morphed image detection, the method comprising: receiving by a user device an image of an object; identifying by the user device a set of landmarks of the object in accordance with a landmark pattern; determining by the user device locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending by the user device a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non-morphed image; using the output for rejecting or accepting the received image. [0012] Example embodiments provide a user device for morphed image detection, the user device being configured for: receiving an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non-morphed image; using the output for rejecting or accepting the received image. [0013] Example embodiments provide a computer program comprising instructions for causing a user device for performing at least the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non-morphed image; using the output for rejecting or accepting the received image. [0014] Example embodiments provide a method for morphed image detection. The method comprises: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device. [0015] Example embodiments provide a server for morphed image detection. The server is configured for: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device. [0016] Example embodiments provide a computer program comprising instructions for causing a server for performing at least the following: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device. [0017] Example embodiments provide a method (referred to as training data generation method) of generating a training dataset for training a machine learning model for morphed image detection. The method comprises: receiving at least one landmark pattern; repeatedly performing the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with the received landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; and adding an entry to the training dataset, the entry indicating the set of locations and a label, wherein the label indicates whether the received image is a real image or morphed image. [0018] Example embodiments provide a computer system of generating a training dataset for training a machine learning model for morphed image detection. The computer system is configured for: receiving at least one landmark pattern; repeatedly performing the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with the received landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; and adding an entry to the training dataset, the entry indicating the set of locations and a label, wherein the label indicates whether the received image is a real image or morphed image. [0019] Example embodiments provide a computer program comprising instructions for causing a computer system for performing at least the following: receiving at least one landmark pattern; repeatedly performing the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with the received landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; and adding an entry to the training dataset, the entry indicating the set of locations and a label, wherein the label indicates whether the received image is a real image or morphed image. [0020] Example embodiments provide a computer implemented data structure comprising training data for a morphed image detection model, the data structure comprising entries, wherein the entry comprises location information indicating a set of landmark locations of an imaged object, and a label indicating a real image or morphed image, the landmark locations being relative locations. BRIEF DESCRIPTION OF THE DRAWINGS [0021] In the following, examples are described in greater detail making reference to the drawings in which: [0022] Fig.1 is a schematic diagram of a morphing detection system in accordance with an example of the present subject matter. [0023] Fig.2A is a diagram illustrating a machine learning model in accordance with an example of the present subject matter. [0024] Fig.2B is a diagram illustrating a machine learning model in accordance with an example of the present subject matter. [0025] Fig.3 is a signaling diagram illustrating a method for morphing detection in accordance with an example of the present subject matter. [0026] Fig.4 is a signaling diagram illustrating a method for morphing detection in accordance with an example of the present subject matter. [0027] Fig.5 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter. [0028] Fig. 6A is a diagram illustrating a method for determining locations of landmarks in an image of a human face in accordance with an example of the present subject matter. [0029] Fig. 6B is a diagram illustrating a method for determining locations of landmarks in an image of a human eyes in accordance with an example of the present subject matter. [0030] Fig.7 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter. [0031] Fig.8 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed image detection in accordance with an example of the present subject matter. [0032] Fig. 9 is a flowchart of a method of determining landmarks of an imaged object in accordance with an example of the present subject matter. [0033] Fig. 10 is a diagram of a data structure representing the training dataset generated in accordance with an example of the present subject matter. [0034] Fig. 11 is a block diagram of an exemplary computer system for implementing at least part of the present method in accordance with an example of the present subject matter. [0035] Fig.12 is a flowchart of a method for training a classical machine learning model in accordance with an example of the present subject matter. [0036] Fig.13 is a flowchart of a method for training a quantum machine learning model in accordance with an example of the present subject matter. [0037] Fig. 14 is a flowchart of a method for training a hybrid classical-quantum machine learning model in accordance with an example of the present subject matter. [0038] Fig.15 is a flowchart of a method for automatic morphed image detection in accordance with an example of the present subject matter. DETAILED DESCRIPTION [0039] In the following description, for purposes of explanation and not limitation, specific details are set forth such as particular architectures, interfaces, techniques, etc., in order to provide a thorough understanding of the examples. However, it will be apparent to those skilled in the art that the disclosed subject matter may be practiced in other illustrative examples that depart from these specific details. In some instances, detailed descriptions of well-known devices and/or methods are omitted so as not to obscure the description with unnecessary detail. [0040] Authentication may be a process for verifying the identity of persons. This may, for example, enable to keep unauthorized persons from accessing sensitive information or services. For example, based on the authentication result of a user, access control signals may be generated to enable the user to access controlled services or controlled areas. The authentication may be performed using an image of the user. For example, an automated border control system or eGate may use the image to verify the user's identity. After the user's identity is verified, a physical barrier such as a gate opens to permit passage. The image may provide a visual representation of the user. The image of the user may be obtained by imaging the user’s face e.g., using a camera. Alternatively, the image of the user may be a reproduced version that is captured from an identity token of the user. The image may be stored in a memory as a digital image. The identity token may, for example, be an identification (ID) card, visa, driver's license, vehicle registration document, health card, company ID card, bank card, or another ID document which carries an identity-linked field comprising a photo of the user. In another example, the identity token may be provided in the form of an ID application installed on a user's mobile portable terminal. In this case, the user's image may be provided, for example, on a display of the user's mobile portable terminal. [0041] However, the images may be morphed. Morphing refers to the changing of one image to obtain a morphed image. The morphing may, for example, modify an image of a given object such that the resulting object resembles the given object. The morphing may be misused to, for example, create a double–identity face image, a double–identity fingerprint or a double–identity iris, or to perform cyberattacks by creating hoax images. For example, in case of face morphing, a misuse of the morphing can enable two individuals to use one identity document. In another example, a fake fingerprint may be created using morphing so that it can be used to identify two different fingers. Thus, the detection of such morphed images may prevent cyberattacks and fake identities. Different techniques may be used to detect morphed images. For example, machine learning models may be used to detect morphed images. [0042] Inference phase [0043] The present subject matter may detect morphed images by inferring the machine learning model. This may enable a secure execution of tasks which are based on imaged objects, the tasks being, for example, authentication tasks or access control tasks. For example, the inference image may be an image of a human face, wherein the first morphing detection method or the second morphing detection method may be used for passport image verification during the passport application process or during check of the passports. In addition, the first morphing detection method may be advantageous as it may enable a full processing of the image on the server side. This may enable to use user devices with less computing power. The second morphing detection method may save network resources e.g., bandwidth, by transmitting the location information instead of the whole image. [0044] At least the user device and the server may be provided. The user device may be a device that is operable by a human operator to originate or receive user communication data including, for example, text and images. The user device may include, but is not limited to, a cellular telephone, smartphone, personal computer, desktop computer, laptop or PDA. The user device may, for example, be configured to communicate with the server using one or more networks. The user device may, for example, be configured to communicate wirelessly with the server using one or more networks. The network may, for example, comprise a mobile network, a local area network (LAN), a general wide area network (WAN), the Internet or a combination thereof. The server may thus be referred to as remote server. The remote server (also referred to as server computer) may refer to a computer system. The remote server may comprise a quantum processing unit (QPU). The quantum processing unit may be a component that may be used to perform quantum computations by operating one or more qubits. The quantum processing unit may, for example, be a chip that contains a number of (interconnected) qubits. The server may further comprise a classical processing component. The classical processing component may, for example, control the qubit(s) to perform quantum operations on the qubits in order to execute the machine learning model. The classical processing component may, for example, comprise a CPU, a memory and a FPGA. The classical processing component may, for example, generate and provide as output one or more control signals to the qubits in the quantum processing unit. The control signals may, for example, comprise electromagnetic signals, electrical signals, magnetic signals, optical signals (such as laser pulses), or a combination thereof. [0045] In one example, the user device may comprise an application that when executed may display a user interface on the user device. The user interface may, for example, comprise one or more interface elements that enable to upload the inference image, wherein the receiving of the inference image by the user device comprises uploading the inference image by a user through the user interface element. Alternatively, the user device may automatically receive the inference image e.g., from another device using a communication protocol such as File Transfer Protocol (FTP) protocol. [0046] The image received by the user device may be referred to as inference image. In one example, the server may comprise the (whole) machine learning model for enabling execution of the first morphing detection method. However, for the execution of the second morphing detection method, the server may or may not comprise the whole machine learning model. [0047] According to one example, the machine learning model may comprise a quantum machine learning model or a classical machine learning model or a hybrid classical-quantum machine learning model. The location information that is input to the machine learning model may be the determined set of locations of the set of landmarks or may be a feature vector that is generated from the set of locations. [0048] According to one example, the machine learning model comprises a first sub- model and a second sub-model, wherein the first sub-model is configured to receive the set of locations and to predict a feature vector that represents the inference image, wherein the second sub-model is configured to receive the feature vector and to predict the output. In this case, the server may comprise the second sub- model while the user device may comprise the first sub-model. This may prevent a leak of information regarding the input of the machine learning model that would otherwise happen if the input has to be transmitted through the network to the first sub-model which may be stored on the server. [0049] According to one example, the second sub-model is a classical machine learning model (e.g., a CNN) or a quantum machine learning model or a hybrid classical-quantum machine learning model. The quantum machine learning model may, for example, be a quantum neural network (QNN), a quantum convolutional neural network (QCNN), or a quantum support vector machine (QSVM). The