scieee AI-readable full text Open interactive document viewer

StyleDemorpher: high-quality face demorphing via StyleGAN2's latent space

Ismayilov, Raul; Spreeuwers, Luuk; Batskos, Ilias

Abstract

Morphing attacks pose a serious threat to automated border control systems by allowing identity documents to be used by multiple individuals, undermining biometric security. To address this, we propose a novel face demorphing framework that leverages the latent space of StyleGAN2. At its core is ReStyle-ID, an encoder network optimized for identity preservation through improved loss functions and targeted training data, enabling accurate and identity-focused inversion. Combined with StyleDemorpher, a face demorphing network trained on a novel DemorphDB dataset with high-quality morph images that simulate realistic and challenging attack scenarios, the framework reconstructs high-resolution demorphed faces and generalizes well to unseen identities and morphing methods. Together, these components overcome key limitations of prior approaches, such as low resolution, poor robustness, and visual artifacts. This work offers a scalable and effective solution for face demorphing and contributes a comprehensive dataset and framework to support future research in biometric security.

Full text

RESEARCH Machine Vision and Applications (2025) 36:113 https://doi.org/10.1007/s00138-025-01735-3 reconstructing the second identity, which is not physically present at the ABC gate but is concealed within the morph. Face demorphing encounters several significant challenges, primarily due to the lack of prior information about the morphing method and the blending factor used to combine the two identities. Additionally, trusted live image capture at the ABC gate often differs from that used to generate the morph in terms of illumination, pose, and expression. These factors make the exact reconstruction of the second identity through facial landmarks complex and prone to noticeable artifacts [4]. To overcome these challenges, researchers have increasingly explored deep learning-based approaches for face demorphing. Techniques utilizing Convolutional Neural Networks (CNNs) and Generative Adversarial Networks (GANs) have shown promise [5–7]. However, these networks often reconstruct low-resolution images with artifacts and distortions. Moreover, their training on limited datasets can lead to poor generalizability when they are applied to previously unseen morphing methods and identities. This paper introduces a novel approach to face demorphing that addresses the limitations of current deep learning-based methods by leveraging StyleGAN2’s [8] latent space, which enables high-resolution (1024 × 1024 pixels) 1 Introduction Morphing attacks present a significant threat to Automated Border Control (ABC) systems [1], as they enable the creation of identity documents that can be used by multiple individuals whose features are blended in the morph. This vulnerability can potentially allow two identities to share a single document, undermining the integrity of border security measures [2, 3]. First introduced in [4], face demorphing has emerged as a prominent research topic in biometrics owing to its potential to counteract morphing attacks. The primary objective of face demorphing is to disentangle the two identities embedded within a morph. This often involves Raul Ismayilov [email protected] Luuk Spreeuwers [email protected] Ilias Batskos [email protected] 1 Data Management and Biometrics, University of Twente, Drienerlolaan 5, 7512AD Enschede, The Netherlands Abstract Morphing attacks pose a serious threat to automated border control systems by allowing identity documents to be used by multiple individuals, undermining biometric security. To address this, we propose a novel face demorphing framework that leverages the latent space of StyleGAN2. At its core is ReStyle-ID, an encoder network optimized for identity preservation through improved loss functions and targeted training data, enabling accurate and identity-focused inversion. Combined with StyleDemorpher, a face demorphing network trained on a novel DemorphDB dataset with high-quality morph images that simulate realistic and challenging attack scenarios, the framework reconstructs high-resolution demorphed faces and generalizes well to unseen identities and morphing methods. Together, these components overcome key limitations of prior approaches, such as low resolution, poor robustness, and visual artifacts. This work offers a scalable and effective solution for face demorphing and contributes a comprehensive dataset and framework to support future research in biometric security. Keywords Biometrics · Face demorphing · Deep learning · Face recognition Received: 30 January 2025 / Revised: 11 July 2025 / Accepted: 30 July 2025 © The Author(s) 2025 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space RaulIsmayilov1· LuukSpreeuwers1· IliasBatskos1 1 3 R. Ismayilov et al. image reconstructions. Central to the framework is ReStyleID, an encoder network trained on over 100,000 images to establish a robust mapping between image and latent spaces while preserving identity features. Building on ReStyle-ID, the StyleDemorpher network is trained for the face demorphing task via transfer learning [9]. This approach leverages the pretrained knowledge of ReStyle-ID to provide strong initialization for disentangling and reconstructing the identities embedded within morphs. Crucially, this strategy enhances the network’s ability to generalize to unseen identities