output of the quantum machine learning model may be provided as the measurement of one or more qubits of the quantum processing unit. [0050] According to one example, the first sub-model is a neural network. The first sub-model may, for example, be a deep neural network such as a CNN or a support vector machine. [0051] According to one example, the first sub-model is comprised in the user device or in the server, wherein the second sub-model is comprised in the server. [0052] According to one example, the machine learning model may comprise a third sub-model that is configured to receive the output or measurement(s) of the second-sub model and provide a prediction of the inference image being morphed or not morphed image. [0053] According to one example, the third sub-model is a neural network. The third sub-model may, for example, be a deep neural network such as a CNN or a support vector machine. [0054] According to one example, the third sub-model is comprised in the server. [0055] According to one example, the user device and/or the server are provided as cloud services. The server may, for example, be a cloud server which is deployed on a public cloud, a private cloud or a hybrid cloud. [0056] According to one example, the first morphing detection method may be implemented by a mobile app. According to one example, the second morphing detection method may be implemented by a mobile app. For example, the mobile app may be launched on the user device in order to perform the first morphing detection method or the second morphing detection method. The launching of the mobile app may, for example, display a user interface for uploading the inference image to the user device. In response to receiving the output from the server, a result of the inference may be displayed on the user interface, wherein the result may be obtained using the output received from the server. Using the mobile app may enable a seamless integration of the present subject matter in existing systems. [0057] The inference image may, for example, be a visual representation of an object or subject. The inference image of the object may be obtained by imaging the object e.g., using a camera. Alternatively, the inference image of the object may be a reproduced version that is captured from a document comprising the image of the object. For example, the set of landmarks may be identified in the inference image in accordance with a landmark pattern. The landmark pattern may be a predefined landmark pattern or a dynamically created landmark pattern. The landmark may refer to a specific point of the object. The locations of the set of landmarks may, for example, be determined with respect to a coordinate system defined relative the object. The locations of the set of landmarks may, thus, be relative locations. [0058] Hence, instead of using a whole image for inference, only a selected set of landmarks is used to represent the inference image. In addition, the landmarks are located relative to the object using a local coordinate system. This may, thus, enable a faster inference of the machine learning model. [0059] The object that is represented in the inference image may refer to a tangible, physical object capable of being rendered in an image. The object may be any object whose visual representation in an image may be morphed. The object may be of a specific object type. In one example, the object type may be an individual, a body part, a human face, human eyes, fingerprints, animal face etc. Covering different object types may enable a wider application of the present subject matter e.g., the machine learning model may be used in face recognition systems, fingerprint recognition systems, and iris recognition systems to detect morphed images. [0060] According to one example, the machine learning model may be trained to detected morphed images of human faces. According to one example, the object in the inference image is a human face. [0061] In one example, a pre-processing of the inference image may be performed before using the pre-processed image to determine whether it is morphed. The pre- processing may, for example, comprise the reduction of the size of the inference image. This may save processing resources required for determining the set of landmarks. The inference image may be pre-processed in order to have one size that is common to other inference images. In addition, pixels of the inference image may be represented by a vector (e.g., tensor). The vector may have fields, wherein the fields may include the pixel width, the pixel height, and pixel value(s) such as red, green, blue (RGB) values. This may enable a uniform representation of the inference image. [0062] For example, a set of landmarks may be used to represent the inference image. The landmark may refer to a specific point of the object. The set of landmarks may be defined as points bearing key information on the geometry of the object. In case the object is a human face, for example, the landmark may be a right eyebrow lateral point, right eyebrow medial point, left eyebrow lateral point, left eyebrow medial point, right eye lateral canthus etc. The set of landmarks may be identified using a landmark pattern. The landmark pattern may indicate features of the object which enable to identify the object and its structure. The landmark pattern may indicate a maximum number of landmarks and/or the landmarks per feature and/or the densities of landmarks and/or distances between landmarks. The landmark pattern may be a user defined pattern or may be defined by a computer- implemented tool. For example, the landmark pattern may be determined using distinctive features of the object in the inference image. In case the object is a human face, the distinctive features may include eye spacing, nose length, mouth width, head eccentricity etc. [0063] In one example, a landmark pattern may be provided per object type. For example, the identification of the set of landmarks in the inference image may be performed by: determining the object type represented by the inference image, selecting from predefined landmark patterns the landmark pattern associated with the determined object type and using the selected landmark pattern to identify the set of landmarks in the inference image. [0064] In one example, the object represented in the inference image may be detected in the image. The object may, for example, be detected using a computer vision technique that identifies and locates objects within an image. An area of the inference image defined by the detected object may be cropped. This may result in a cropped image. The set of landmarks are then identified in the cropped image and the locations are determined using the cropped image. This may enable to determine the landmarks after the object is detected and cropped. Thus, the landmarks may not depend on the location of the object within the inference image or on the distance of the object to the camera. This may significantly reduce the amount of data necessary to infer the machine learning model. [0065] The present subject matter may use different advantageous techniques to provide the landmark pattern(s). In one example, for each object type a reference image that represents the object type may be provided. The landmark pattern(s) may be determined using the respective reference image(s). In one example, a feature extraction tool may be used to extract the features that identify the object structure from the reference image. The landmark pattern may be defined by assigning to each feature of the extracted features zero or more landmarks that would represent the feature. The landmark pattern may indicate the position of the landmarks with respect to the respective feature e.g., it may indicate 10 landmarks surrounding the eye of a human face etc. This example may enable to define a priori landmark patterns which may be used during the inference. [0066] In another example, a trained machine learning model may be used to create the landmark pattern that identifies the structure of the object in the inference image. This may enable to create the landmark pattern dynamically or automatically during the inference. In this example, the creation of the landmark pattern may enable an automatic identification of the landmarks in the inference image e.g., the creation of the landmark pattern implicitly includes the step of identification of the landmarks. [0067] The set of locations (or positions) of the identified set of landmarks may be determined. In one example, the steps of identifying the set of landmarks of the inference image and the determination of their locations may be performed, e.g., in one step, concurrently or in parallel. This may speedup the inference. Alternatively, the set of locations of each identified set of landmarks may be determined after the set of landmarks is identified. [0068] The set of locations of the set of landmarks of the inference image may be provided as relative locations e.g., which do not depend on the image size. For that, a coordinate system which is defined relative to the object in the inference image may be used to determine the locations of the set of landmarks. The coordinate system may be a local coordinate system associated with the object. The coordinate system may refer to a frame of reference defined by orthogonal directions and an origin. The origin may be a reference point that is part of the object. The origin may be used as a fixed point of reference for the geometry of the surrounding space. The local coordinate system may be defined per object type. Using a fixed point per object type as origin may provide locations which accurately reflect the shape of the object. The location of each landmark may be provided as coordinates relative to the point of origin. The location may be a direction vector in the local coordinate system. The location of the landmark may, for example, refer to a three-dimensional measurement from a position of the landmark to the origin. [0069] In another example, initial locations of the set of landmarks of the inference image may be determined in a first coordinate system (e.g., an absolute coordinate system). In addition, a transformation of the first coordinate system to the local coordinate system may be applied to the initial locations. This may result in the locations of the set of landmarks of the inference image which are determined in the local coordinate system. [0070] In one example, the local coordinate system may be a three-dimensional, 3D, coordinate system. The set of landmark locations may be provided as 3D coordinates. The set of locations of the set of landmarks may thus describe the three-dimensional geometry of the object. This may provide an accurate position of the landmarks and accurate distinction between the set of landmarks in three dimensions. This may enable more efficient morphed image detection, because the morphing algorithms may generate specific patterns in the three-dimensional geometry of the thusly created objects. [0071] In one example, the local coordinate system may be a two-dimensional, 2D, coordinate system. The set of landmark locations may thus be provided as 2D coordinates. Compared to 3D coordinates, this may save processing resources such as storage resources while still providing reliable results. For example, each entry of the training dataset may comprise the tuple (3D coordinates, label) or (2D coordinates, label). [0072] The present subject matter may further reduce the size of the input data while still providing accurate representation of the input data. For that, the set of locations of the set of landmarks of the inference image may be represented by a feature vector in a predefined k-dimensional feature space having the dimension k which is smaller than the number of landmarks identified in the inference image. The location information which is input to the machine learning model may be the feature vector. The feature space may refer to a k-dimensional space spanned up by k different features used to characterize the set of landmark locations e.g., a feature may be the number of locations, location density etc. In one example, the k different features may be determined, and the set of locations of the set of landmarks of the inference image may be used to evaluate the k different features, and the resulting evaluations may be provided as the feature vector. The k different features may be user determined features or automatically determined features e.g., using machine learning techniques. [0073] In one example, the feature vector may be determined using transfer learning. The transfer learning may be used to apply knowledge gained while solving another task which is related to the morphing detection task. For example, knowledge gained while learning to recognize the objects may be applied when trying to detect morphing of the objects. [0074] In one example, the set of locations of the set of landmarks of the inference image may be represented with the feature vector using a linear transformation of a vector (y) representing the set of locations into the feature vector (x), using a weight matrix (W), where y= x×W. The linear transformation may, for example, be user defined e.g., the weight matrix may be a user defined matrix. Alternatively, the weight matrix may comprise learnable weights which may be provided using the transfer learning. For example, another machine learning model having the weight matrix W as a trainable weight matrix may have been trained to generate the feature vector from a set of landmark locations (e.g., for object recognition). The weight matrix W may thus be transferred from this other machine learning model in order to be used with the present example. [0075] In one example, the set of landmark locations of the set of landmarks of the inference image may be represented with the feature vector using a trained neural network (referred to herein as first neural network or first sub-model) comprising a fully connected layer having nodes representing the set of locations and an output layer representing the feature vector. The first neural network is configured to receive the set of locations of the set of landmarks of the inference image and to output the feature vector. [0076] In one example, the size k of the feature vector that represents the object of the inference image may be defined based on the number of qubits in a quantum processing unit (QPU) that enables to train a quantum machine learning model to detect morphed images. The size of the feature vector may, for example, be provided based on the encoding scheme used by the quantum machine learning model for encoding classical data into quantum states. For example, the size k of the feature vector may be equal to the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the angle encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states. Alternatively, the size k of the feature vector may be smaller than the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the amplitude encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states. [0077] In one example, the output of the trained machine learning model may be used to perform authentication of a user. If the image of the user is not morphed this may indicate that the user’s identity is authentic. The authenticated user may be allowed to get access to services. The computer system may, for example, be configured to generate a control signal for enabling access to the services by the authenticated user. [0078] In one example application, an electric gate may be provided. The electric gate comprises an electric gate motor that enables it to automatically open and close. If the output of the trained model indicates that the user is authenticated, the user may be enabled access to an area by sending a control signal to the electric gate motor to open the electric gate. The electric gate may, for example, be a sliding door. [0079] According to one example, the machine learning model was trained using a training dataset. The training dataset may, for example, be obtained by the training data generation method. The machine learning model may be retrained in response to any one of: the training dataset is updated, or a validity time is expired, wherein the retraining is performed using an updated training dataset. The training dataset may be updated by adding entries to and/or removing entries from the training dataset. For example, after expiry of the validity time period, the training dataset may be updated and the machine learning model may be retrained using the updated training dataset. This may enable an up-to-date model which may improve the morphed image detection efficiency. [0080] According to one example, the training or retraining of the machine learning model may comprise for each entry of the training dataset: the location information of the entry may be input (b1) to the machine learning model. In response, the machine learning model may output (b2) a value indicating whether the training image represented by the location information is morphed or not. A loss function may be evaluated (b3) using the value and the label of the entry. In case the loss function does not fulfill a convergence criterion, the learnable weights of the machine learning model may be updated and steps b1 to b3 may be repeated for a next entry of the training dataset; otherwise, the trained machine learning model may be provided. The update of the weights may, for example, be performed using gradient descent. [0081] Training phase [0082] The present subject matter may provide optimal training data for training and/or retraining the machine learning model which may subsequently be used in the inference phase. The resulting trained model may have a higher detection efficiency of morphed image. The efficiency may be defined as the ration of the number of detected morphed images and the total number of morphed images which are input to the model. [0083] A training dataset may be generated in order to train the machine learning model to detect morphed images. The training dataset may be created using a set of images. The image used for creating the training dataset may be referred to as training image. The training image may, for example, be a visual representation of an object or subject. The training image of the object may be obtained by imaging the object e.g., using a camera. Alternatively, the training image of the object may be a reproduced version that is captured from a document comprising the training image of the object. For each training image of the set of training images, a set of landmarks of the object that is represented in the training image may be identified. For example, the set of landmarks may be identified in the training image in accordance with a landmark pattern. The landmark pattern may be a predefined landmark pattern or a dynamically created landmark pattern. The landmark may refer to a specific point of the object. The locations of the set of landmarks may, for example, be determined with respect to a coordinate system defined relative the object. The locations of the set of landmarks may, thus, be relative locations. For each training image of the set of training images, an entry may be included in the training dataset. The entry may comprise a location information (which may be referred to as ^^, where the subscript ^ refers to the training image) indicating the set of locations and a label indicating whether the training image is a real training image (i.e., non-morphed training image) or morphed training image. [0084] For example, each entry of the training dataset may comprise a tuple (^^, ^^^^^^), where ^^ is the location information determined for the ^-th training image of the set of training images and the ^^^^^^ is the label of the ^-th training image. In one example, the training dataset may be stored in a storage system of the computer system. The computer system may control access to the training dataset. For example, the computer system may define permissions, such as read permission and execute permissions, for access to the training dataset. One or more users may use the training dataset based on permissions which are assigned to the users. [0085] Hence, instead of using a whole training image as a training entry, only a selected set of landmarks is used to represent the training image. In addition, the landmarks are located relative to the object using a local coordinate system. The training data may, thus, enable a faster training of machine learning models. The resulting trained model may efficiently detect morphed training images. [0086] The object that is represented in each training image of the set of training images may refer to a tangible, physical object capable of being rendered in a training image. The object may be any object whose visual representation in a training image may be morphed. The object may be of a specific object type. In one example, the object type may be an individual, a body part, a human face, human eyes, fingerprints, animal face etc. Covering different object types may enable a wider application of the present subject matter e.g., the resulting trained model may be used in face recognition systems, fingerprint recognition systems, and iris recognition systems to detect morphed training images. [0087] The present subject matter may advantageously control the number and types of the objects in the set of training images in order to find a desired balance between efficiency of the resulting trained model and the extent of application of the trained model. For example, the set of training images used to generate the training dataset may be a homogeneous set of training images or a heterogeneous set of training images. The homogenous set of training images may represent objects of the same object type, while the heterogeneous set of training images may represent objects of different object types. [0088] The homogeneous set of training images may be advantageous for the following reasons. The homogeneous set of training images may enable a systematic and faster generation of the training dataset compared to training images of different object types e.g., with the homogenous set of training images a smaller number e.g., one, of landmark patterns may be sufficient to find the landmarks in all set of training images. The homogeneous set of training images may provide homogeneous training samples, wherein the homogeneous training samples may have higher affinity among them enabling a fast convergence of the training process when applied on the created training dataset. The homogeneous set of training images may enable a trained model that is more efficient in detecting any other morphed training image of the object type represented by the set of training images. In one example, the homogenous set of training images may be training images of one object type e.g., the set of training images may be training images of human faces, wherein the human faces may be of a same or different individuals. [0089] The heterogeneous set of training images may be advantageous for the following reasons. The heterogeneous set of training images may provide a larger training dataset due to the availability of a higher number of training images. The heterogeneity may allow to build a robust learning system by leveraging the intrinsic knowledge among data. Indeed, with a set of training images of different object types, the model may learn different morphing techniques, and may thus enable a morphing detection that works well not only for one specific type of morphing (e.g., face morphing) but also for other types of morphing. The heterogeneous set of training images may thus enable a wider application of the present subject matter while still providing reliable detection results. In one example, the heterogeneous set of training images may be training images of different object types. The different object types may be human face, human eyes, animal face, fingerprints etc. [0090] The present subject matter may advantageously control the set of training images in order to balance the training dataset with respect to a set of training image attributes. The set of training image attributes may, for example, comprise at least one of lighting conditions, background color, skin tone, facial expression and any other attribute descriptive of a training image or of the object represented in the training image. Each training image of the set of training images may have a specific set of values of the set of training image attributes respectively. For example, the set of training images may comprise multiple subsets of training images, each subset having a distinct set of values of the set of training image attributes. For example, the number of subsets of the training images may be higher than a threshold. This may enable to control the level of diversity of the set of training images. For example, the first subset training images may have a first set of values of the set of training image attributes, the second subset training images may have a second set of values of the set of training image attributes, and so forth. Each pair of sets of values (e.g., the first set and second set of values) of the training image attributes may differ in at least one training image attribute. Using different attribute values in the set of training images may enable landmarks which are independent from background, lighting conditions, skin tone etc. This may significantly reduce the amount of data necessary to train the machine learning model. According to one example, the set of training images may be provided as the homogeneous set of training images comprising the multiple subsets. Alternatively, the set of training images may be provided as the heterogeneous set of training images comprising the multiple subsets. [0091] The set of training images may, for example, comprise training images of different resolutions. In one example, the set of training images may comprise scanned training images of the objects and/or training images of the objects which are captured directly from the objects e.g., by a digital camera. For example, the set of training images may comprise a minimum fraction of training images which are scanned training images. A scanned training image may, for example, be obtained using a photo scanner or a camera for capturing a training image in an identity token. The scanned training images may provide accurate detection in spite of containing only smaller part of data. The resulting trained machine learning model may, for example, be useful for passport image verification during the passport application process or during check of the passports. [0092] The present subject matter may control the process of generation of the training dataset by using different access methods to access the set of training images. In one example, at least part of the set of training images (named retrieved training images) may be retrieved or received from one or more existing database systems. For example, the retrieved training images may be the whole set of training images or a subset of the set of training images. The computer system may be configured to connect to the database systems and request or retrieve the at least part of the set of training images. This may speed up the generation of the training data compared to a local generation of the set of training images. Additionally, or alternatively, at least part of the set of training images (named produced training images) may be produced locally by the computer system. This may save processing resources such as the network resources that would otherwise be required to retrieve training images. For example, the produced training images may be the whole set of training images or a subset of the set of training images. Thus, the set of training images may comprise retrieved training images and/or produced training images. In one example, the produced training images may comprise morphed training images and/or non-morphed training images. In one example, the retrieved training images may comprise morphed training images and/or non-morphed training images. This example may provide a flexible and controllable access to the training images