and morphing methods not encountered during training. Training is conducted on DemorphDB, a high-quality dataset introduced in this paper, which is designed as a challenging and realistic benchmark for advancing face demorphing techniques. Overall, the proposed framework simulates realistic morphing attack scenarios and aims to reconstruct accurate and high-quality demorphed images. This method demonstrates high generalizability across identities and morphing methods that were unseen during training, effectively addressing the shortcomings of previous approaches. The contributions of this paper are as follows: ●DemorphDB Dataset: A comprehensive dataset of 1,653 identities with document-like images from five face image datasets, including 643 identities with multiple images. Each identity is paired with high-quality traditional and deep learning-based morphs generated from the ten closest identities. The dataset is extensible, supporting additional morphing methods. ●ReStyle-ID Encoder: An improved StyleGAN2 [8] encoder based on the ReStyle [10] architecture, designed to better preserve identity information. The enhancements include the use of updated loss functions and training data, which achieve superior identity retention. ●StyleDemorpher Network: A robust demorphing network capable of generating high-quality demorphed images without requiring knowledge of the morphing method. It leverages the ReStyle-ID encoder network architecture, retrained to use the trusted live capture image as a reference image and disentangle the second identity embedded within the morph. 2 Related work 2.1 Face demorphing Face morphing merges features from two distinct identities into a single image that shares attributes of both. Formally, for images IA and IB of two different identities: IAB =M(IA,I B), (1) where M(·) denotes the face morphing procedure, and IAB is the morph image. Morphs can often be created through either landmarkbased or deep learning-based methods. Landmark-based approaches typically identify facial landmarks to construct triangular meshes, which are then warped to produce a morph [11]. These approaches often introduce ghosting artifacts that require manual retouching. Numerous landmarkbased techniques [12–14] have been proposed, most of which employ a splicing step to blend the morphed facial region seamlessly into one of the original images [15]. Deep learning-based methods [16–18] avoid the use of landmarks by leveraging neural networks for end-to-end morph generation. While they usually reduce the need for manual editing, they can sometimes yield lower-quality outputs [19]. Face demorphing, introduced in [4] and built on prior work [2, 20], aims to recover the accomplice’s image from a forged document containing a morph of the criminal and the accomplice. This process becomes challenging when the criminal attempts to use the document, especially because the exact morphing procedure is often unknown. Additional complications arise since the criminal’s image at the ABC gate differs from the one used to generate the morph, potentially introducing artifacts during demorphing [4]. In [21], the authors address one aspect of this challenge by using a deep learning network to first estimate the morphing factor. However, such methods only target landmark-based morphs and heavily depend on accurate landmark detection. Deep learning-based face demorphing can overcome these limitations by training on morphs produced by diverse methods. For example, [5] uses a Convolutional Neural Network (CNN) to process both document and live capture images, outputting a demorphed image. Another approach, FD-GAN [7], employs a GAN framework comprising an encoder, an identity separation network to isolate the features of the accomplice, and a restoration network to reconstruct the image. The discriminator network then evaluates the authenticity of the generated image compared with the target image. Similarly, [22] uses a dual-branch identity separation network to extract the semantic latent code of the accomplice from the morph and then employs a pretrained diffusion autoencoder [23] network to restore the accomplice’s identity. Although landmark-based demorphing methods can work well when the morphing technique and facial landmarks are known and accurately extracted, they often introduce artifacts and struggle with deep learning-based morphs. Deep learning-based demorphing methods, on the other hand, can be trained to handle various morphing approaches but often 1 3 113 Page 2 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space rely on a limited number of training identities, produce lowresolution outputs, or generate distorted images owing to insufficient training data. A notable exception is the method in [22], which uses a pretrained diffusion autoencoder to synthesize high-fidelity, high-resolution facial images. However, the multi-step denoising procedure inherent to diffusion models requires multiple forward passes, thus increasing the processing time and computational demands compared with solutions based on CNNs and GANs. 2.2 Latent space of StyleGAN2 Originally introduced in [8], StyleGAN2 refines the StyleGAN architecture [24] to produce high-resolution, realistic images with improved training stability. Unlike conventional generators that use a single latent code [25, 26], StyleGAN starts with a constant input and injects one or more latent codes (or “styles”) at each convolution layer. Each layer also uses separately scaled noise to embed fine stochastic details. This setup enables