e.g., if one access method is not available, the present subject matter can still use alternative access methods to produce the training data. This may improve the process of generation of the training dataset. [0093] The produced training images of the set of training images may, for example, be obtained as follows. The computer system may receive non-morphed training images. A subset of the received non-morphed training images may be used to generate morphed training images by the computer system in order to obtain said produced training images. The morphed training images may, for example, be generated using one or more morphing algorithms. The morphing algorithm may, for example, be a Generative Adversary Networks (GANs) or landmark-based morphing algorithm. The morphing algorithm may, for example, be a face morphing algorithm that extracts feature points on the face, and based on these feature points training images are partitioned and face morphing is performed. [0094] In one example, a pre-processing of the set of training images may be performed before using the pre-processed training images to generate the training dataset. The pre-processing may, for example, comprise the reduction of the size of the set of training images. This may save processing resources required for determining the set of landmarks. The set of training images may be pre-processed in order to have one size. In addition, pixels of each training image of the set of training images may be represented by a vector (e.g., tensor). The vector may have fields, wherein the fields may include the pixel width, the pixel height, and pixel value(s) such as red, green, blue (RGB) values. This may enable a uniform representation of the set of training images. [0095] In one example, at least part of the set of training images may be processed in parallel in order to generate the training dataset. This may speed up the process of generating the training dataset. Additionally, or alternatively, at least part of the set of training images may be processed sequentially. This may enable a simplified implementation of the training image processing. In one example, the set of training images may be processed in batches, wherein each batch may have a size smaller than a maximum size. For example, the training dataset may be produced in a distributed computing system e.g., each system component of the distributed computing system may process its respective batches of training images, and the resulting training data entries may be combined in one training dataset. [0096] Hence, as described above, the present subject matter may use different techniques to provide and process the set of training images for identification of landmarks. In addition, the present subject matter may provide different techniques to improve the determination of the landmarks. [0097] For example, a set of landmarks may be used to represent each training image of the set of training images. The landmark may refer to a specific point of the object. The set of landmarks may be defined as points bearing key information on the geometry of the object. In case the object is a human face, for example, the landmark may be a right eyebrow lateral point, right eyebrow medial point, left eyebrow lateral point, left eyebrow medial point, right eye lateral canthus etc. The set of landmarks may be identified using a landmark pattern. The landmark pattern may indicate features of the object which enable to identify the object and its structure. The landmark pattern may indicate a maximum number of landmarks and/or the landmarks per feature and/or the densities of landmarks and/or distances between landmarks. The landmark pattern may be a user defined pattern or may be defined by a computer-implemented tool. For example, the landmark pattern may be determined using distinctive features of the object in the training image. In case the object is a human face, the distinctive features may include eye spacing, nose length, mouth width, head eccentricity etc. [0098] In one example, a landmark pattern may be provided per object type of the set of training images. For example, if the set of training images is a homogeneous set of training images, one landmark pattern may be used to generate the set of landmarks of each training image of the set training images. For example, one landmark pattern may be predefined for the whole set of training images so that during the generation of the training dataset the landmark pattern may automatically be used to identify the set of landmarks in each training image of the set of training images. For example, if the set of training images is a heterogeneous set of training images, a distinct landmark pattern may be used per object type to generate the set of landmarks of each training image of that object type. For example, multiple landmark patterns may be predefined for the set of training images. For each received training image of the set of training images, the identification of the set of landmarks in the training image may be performed by: determining the object type represented by the training image, selecting from the predefined landmark patterns the landmark pattern associated with the determined object type and using the selected landmark pattern to identify the set of landmarks in the training image. [0099] In one example, the object represented in each training image of the set of training images may be detected in the training image. The object may, for example, be detected using a computer vision technique that identifies and locates objects within a training image. An area of the training image defined by the detected object may be cropped. This may result in a cropped training image. The set of landmarks are then identified in the cropped training image and the locations are determined using the cropped training image. This may enable to determine the landmarks after the object is detected and cropped. Thus, the landmarks may not depend on the location of the object within the training image or on the distance of the object to the camera. This may significantly reduce the amount of data necessary to train the machine learning model. [0100] The present subject matter may use different advantageous techniques to provide the landmark pattern(s). In one example, for each object type in the set of training images a reference training image of the set of training images that represents the object type may be selected. The selected reference training image may be a randomly selected training image or a training image whose training image attribute values fulfil a predefined selection criterion. The selection criterion may require that the value of each training image attribute of the set of training image attributes has a specific value or is within a specific range of values. The landmark pattern(s) may be determined using the respective reference training image(s). In one example, a feature extraction tool may be used to extract the features that identify the object structure from the reference training image. The landmark pattern may be defined by assigning to each feature of the extracted features zero or more landmarks that would represent the feature. The landmark pattern may indicate the position of the landmarks with respect to the respective feature e.g., it may indicate 10 landmarks surrounding the eye of a human face etc. This example may enable to define a priori landmark patterns which may be used during the generation of the training dataset. [0101] In another example, a trained machine learning model may be used to create the landmark pattern that identifies the structure of the object in each training image of the set of training images. This may enable to create the landmark pattern dynamically or automatically during the generation of the training dataset. In this example, the creation of the landmark pattern may enable an automatic identification of the landmarks in the training image e.g., the creation of the landmark pattern implicitly includes the step of identification of the landmarks. [0102] The set of locations (or positions) of each identified set of landmarks may be determined. In one example, the steps of identifying the set of landmarks of a training image and the determination of their locations may be performed, e.g., in one step, concurrently or in parallel. This may speedup the generation of the training dataset. Alternatively, the set of locations of each identified set of landmarks may be determined after the set of landmarks is identified. [0103] The set of locations of the set of landmarks of each training image of the set of training images may be provided as relative locations e.g., which do not depend on the training image size. For that, a coordinate system which is defined relative to the object in the training image may be used to determine the locations of the set of landmarks. The coordinate system may be a local coordinate system associated with the object. The coordinate system may refer to a frame of reference defined by orthogonal directions and an origin. The origin may be a reference point that is part of the object. The origin may be used as a fixed point of reference for the geometry of the surrounding space. In case more than one object type is covered by the set of training images, the local coordinate system may be defined per object type. Using a fixed point per object type as origin may provide locations which accurately reflect the shape of the object. The location of each landmark may be provided as coordinates relative to the point of origin. The location may be a direction vector in the local coordinate system. The location of the landmark may, for example, refer to a three-dimensional measurement from a position of the landmark to the origin. [0104] In another example, initial locations of the set of landmarks of a training image may be determined in a first coordinate system (e.g., an absolute coordinate system). In addition, a transformation of the first coordinate system to the local coordinate system may be applied to the initial locations. This may result in the locations of the set of landmarks of the training image which are determined in the local coordinate system. [0105] In one example, the local coordinate system may be a three-dimensional, 3D, coordinate system. The set of landmark locations may be provided as 3D coordinates. The set of locations of the set of landmarks may thus describe the three-dimensional geometry of the object. This may provide an accurate position of the landmarks and accurate distinction between the set of landmarks in three dimensions. This may enable more efficient morphed training image detection, because the morphing algorithms may generate specific patterns in the three- dimensional geometry of the thusly created objects. [0106] In one example, the local coordinate system may be a two-dimensional, 2D, coordinate system. The set of landmark locations may thus be provided as 2D coordinates. Compared to 3D coordinates, this may save processing resources such as storage resources while still providing reliable results. For example, each entry of the training dataset may comprise the tuple (3D coordinates, label) or (2D coordinates, label). [0107] Hence, for each ^-th training image of the set training images, a set landmarks may be identified and a set locat ^ ^^ ions ^^^^ , …., ^^^^ may be determined respectively, ≥ 2. Each entry of the resulting training dataset may comprise a tuple (^^, ^^^^^^), where ^^ = is the location information determined for the ^-th training image and which contains the set of locations determined for the ^-th training image. [0108] The present subject matter may further reduce the size of the input data while still providing accurate representation of the input data. For that, for each training image of the set of training images, the set of locations of the set of landmarks of the training image may be represented by a feature vector in a predefined ^- dimensional feature space having the dimension ^ which is smaller than the number of landmarks identified in the training image. In this case, the location information of each entry of the training dataset may be a feature vector. The feature space may refer to a ^-dimensional space spanned up by ^ different features used to characterize the set of landmark locations e.g., a feature may be the number of locations, location density etc. In one example, the ^ different features may be determined, and for each training image of the set of training images, the set of locations of the set of landmarks of the training image may be used to evaluate the ^ different features, and the resulting evaluations may be provided as the feature vector. The ^ different features may be user determined features or automatically determined features e.g., using machine learning techniques. [0109] In one example, the feature vectors may be determined using transfer learning. The transfer learning may be used to apply knowledge gained while solving another task which is related to the morphing detection task. For example, knowledge gained while learning to recognize the objects may be applied when trying to detect morphing of the objects. [0110] In one example, the set of locations of the set of landmarks of the training image may be represented with the feature vector using a linear transformation of a vector (^) representing the set of locations into the feature vector (^), using a weight matrix (^), where ^ = ^ × ^. The linear transformation may, for example, be user defined e.g., the weight matrix may be a user defined matrix. Alternatively, the weight matrix may comprise learnable weights which may be provided using the transfer learning. For example, another machine learning model having the weight matrix W as a trainable weight matrix may have been trained to generate the feature vector from a set of landmark locations (e.g., for object recognition). The weight matrix W may thus be transferred from this other machine learning model in order to be used with the present example. [0111] In one example, the set of landmark locations of the set of landmarks of the training image may be represented with the feature vector using a trained neural network (referred to herein as first neural network) comprising a fully connected layer having nodes representing the set of locations and an output layer representing the feature vector. The first neural network is configured to receive the set of locations of the set of landmarks of the training image and to output the feature vector. [0112] In one example, the size ^ of the feature vector that represents the object of each training image of the set of training images may be defined based on the number of qubits in a quantum processing unit (QPU) that enables to train a quantum machine learning model to detect morphed training images. The size of the feature vector may, for example, be provided based on the encoding scheme used by the quantum machine learning model for encoding classical data into quantum states. For example, the size ^ of the feature vector may be equal to the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the angle encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states. Alternatively, the size ^ of the feature vector may be smaller than the number of qubits which are available in the quantum processing unit. This may particularly be advantageous in case the amplitude encoding scheme is used by the quantum machine learning model for encoding classical data into quantum states. [0113] Hence, for each ^-th training image of the set of training images a feature vector that represents the object in the training image may be provided. The feature vector comprises ^ feature values ^^ ^ ^ , …. ^^ . Each entry of the resulting training dataset may comprise a tuple (^^, ^^^^^^), where ^^ = {^^ ^ , …., ^^ ^ } is the location information determined for the ^-th training image and which contains the feature vector determined for the ^-th training image. The size of the present entry may be smaller than the entry of the previous example as the size of the feature vector {^^ ^ , …., ^^} may be smaller than the size of the set of locations {^^^^ , ^^ ^ ^ …., ^^^^ }. [0114] In one example, the training dataset may be provided as a data structure. The data structure may, for example, comprise a table comprising a column representing the label and one or more columns representing the location information. Alternatively, the data structure may be an Extensible Markup Language (XML) file or JavaScript Object Notation (JSON) file. [0115] The entries of the data structure may, for example, be represented as follows (e.g., in a table): (^^, ^^^^^^), (^^, ^^^^^^), (^^, ^^^^^^), …. Where ^ = {^^ , …., ^^} or ^ = ^ ^^ ^ ^ ^ ^ {^^^^ , …., ^^^^ }, that is the location information may be provided as feature vector or as a set of locations. [0116] After being produced, the training dataset may advantageously be used to train a machine learning model for training image morphing detection. In one example, the machine learning model may comprise a quantum machine learning model or a classical machine learning model or a hybrid classical-quantum machine learning model. The quantum machine learning model may, for example, be a quantum neural network (QNN), a quantum convolutional neural network (QCNN), or a quantum support vector machine (QSVM). The classical machine learning model may, for example, comprise a deep neural network such as a CNN or a support vector machine. The document arXiv:2009.09423 provides an example implementation of CNNs in a quantum environment for training image classification. [0117] The quantum machine learning model may comprise an encoding layer. The encoding layer may be configured to encode the feature vector into a quantum state using a set of qubits. The quantum state may refer to a mathematical entity that provides a probability distribution for the outcomes of each possible measurement on the system of the set of qubits. This may, for example, be performed using an encoding scheme, wherein the encoding scheme may be an angle encoding or amplitude encoding. The encoding of the feature vector into a quantum state may, for example, be done using single qubit Pauli rotation gates (R_X, R_Y, R_Z) which are applied to individual qubits. The encoding layer may or may not entangle the resulting quantum state. That is, the encoding layer may provide for a given feature vector a quantum state which may be an entangled quantum state or unentangled quantum state. The entangling may not involve any input data or trainable parameters as it may be implemented using multi-qubit entangling gates. The entangling may enable to access a higher dimensional state space. [0118] The quantum machine learning model may further comprise a learning layer having one or more trainable or free parameters. The learning layer may be configured to change the quantum state by applying one or more unitary transformations. The learnable parameters may, for example, be the rotation angles of single qubit Pauli rotation gates e.g., the Pauli rotation angle may be applied on each qubit of the set of qubits after the quantum state has been created. The learnable parameters may, for example, comprise a number of rotation angles which is applied to the set of qubits respectively. [0119] The quantum machine learning model may further comprise a measurement layer for measuring the set of qubits after the change is applied. This set of measurements may provide an indication whether the training image represented by the feature vector is morphed or not morphed. A loss function may be evaluated using the set of measurements and the label of the training image. The quantum machine learning model may be trained by backpropagation using the loss function and an optimization technique that is performed by a classical computer. The backpropagation may enable to update of the learnable parameters using gradient descent. The convergence criterion may, for example, require that the loss function exceeds a threshold. The trained quantum machine learning model may be used to determine whether a training image is a morphed training image or not. [0120] In case the feature vector is provided by the first neural network as described herein, the quantum machine learning model and the first neural network may be jointly trained. For example, in each iteration of the training, a set of locations may be input to the first neural network to generate the feature vector, the feature vector is provided as input to the quantum machine learning model, and the resulting set of measurements may provide an indication whether the training image represented by the feature vector is morphed or not morphed. A loss function may be evaluated using the set of measurements and the label of the training image. In case the loss function does not fulfill a convergence criterion, the backpropagation is performed in order to update both the learnable parameters of the quantum machine learning model as well as the weights of the first neural network. The update of the first neural network weights and the learnable parameters may be performed using gradient descent. In case the loss function fulfills the convergence criterion, the resulting trained first neural network and quantum machine learning model may be provided. The convergence criterion may, for example, require that the loss function exceeds a threshold. The trained first neural network and quantum machine learning model may be used to determine whether a training image is a morphed training image or not. [0121] In another example, the training of the quantum machine learning model may be performed jointly with the first neural network and a second neural network, wherein the second neural network is configured to receive as input the set of measurements and to provide as output a value indicating whether the training image is morphed or not. For example, in each iteration of the training, a set of locations may be input to the first neural network to generate the feature vector which is provided as input to the quantum machine learning model which provide in turn the set of measurements as input to the second neural network, the second neural network provides a value indicating whether the training image is morphed or not. A loss function may be evaluated using the set of measurements and the label of the training image. In case the loss function does not fulfill a convergence criterion, the backpropagation is performed in order to update the learnable parameters of the quantum machine learning model the weights of the first neural network and the weights of the second neural network. In case the loss function fulfills the convergence criterion, the resulting trained first neural network, second neural network and quantum machine learning model may be provided. The convergence criterion may, for example, require that the loss function exceeds a threshold. The trained first neural network and quantum machine learning model and second neural network may be used to determine whether a training image is a morphed training image or not. [0122] The present subject matter may, for example, use the trained machine learning model for determining whether a training image is a morphed training image or not morphed training image. For that, a training image of an object may be received. The training image may, for example, be captured from an identity token or may be read from a storage device where the training image is stored. A set of landmarks of the object may be identified in accordance with a landmark pattern. Locations of the set of landmarks may be determined in step with respect to a coordinate system defined relative to the object. Location information may be input to the trained machine learning model. The location information indicates the set of locations. An output of the trained machine learning model may be received from the trained machine learning model. The output indicates whether the received inference training image is a morphed training image or non-morphed training image. [0123] It is understood that one or more of the aforementioned examples may be combined as long as the combined embodiments are not mutually exclusive. [0124] Fig. 1 is a schematic diagram of a morphing detection system 10 in accordance with an example of the present subject matter. The morphing detection system 10 may comprise one or more user devices 11.1 through 11.N. The morphing detection system 10 may further comprise one or more servers 13.1 through 13.M. Each user device of the user devices 11.1 through 11.N may be configured to communicate with one or more of the servers 13.1 through 13.M using one or more networks 12. The network 12 may, for example, comprise a mobile network, a local area network (LAN), a general wide area network (WAN), the Internet or a combination thereof. Each server of the servers 13.1 through 13.M may be configured to communicate with one or more of the user devices 11.1 through 11.N through the network 12. [0125] As shown in Fig.1, the user device may be of different types such as desktop computer, laptop, user equipment or smartphone 11.3. Each server of the servers 13.1 through 13.M may comprise (a copy or instance of) the trained machine learning model 14.1 through 14.M. The machine learning model 14.1 through 14.M may be configured to receive location information representing an image of an object and predict whether the image is morphed or not morphed images. In this example, the machine learning model is fully contained in the server, but it is not limited to, because it may be split over the server and the user device as exemplified in Fig.2A and Fig.2B. [0126] The location information that represents an imaged object may be generated at the sever or at the user device. The user device may send to a respective server the whole image to be inferred by the ML model or send the location information to the respective server. [0127] For example, the user devices 11.1-N may be located in respective passport providing services, e.g., in different cities, and the servers 13.1-13.M may be provided as cloud servers. The images may be of humane faces which may be used as passport photos. [0128] Fig.2A is a diagram illustrating a machine learning model in accordance with an example of the present subject matter. The machine learning model 20 comprises a first sub-model 21 and a second sub-model 22. The first sub-model 21 may be a neural network. The second sub-model 22 may be a quantum machine learning model. The quantum machine learning model may comprise quantum layers such as encoding layer, learning layer and measurement layer. [0129] The machine learning model 20 may be configured to receive as input a set of locations 26 and provide an output 27. The set of locations 26 may be locations of a set of landmarks of an object (e.g., human face) in an image. Figs.6A and 6B provide an example of the image and a method to obtain the set of locations. The output may indicate whether the image is morphed or not morphed. [0130] The first sub-model may output a feature vector in response to receiving the set of locations. The feature vector may be input to the quantum machine learning model. In response, the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector. The quantum state may be changed using the learning layer of the quantum machine learning model. The set of measurements of the qubits of the quantum machine learning model may be provided by the measurement layer. The set of measurements may be used as an indication whether the image represented by the set of locations is morphed or not morphed. [0131] As indicated in Fig. 2A, the first sub-model may be deployed on the user device e.g., 11.1 while the second sub-model may be deployed on the server e.g., 13.1. [0132] Fig.2B is a diagram illustrating a machine learning model in accordance with an example of the present subject matter. The machine learning model 20 comprises a first sub-model 21, a second sub-model 22 and a third sub-model 23. The first sub-model 21 may be a neural network. The second sub-model 22 may be a quantum machine learning model. The second sub-model 23 may be a neural network. The