fine-grained control over generated images and leads to a high degree of realism. Overall, StyleGAN comprises 18 convolutional blocks, each receiving its own latent codes. The network also includes a mapping network that transforms latent codes drawn from Z (a multivariate standard normal) into an intermediate latent space W to achieve better disentanglement of various image attributes. StyleGAN2 [8] improves upon StyleGAN to remove artifacts and enhance stability. Owing to its high-quality outputs and well-disentangled latent space, many studies aim to embed real images into StyleGAN2’s latent space for editing. For example, a neutral facial expression can be changed to a smile by adjusting the corresponding latent code. This embedding process, known as GAN inversion [27], is typically realized via two approaches: optimization-based methods and encoderbased methods. Optimization-based methods [8, 28, 29] iteratively refine latent codes via gradient descent on multiple loss functions, achieving high fidelity at the cost of considerable computation, often several minutes per image. Conversely, encoderbased approaches [10, 30, 31] train an encoder to map images into the latent space in one or a few forward passes, offering faster embedding but typically lower similarity. Once embedded, the image’s attributes can be modified through latent code editing. For facial images, prior work [32–34] has shown that expressions, poses, or lighting can be altered by manipulating the latent codes. However, these methods do not apply directly to face demorphing, which requires finding a novel facial identity in the latent space corresponding to the hidden identity in a morph. Although embedding remains a crucial step in projecting real faces into StyleGAN2’s latent space, this paper introduces a dedicated approach tailored to the face demorphing task. 3 Methodology This section outlines the methodology of the proposed frameworks. First, we introduce the core component, the ReStyle-ID encoder framework, which ensures identitypreserving inversion essential for face demorphing within the StyleGAN2 [8] latent space. Next, we present the StyleDemorpher framework, illustrating how it adapts the pretrained ReStyle-ID encoder to produce high-quality face demorphing results. Finally, we describe the formulation of the loss functions used in both frameworks. 3.1 ReStyle-ID: identity-preserving inversion framework The proposed ReStyle-ID framework builds upon the architecture and iterative encoding mechanism of ReStyle [10], which is distinct from conventional StyleGAN2 [8] encoders such as e4e [30] and pSp [31]. Unlike these encoders, which process the input image in a single forward pass, ReStyle employs multiple iterative passes, with each step progressively refining the encoding. ReStyle-ID leverages this iterative structure while introducing targeted enhancements to better preserve identity information. This focus is particularly critical for face demorphing tasks, where the input morphed image is often highly similar to the original identity to be recovered. Our framework improves upon the ReStyle baseline with the following key modifications: ●An expanded dataset, including synthetic images of document-like quality, is used. Details are provided in Sect. 5.1.1. ●The identity loss function is refined by incorporating the MTCNN [35] model for adaptive face detection and cropping, which replaces the static center crop. Additionally, the MS-SSIM [36] loss function was integrated to enhance identity preservation, as elaborated in Sect. 3.3.3. ●During training, all background information in the images is removed during loss computation to ensure the encoder learns to focus solely on identity-relevant facial features. This design choice guides the network to inherently disregard background content, enabling it to generalize to full, unmodified inputs during inference without explicit background removal. Importantly, ReStyle-ID is not proposed as a fundamentally new architecture but as a focused refinement of the original 1 3 Page 3 of 22 113 R. Ismayilov et al. all 18 layers of the StyleGAN2 architecture, the W+ space allows for 18 distinct w vectors, one for each layer. This flexibility significantly enhances the inversion quality [28]. Initially, the latent code wˆy0 is set to the average latent code of StyleGAN2, w , with its corresponding image Iˆy0 . At each iteration t, where 0≤t≤N and N is the total number of iteration steps, the target image Ix and the current prediction Iˆyt are concatenated and passed to the encoder network E. The architecture of the encoder network is visualized in Fig. 2. This network generates a residual code ∆E t : ∆E t= E ( I x∥ I ˆyt). (2) The residual code is then combined with the current latent code prediction wˆyt , resulting in an improved latent code: wˆyt+1 =∆E t+wˆyt. (3) The StyleGAN2 generator G then generates the image Iˆ y t+1 corresponding to the improved latent code: I ˆy t+1 = G (w ˆy t+1 ). (4) This process continues iteratively, updating the current latent code and corresponding image until the final iteration N. During training, a pretrained face segmentation network [39] is employed to identify and remove background pixels solely for loss computation. Specifically, background regions are masked by setting their values to zero in both Ix and Iˆ y t+1 , ensuring that all losses are computed on face-only images. This masking strategy, introduced in the ReStyle-ID framework, enforces identity-focused supervision by suppressing the influence of background content. In