quantum machine learning model may comprise quantum layers such as encoding layer, learning layer and measurement layer. [0133] The machine learning model 20 may be configured to receive as input a set of locations 26 and provide an output 27. The set of locations 26 may be locations of a set of landmarks of an object (e.g., human face) in an image. The output may indicate whether the image is morphed or not. [0134] The first sub-model may output a feature vector in response to receiving the set of locations. The feature vector may be input to the quantum machine learning model. In response, the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector. The quantum state may be changed using the learning layer of the quantum machine learning model. The set of measurements of the qubits of the quantum machine learning model may be provided by the measurement layer. The third sub-model may receive as input the set of measurements and output a value indicating whether the image represented by the location information is morphed or not. [0135] As indicated in Fig. 2B, the first sub-model may be deployed on the user device e.g., 11.1 while the second and third sub-models may be deployed on the server e.g., 13.1. [0136] Fig.3 is a signaling diagram illustrating a method for morphing detection in accordance with an example of the present subject matter. For the purpose of explanation, the method described in Fig. 3 may be implemented in the system illustrated in Fig.1, but is not limited to this implementation. The user device 11.N may receive (31) an image 30 of an object. The user device 11.N may identify a set of landmarks of the object in accordance with a landmark pattern. The user device 11.N may determine (33) location information representing locations of the set of landmarks with respect to a coordinate system defined relative to the object. In this example, the location information may be provided as a feature vector, but it is not limited to, that is generated from the set of locations of the landmarks of the object. The user device 11.N may send (34) the location information to the server 13.1. The location information may be received by the server 13.1. The server 13.1 may input (35) the location information to the trained machine learning model. The server 13.1 may receive (36) an output of the trained machine learning model indicating whether the image 30 is a morphed image or non-morphed image. The output may be sent (37) by the server 13.1 to the user device 11.N. The output may be received by the user device 11.N. The user device 11.N may use (38) the output for rejecting or accepting the received image 30. [0137] Fig.4 is a signaling diagram illustrating a method for morphing detection. For the purpose of explanation, the method described in Fig.4 may be implemented in the system illustrated in Fig.1, but is not limited to this implementation. The user device 11.N may receive (41) an image 40 of an object. The user device 11.N may send (42) the image to the server 13.1. The server 13.1 may identify a set of landmarks of the object in accordance with a landmark pattern. The server 13.1 may determine (43) location information representing locations of the set of landmarks with respect to a coordinate system defined relative to the object. The location information indicates the set of locations. In this example, the location information may be provided as a feature vector, but it is not limited to, that is generated from the set of locations of the landmarks of the object. The server 13.1 may input (45) the location information to the trained machine learning model. The server 13.1 may receive (46) an output of the trained machine learning model indicating whether the image 30 is a morphed image or non-morphed image. The output may be sent (47) by the server 13.1 to the user device 11.N. The output may be received by the user device 11.N. The user device 11.N may use (48) the output for rejecting or accepting the received image 40. [0138] Fig.5 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed training image detection in accordance with an example of the present subject matter. The training dataset may be generated using a set of training images. [0139] A training image of an object may be received in step 101. For example, the training image may be received from a local storage of the computer system. Alternatively, the training image may be received from a remote database system in which the training image is stored e.g., step 101 may be performed in response to sending a request to the database system. [0140] A set of landmarks of the object may be identified in step 103 in accordance with a landmark pattern. [0141] Locations of the set of landmarks may be determined in step 105 with respect to a coordinate system defined relative to the object. Figs.6A and 4B provide an example implementation of step 105. [0142] An entry may be added in step 107 to the training dataset. The entry indicates the set of locations and a label, wherein the label indicates whether the received training image is a real training image or morphed training image. The real training image refers to a non-morphed training image. [0143] As indicated in Fig.5, steps 101 to 107 may be repeated for each further training image of the set of training images. The repetition may be performed until a stopping criterion is fulfilled. The stopping criterion may require that all the set of training images are processed or that a maximum number of repetitions is reached. [0144] In one example implementation of Fig. 5, steps 103 and 105 may be performed concurrently, e.g., the location of the landmark may be determined in response to identifying the landmark. [0145] In one example implementation of Fig.5, the method may be repeated for each further set of training images, wherein the training dataset is updated/increased with new entries obtained for each further set of training images. [0146] Fig. 6A is a diagram illustrating a method for determining locations of landmarks in a training image (or inference image) 130 of a human face 134 in accordance with an example of the present subject matter. For that, a local coordinate system 131 may be used. Fig.6A further shows an absolute coordinate system 135. The absolute coordinate system 135 may be a world coordinate system. [0147] The local coordinate system 131 may be defined by an origin 132 and three orthogonal directions. The origin may be a specific point of the human face 134. In one example, the origin may be a user defined point. Alternatively, the origin may be a randomly selected point of the human face. Alternatively, the origin may be a center point of the human face or center of mass point of the human face. [0148] In one example, the locations of the landmarks of the human face 134 may be determined with respect to the local coordinate system 131 e.g., the location may be provided by a direction vector between the landmark and the origin 132. The locations may be provided as 3D coordinates representing the three directions. [0149] In one example, initial locations of the landmarks of the human face 134 may first be determined with respect to the absolute coordinate system 135 and then a transformation from the absolute coordinate system 135 to the local coordinate system 131 may be applied to the initial locations in order to obtain locations in the local coordinate system 131. [0150] Fig. 6B is a diagram illustrating a method for determining locations of landmarks in a training image (or inference image) 150 of human eyes 154 in accordance with an example of the present subject matter. For that, a local coordinate system 151 may be used. Fig.6B further shows an absolute coordinate system 155. The absolute coordinate system 155 may be a world coordinate system. [0151] The local coordinate system 151 may be defined by an origin 152 and two orthogonal directions. The origin may be a specific point of the eyes 154. In one example, the origin may be a user defined point. Alternatively, the origin may be a randomly selected point of the eyes. Alternatively, the origin may be a center point of the eyes. [0152] In one example, the locations of the landmarks of the eyes 154 may be determined with respect to the local coordinate system 151 e.g., the location may be provided as a direction vector between the landmark and the origin 152. The locations may be provided as 2D coordinates representing the two directions. [0153] In one example, initial locations of the landmarks of the eyes 154 may first be determined with respect to the absolute coordinate system 155 and then a transformation from the absolute coordinate system 155 to the local coordinate system 151 may be applied to the initial locations in order to obtain locations in the local coordinate system 151. [0154] Fig.7 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed training image detection in accordance with an example of the present subject matter. The training dataset may be generated using a set of training images of one specific object type such as the human face. The set of training images may represent faces of different individuals (objects) or of the same individual. [0155] A training image of the specific object type of the set of training images may be received in step 201. For example, the training image may be received from a local storage of the computer system. Alternatively, the training image may be received from a remote database system in which the training image is stored e.g., step 201 may be performed in response to sending a request to the database system. [0156] A set of landmarks of the object may be identified in step 203 in accordance with a landmark pattern. The landmark pattern may be provided in advance for the specific object type of the set of training images. Alternatively, the landmark pattern may be determined in step 203 for the object type of the training image. [0157] Locations of the set of landmarks may be determined in step 205 with respect to a coordinate system defined relative to the object. [0158] An entry may be added in step 207 to the training dataset. The entry indicates the set of locations and a label, wherein the label indicates whether the received training image is a real training image or morphed training image. [0159] As indicated in Fig.7, steps 201 to 207 may be repeated for each further training image of the set of training images. The repetition may be performed until a stopping criterion is fulfilled. The stopping criterion may require that all the set of training images are processed or that a maximum number of repetitions is reached. [0160] In one example implementation of Fig. 7, steps 203 and 205 may be performed concurrently, e.g., the location of the landmark may be determined as the landmark is identified. [0161] In one example implementation of Fig.7, the method may be repeated for each further set of training images, wherein the training dataset is updated/increased with new entries obtained for each further set of training images. [0162] Fig.8 is a flowchart of a method of generating a training dataset for training a machine learning model for morphed training image detection in accordance with an example of the present subject matter. The training dataset may be generated using a set of training images of different object types such as the human face, human hand, eyes etc. [0163] A training image of the set of training images may be received in step 301. For example, the training image may be received from a local storage of the computer system. Alternatively, the training image may be received from a remote database system in which the training image is stored e.g., step 301 may be performed in response to sending a request to the database system. [0164] The object type represented by the training image may be determined in step 303. The determination of the object type may, for example, be performed using a computer vision technique. [0165] In step 305, a landmark pattern of the determined object type may be created or selected among provided landmark patterns. [0166] A set of landmarks of the object may be identified in step 307 in accordance with the landmark pattern. [0167] Locations of the set of landmarks may be determined in step 309 with respect to a coordinate system defined relative to the object in the training image. [0168] An entry may be added in step 311 to the training dataset. The entry indicates the set of locations and a label, wherein the label indicates whether the received training image is a real training image or morphed training image. [0169] As indicated in Fig.8, steps 301 to 311 may be repeated for each further training image of the set of training images. The repetition may be performed until a stopping criterion is fulfilled. The stopping criterion may require that all the set of training images are processed or that a maximum number of repetitions is reached. [0170] In one example implementation of Fig. 8, steps 307 and 309 may be performed concurrently, e.g., the location of the landmark may be determined as the landmark is identified. [0171] In one example implementation of Fig.8, the method may be repeated for each further set of training images, wherein the training dataset is updated/increased with new entries obtained for each further set of training images. [0172] Fig. 9 is a flowchart of a method of determining landmarks of a training imaged object in accordance with an example of the present subject matter. [0173] A training image of an object may be received in step 401. The object may be detected in the training image in step 403. This detection may, for example, be performed using a computer vision technique. The received training image may be cropped in step 405 in an area of the training image defined by the detected object. This may result in a cropped training image. A set of landmarks of the object may be identified in the cropped training image in step 407 in accordance with a landmark pattern. Locations of the set of landmarks may be determined in step 409 with respect to a coordinate system defined relative to the object in the cropped training image. [0174] Fig. 10 is a diagram of a data structure representing the training dataset generated in accordance with an example of the present subject matter. The data structure 500 comprises n entries 501.1 through 501.n. Each i-th entry 501.i of the data structure comprises a tuple (^^, ^^^^^^), where ^^ is the location information determined for the ^-th training image and the ^^^^^^ is the label of the ^-th training image. [0175] Fig. 11 is a block diagram of an exemplary computer system for implementing at least part of the present method in accordance with an example of the present subject matter. The computer system may provide an exmaple implemenation of the user device e.g., shown in Fig.1, Fig.3 or Fig.4. [0176] The components of the computer system 602 may include, but are not limited to, one or more processors or processing units 603, a storage system 611, a memory unit 605, and a bus 607 that couples various system components including memory unit 605 to processor 603. The storage system 611 may include for example a hard disk drive (HDD). The memory unit 605 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and/or cache memory. [0177] The computer system 602 may also communicate with one or more external devices such as a keyboard, a pointing device, a display 613, etc.; one or more devices that enable a user to interact with computer system 602; and/or any devices (e.g., network card, modem, etc.) that enable the computer system 602 to communicate with one or more other computing devices. Such communication can occur via I/O interface(s) 619. Still yet, the computer system 602 can communicate with one or more networks such as a local area network (LAN), a general wide area network (WAN), and/or a public network (e.g., the Internet) via a network adapter 609. As depicted, the network adapter 609 communicates with the other components of the client system 602 via bus 607. [0178] The memory unit 605 is configured to store applications that are executable on the processor 603. For example, the memory unit 605 may comprise an operating system as well as one or more application programs. The application programs comprise instructions that when executed enable to perform at least part of the method described with reference to Fig.3, 4, 5, 7, 8, 9, 12, 13, 14 or 15. [0179] Fig.12 is a flowchart of a method for training a classical machine learning model in accordance with an example of the present subject matter. The training may be performed using the training dataset as generated e.g., by the method of Fig. 5. For simplification, Fig. 12 may be described with reference to the data structure of Fig.10. The entries 501.1-n may be processed one by one using the method. In this example, the location information stored in each entry of the training dataset may be the set of locations of the set of landmarks of the training image, e.g., ^ = ^ ^^ ^ {^^^^ , …., ^^^^ }. The classical machine learning model may, for example, be a deep neural network such as a CNN or a support vector machine. [0180] In step 701, the location information ^^ of the current i-th entry 501.i may be input to the classical machine learning model. In response, the machine learning model may ouput in step 703 a value ^^ indicating whether the training image represented by the location information ^^ is morphed or not. A loss function may be evaluated in step 705 using the value ^^ and the label ^^^^^^ of the current entry 501.i. In case (707) the loss function does not fulfill a convergence criterion, the leanrable weights of the machine learning model may be updated in step 709 and steps 701 to 707 may be repeated for a next entry of the training dataset 500; otherwise, the trained machine learning model may be provided in step 711. The update of the neural network weights may be performed using gradient descent. [0181] Fig.13 is a flowchart of a method for training a quantum machine learning model in accordance with an example of the present subject matter. The training may be performed using the training dataset as generated e.g., by the method of Fig. 5. For simplification, Fig. 13 may be described with reference to the data structure of Fig.10. The entries 501.1-n may be processed one by one using the method. In this example, the location information stored in each entry of the training dataset may be the feature vector of the training image, e.g., ^ ^ ^ ^ = {^^ , …., ^^ }. [0182] In step 801, the location information ^^ of the current i-th entry 501.i may be input to the quantum machine learning model. In response, the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector in step 803. The quantum state may be changed in step 805 using the learning layer of the quantum machine learning model. The set of measurements of the qubits may be provided in step 807 as an indication whether the training image represented by the location information ^^ is morphed or not. A loss function may be evaluated by a classical computer in step 809 using the output of the model and the label ^^^^^^ of the current entry 501.i. In case (811) the loss function does not fulfill a convergence criterion the learnable parameters of the learning layer may be updated in step 813 and steps 801 to 811 may be repeated for a next entry of the training dataset 500, otherwise, the trained quantum machine learning model may be provided in step 815. The update of the learnable parameters may be performed using gradient descent. [0183] Fig.14 is a flowchart of a method for training a hybrid classical-quantum machine learning model in accordance with an example of the present subject matter. The training may be performed using the training dataset as generated e.g., by the method of Fig.5. For simplification, Fig.14 may be described with reference to the data structure of Fig.10. The entries 501.1-n may be processed one by one using the method. In this example, the location information stored in each entry of the training dataset may be the set of locations of the set of landmarks of the training image, [0184] In step 901, the location information ^^ of the current i-th entry 501.i may be input to a first neural network. The first neural network may output a feature vector in response to receiving the location information. In step 902, the feature vector may be input to the quantum machine learning model. In response, the quantum machine learning model may generate using the encoding layer a quantum state representing the feature vector in step 903. The quantum state may be changed in step 905 using the learning layer of the quantum machine learning model. The set of measurements of the qubits may be provided in step 906. A second neural network may receive as input the set of measurements and output in step 907 a value ^^ indicating whether the training image represented by the location information ^^ is morphed or not. A loss function may be evaluated in step 909 using the value ^^ and the label ^^^^^^ of the current entry 501.i. In case (911) the loss function does not fulfill a convergence criterion the learnable parameters of the quantum machine learning model and the weights of the two neural networks may be updated in step 913 and steps 901 to 911 may be repeated for a next entry of the training dataset 500; otherwise, the trained quantum machine learning model as well as the two trained networks may be provided in step 915. The update of the neural network weights and the learnable parameters may be performed using gradient descent. [0185] Fig.15 is a flowchart of a method for morphed training image detection e.g., by a server, in accordance with an example of the present subject matter. [0186] An image of an object may be received by the server in step 1001. The image may be received from a user device through one or more networks. The user device may, for example, be configured to communicate wirelessly with the server using one or more networks. The network may, for example, comprise a mobile network, a local area network (LAN), a general wide area network (WAN), the Internet or a combination thereof. A set of landmarks of the object my be identified in step 1003 in accordance with a landmark pattern. Locations of the set of landmarks may be determined in step 1005 with respect to a coordinate system defined relative to the object. Location information may be input in step 1007 to a trained machine learning model (e.g., which is obtained in Fig. 12, 13 or 14). The location information indicates the set of locations. An output of the trained machine learning model may be received in step 1009 from the trained machine learning model. The output indicates whether the received training image is a morphed training image or non- morphed training image. The output may be sent to the user device in step 1011. [0187] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as an apparatus, method, computer program or computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit,” “module” or “system.” Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer executable code embodied thereon. A computer program comprises the computer executable code or "program instructions". [0188] The term “computer system” refers to data processing hardware and encompasses all kinds of apparatus, devices, and machines for processing data, including by way of example, a programmable processor, a computer, or multiple processors or com-puters. The apparatus can also be or further include special purpose logic circuitry, e.g., a central processing unit (CPU), a FPGA (field programmable gate array), or an ASIC (application specific integrated circuit). In some implementations, the data pro-cessing apparatus and/or special purpose logic circuitry may be hardware-based and/or software-based. The apparatus can optionally include code that creates an execution environment for computer programs, e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them. The present disclosure contemplates the use of data processing apparatuses with or without conventional operating systems, for example LINUX, UNIX, WINDOWS, MAC OS, ANDROID, IOS or any other suitable conventional operating system. [0189] Any combination of one or more computer readable medium(s) may be utilized. The computer readable medium may be a computer readable storage medium. A ‘computer-readable storage medium’ as used herein encompasses any tangible storage medium which may store instructions which are executable by a processor of a computing device. The computer-readable storage medium may be referred to as a computer-readable non-transitory storage medium. The computer- readable storage medium may also be referred to as a tangible computer readable medium. In some embodiments, a computer-readable storage medium may also be able to store data which is able to be accessed by the processor of the computing device. [0190] ‘Computer memory’ or ‘memory’ is an example of a computer-readable storage medium. Computer memory is any memory which is directly accessible to a processor. ‘Computer storage’ or ‘storage’ is a further example of a computer- readable storage medium. Computer storage is any non-volatile computer-readable storage medium. In some embodiments computer storage may also be computer memory or vice versa. [0191] A ‘processor’ as used herein encompasses an electronic component which is able to execute a program or machine executable instruction or computer executable code. References to the computing device comprising “a processor” should be interpreted as possibly containing more than one processor or processing core. The processor may for instance be a multi-core processor. A processor may also refer to a collection of processors within a single computer system or distributed amongst multiple computer systems. The term computing device should also be interpreted to possibly refer to a collection or network of computing devices each comprising a processor or processors. The computer executable code may be executed by multiple processors that may be within the same computing device or which may even be distributed across multiple computing devices. [0192] Computer executable code may comprise machine executable instructions or a program which causes a processor to perform an aspect of the present invention. Computer executable code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages and compiled into machine executable instructions. In some instances the computer executable code may be in the form of a high level language or in a pre-compiled form and be used in conjunction with an interpreter which generates the machine executable instructions on the fly. [0193] Generally, the program instructions can be executed on one processor or on several processors. In the case of multiple processors, they can be distributed over several different entities. Each processor could execute a portion of the instructions intended for that entity. Thus, when referring to a system or process involving multiple entities, the computer program or program instructions are understood to be adapted to be executed by a processor associated or related to the respective entity. [0194] While the invention has been illustrated and described in detail in the drawings and foregoing description, such illustration and description are to be considered illustrative or exemplary and not restrictive; the invention is not limited to the disclosed examples.
REFERENCE SIGNS LIST 10 morphing detection system 12 one or more networks 11.1-N one or more user devices 13.1-M one or more servers 20 ML model 21 first sub-model 22 second sub-model 23 third sub-model 26 set of locations 27 output 30 image 31-38 method steps 40 image 41-48 method steps 101-107 method steps 130 image 131 local coordinate system 132 origin 135 absolute coordinate system 150 image 151 local coordinate system 152 origin 155 absolute coordinate system 201-207 method steps 301-311 method steps 401-409 method steps 500 data structure 501.1-n entries 603 processing units 605 memory unit 607 bus 609 network adapter 611 storage system 613 display 619 I/O interface 701-711 method steps 801-815 method steps 901-915 method steps 1001-1009 method steps