ReStyle baseline, tailored for identity-sensitive applications such as face demorphing. The structural similarity is intentional: our aim is to retain ReStyle’s strengths, namely, fast inference and iterative refinement, while improving its ability to preserve identity information. The introduced modifications are deliberately scoped and task-driven rather than architectural, enhancing identity fidelity within the StyleGAN2 latent space without compromising efficiency or stability. The operation of the ReStyle-ID framework is illustrated in Fig. 1. Given an input image Ix , the objective of the ReStyle-ID framework is to find a latent code w that best represents the input. The expanded latent space of StyleGAN2 [8], denoted as W+ , is utilized for this task. Unlike the conventional latent space W of StyleGAN2, which uses a single 512-dimensional latent code (style) w shared across Fig. 2 Simplified architecture of the ReStyle-ID encoder and StyleDemorpher network, following [10]. The two input images are concatenated along the channel dimension, and feature maps are extracted via the feature pyramid network [37] based on the ResNet-IR [38] backbone. The feature maps are passed through 18 map2style networks [31], transforming them into 18 512-dimensional vectors corresponding to w∈W+ Fig. 1 Overview of the ReStyle-ID inversion framework. The input image Ix is iteratively refined by the encoder E, which generates residual latent codes ∆E t to update the current latent code wˆyt . These codes are mapped to images via the StyleGAN2 generator G, progressively aligning generated image Iˆyt with input image Ix . Backgrounds are removed during training to ensure identity-focused encoding 1 3 113 Page 4 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space ● IA - An image of a criminal, A, used to create the morph. ● IA′ - A different image of the same criminal, A, modeled as the trusted live capture at the ABC gate. ● IB - An image of an accomplice, B, assisting criminal A in morph creation. This image is targeted for recovery by the face demorphing algorithm. ● IAB - The morph image used in the identity document that criminal A attempts to utilize. Although all four images can be employed during StyleDemorpher’s training phase, only IAB and IA′ are available during inference, as the images used to create the morph are not accessible. The operation of the StyleDemorpher framework is depicted in Fig. 3. The framework processes an input morph image, IAB , and a trusted live capture image, IA′ . While Fig. 3 visualizes the morph image generated via StyleGAN2, any morphing method can be used for generating morph images. IAB and IA′ are concatenated along the channel dimension and fed into the StyleDemorpher network, denoted as SD. This network outputs a residual code, ∆SD : ∆SD = SD ( I AB ∥ I A′). (5) Concurrently, the morph image IAB is input to the frozen, pretrained ReStyle-ID framework. Although simplified in the figure, the "Frozen Encoder Framework" block represents the complete encoding framework shown in Fig. 1. The encoding is iteratively refined over N steps, and the final latent code wAB at t=N is saved. This latent code is then combined with ∆SD to estimate the latent code wˆ B for reconstructing identity B: wˆ B=∆SD +wAB. (6) This approach leverages the morph’s latent code to navigate to the latent space location of identity B. Using this latent code, the frozen StyleGAN2 generator, G, reconstructs the image of identity B: I ˆ B= G (w ˆ B). (7) During training, the target image of identity B guides StyleDemorpher’s learning process. Instead of using IB directly, ReStyle-ID encodes it into the latent space, and StyleGAN2 reconstructs it as ˜ IB=G(E(IB)) , promoting demorphing within StyleGAN2’s latent space. Next, the backgrounds of Iˆ B , ˜ IB , and IA′ are removed, and similarity-based loss functions are computed between ˜ IB and Iˆ B . Additionally, inverse identity loss, aimed at removing the presence of contrast to the original ReStyle framework, which includes background pixels during loss computation, ReStyle-ID encourages the encoder to attend exclusively to facial features. The StyleGAN2 generator G remains frozen throughout training, and only the encoder network E is updated via back-propagation of the loss defined in Sect. 3.3.6. At inference time, full (unmasked) images are passed to the encoder. However, due to the face-focused training supervision, the encoder implicitly deprioritizes background information, often leading to uniform or neutral-colored regions in the output background. This behavior emerges despite no explicit background masking during inference and without any changes to the encoder architecture or inference-time pipeline. 3.2 StyleDemorpher: face demorphing framework The StyleDemorpher framework excels in face demorphing by leveraging the latent space capabilities of StyleGAN2 [8]. It adopts the ReStyle-ID encoder architecture, as shown in Fig. 2. The pretrained weights of the ReStyle-ID encoder are used as the starting point for training StyleDemorpher. This strategic use of pretrained weights equips StyleDemorpher with a robust initial understanding of the correlation between image representations and the latent space of StyleGAN2, which is built from a substantial dataset used with the ReStyle-ID encoder. The ability of the ReStyle-ID encoder to train with single images of varying expressions and poses enables the use of extensive image datasets such as FFHQ [8] and CelebA-HQ [40]; however, modeling face morphing attacks requires high