Claims

CLAIMS 1. A method for morphed image detection, the method comprising: receiving by a user device (11.N) an image (30) of an object; identifying by the user device a set of landmarks of the object in accordance with a landmark pattern; determining (33) by the user device locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending (34) by the user device a location information to a remote server (13.1), the location information indicating the set of locations, the remote server comprising a trained machine learning model; receiving the location information by the remote server (13.1); inputting (35) by the remote server (13.1) the location information to the trained machine learning model; receiving (36) by the remote server an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image; sending (37) the output by the remote server to the user device; receiving the output by the user device (11.N); using (38) by the user device (11.N) the output for rejecting or accepting the received image (30).
2. A method for morphed image detection, the method comprising: receiving by a user device (11.N) an image (40) of an object; sending (42) by the user device the image to a remote server (13.1), the remote server comprising a training machine learning model; receiving the image by the remote server; identifying by the remote server (13.1) a set of landmarks of the object in accordance with a landmark pattern; determining (43) by the remote server (13.1) locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting (45) by the remote server (13.1) a location information to the trained machine learning model, the location information indicating the set of locations; receiving (46) by the remote server (13.1) an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image; sending (47) the output by the remote server (13.1) to the user device (11.N); receiving the output by the user device (11.N); using (48) by the user device (11.N) the output for rejecting or accepting the received image (40).
3. The method of claim 1 or 2, wherein the machine learning model comprises a first sub-model and a second sub-model, the first sub-model being configured to receive the set of locations and to predict the location information, the second sub-model being configured to receive as input the location information and to predict the output.
4. The method of claim 3, the second sub-model being a quantum machine learning model or a hybrid classical-quantum machine learning model.
5. The method of claim 3 or 4, the first sub-model being a neural network.
6. The method of any of the preceding claims 3 to 5, wherein the first sub-model is comprised in the user device or in the server, wherein the second sub- model is comprised in the server.
7. The method of any of the preceding claims, wherein the machine learning model was trained using a training dataset, the method further comprising retraining the machine learning model in response to any one of: the training dataset is updated; or a validity time is expired, wherein the retraining is performed using an updated training dataset.
8. The method of any of the preceding claims, further comprising representing the set of locations with a feature vector in a k-dimensional feature space having a dimension k smaller than the number of the set of landmarks, wherein the location information comprises the feature vector.
9. The method of any of the preceding claims, the object being a human face, wherein accepting the image comprises authenticating a user represented in the image.
10. The method of any of the preceding claims, wherein the user device and/or server are provided as cloud services.
11. The method of any of the preceding claims, being implemented in a mobile app, the method further comprising: before executing the method staring the mobile app on the user device.
12. The method of any of the preceding claims, the receiving of the image further comprising: detecting the object in the image; cropping an area of the image defined by the detected object, resulting in a cropped image, wherein the landmarks are identified in the cropped image and the locations are determined using the cropped image.
13. The method of any of the preceding claims, further comprising representing the set of locations with a feature vector using a linear transformation of a vector, ^, representing the set of locations into the feature vector, ^, using a weight matrix, ^, where ^ = ^ × ^, wherein the location information comprises the feature vector.
14. The method of any of the preceding claims, the method further comprising: representing the set of locations with a feature vector having a size that is smaller than or equal to the number of qubits of a quantum of a quantum processing unit, wherein the location information comprises the feature vector.
15. The method of any of the preceding claims, the landmark location being two- dimensional, 2D, coordinates.
16. The method of any of the preceding claims, the landmark location being three-dimensional 3D coordinates.
17. A morphing detection system comprising a server and user device, the user device and the server being configured to perform the method of claim 1 or the method of claim 2.
18. A computer program comprising instructions which, when the program is executed by a user device and a server, cause the user device and the server to perform the method of claim 1 or method of claim 2.
19. The computer program of claim 18, being a mobile app.
20. A method for morphed image detection, the method comprising: receiving (34) through one or more networks from a user device (11.N) a location information, the location information indicating a set of locations of a set of landmarks of an object in an image (30); inputting (35) the location information to a trained machine learning model; receiving (36) an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending (37) the output to the user device.
21. A server (13.1) being configured for: receiving through one or more networks from a user device (11.N) a location information, the location information indicating a set of locations of a set of landmarks of an object in an image (30); inputting the location information to a trained machine learning model (14.1); receiving an output of the trained machine learning model (14.1) indicating whether the image (30) is a morphed image or non-morphed image; sending the output to the user device (11.N).
22. A computer program comprising instructions which, when the program is executed by a server cause the server to perform at least: receiving through one or more networks from a user device a location information, the location information indicating a set of locations of a set of landmarks of an object in an image; inputting the location information to a trained machine learning model; receiving an output of the trained machine learning model indicating whether the image is a morphed image or non-morphed image; sending the output to the user device.
23. A method for morphed image detection, the method comprising: receiving (31) by a user device (11.N) an image (30) of an object; identifying by the user device (11.N) a set of landmarks of the object in accordance with a landmark pattern; determining by the user device (11.N) locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending (34) by the user device a location information to a remote server (13.1), the location information indicating the set of locations, in response to sending the location information receiving (37) from the server (13.1) an output indicating whether the received image is a morphed image or non-morphed image; using (38) the output for rejecting or accepting the received image (30).
24. A user device (11.N) for morphed image detection, the user device (11.N) being configured for: receiving an image (30) of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending a location information to a remote server (13.1), the location information indicating the set of locations, in response to sending the location information receiving from the server (13.1) an output indicating whether the received image (30) is a morphed image or non-morphed image; using the output for rejecting or accepting the received image (30).
25. A computer program comprising instructions for causing a user device for performing at least the following: receiving an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; sending a location information to a remote server, the location information indicating the set of locations, in response to sending the location information receiving from the server an output indicating whether the received image is a morphed image or non- morphed image; using the output for rejecting or accepting the received image.
26. A method for morphed image detection, the method comprising: receiving (42) from a user device (11.N) over one or more networks an image (40) of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting (45) location information to a trained machine learning model (14.1), the location information indicating the set of locations; receiving (46) an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending (47) the output to the user device (11.N).
27. A server (13.1) for morphed image detection, the server (13.1) being configured for: receiving from a user device (11.N) over one or more networks an image (40) of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model (14.1), the location information indicating the set of locations; receiving an output of the trained machine learning model (14.1) indicating whether the received image (40) is a morphed image or non-morphed image, sending the output to the user device (11.N).
28. A computer program comprising instructions for causing a server for performing at least the following: receiving from a user device over one or more networks an image of an object; identifying a set of landmarks of the object in accordance with a landmark pattern; determining locations of the set of landmarks with respect to a coordinate system defined relative to the object; inputting location information to a trained machine learning model, the location information indicating the set of locations; receiving an output of the trained machine learning model indicating whether the received image is a morphed image or non-morphed image, sending the output to the user device.
29. Any of the preceding claims 20 to 28, wherein the location information comprises a feature vector that represents the set of locations in a k- dimensional feature space having a dimension k smaller than the number of a set of landmarks, wherein the location information comprises the feature vector.
EP24743354.3A 2023-07-17 2024-07-11 Image morphing detection Pending EP4690141A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DE102023118867.4A DE102023118867A1 (en) 2023-07-17 2023-07-17 IMAGE MORPHING DETECTION
PCT/EP2024/069709 WO2025016877A1 (en) 2023-07-17 2024-07-11 Image morphing detection

Publications (1)

Publication Number Publication Date
EP4690141A1 true EP4690141A1 (en) 2026-02-11

Family

ID=91953803

Family Applications (1)

Application Number Title Priority Date Filing Date
EP24743354.3A Pending EP4690141A1 (en) 2023-07-17 2024-07-11 Image morphing detection

Country Status (3)

Country Link
EP (1) EP4690141A1 (en)
DE (1) DE102023118867A1 (en)
WO (1) WO2025016877A1 (en)

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11669607B2 (en) * 2019-08-29 2023-06-06 PXL Vision AG ID verification with a mobile device
KR20210106790A (en) * 2020-02-21 2021-08-31 삼성전자주식회사 Server, electronic apparatus and the control method thereof

Also Published As

Publication number Publication date
WO2025016877A1 (en) 2025-01-23
DE102023118867A1 (en) 2025-01-23

Similar Documents

Publication Publication Date Title
EP4320606B1 (en) Personalized biometric anti-spoofing protection using machine learning and enrollment data
CN115050064B (en) Human face liveness detection method, device, equipment and medium
KR102294574B1 (en) Face Recognition System For Real Image Judgment Using Face Recognition Model Based on Deep Learning
CN107766786B (en) Activity test method and activity test computing device
CN110222573B (en) Face recognition method, device, computer equipment and storage medium
Chopparapu et al. A hybrid facial features extraction-based classification framework for typhlotic people
EP3642756B1 (en) Detecting artificial facial images using facial landmarks
CN111680675B (en) Face living body detection method, system, device, computer equipment and storage medium
CN112567398B (en) Techniques for matching different input data
US10956738B1 (en) Identity authentication using an inlier neural network
CN114972016B (en) Image processing method, apparatus, computer device, storage medium, and program product
KR20200087350A (en) System for Face Recognition Based On AI
Pan et al. Hierarchical support vector machine for facial micro-expression recognition
KR20200084427A (en) Face Recognition System for Extracting Feature Vector Using Face Recognition Model Based on Deep Learning
KR20200075063A (en) Apparatus for Extracting Face Image Based on Deep Learning
JP7600315B2 (en) Detecting Wrapped Attacks in Face Recognition
US12300038B2 (en) Method and apparatus with liveness detection
KR20200079095A (en) Edge Device for Face Recognition
WO2022217294A1 (en) Personalized biometric anti-spoofing protection using machine learning and enrollment data
Arora et al. Cryptography and Tay-Grey wolf optimization based multimodal biometrics for effective security
EP4690141A1 (en) Image morphing detection
EP4710306A1 (en) Training data for image morphing detection
Wang et al. Iris image super resolution based on gans with adversarial triplets
CN115188082B (en) Training method, device, equipment and storage medium of face fake identification model
Ramkumar et al. IRIS DETECTION FOR BIOMETRIC PATTERN IDENTIFICATION USING DEEP LEARNING.

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20251104

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR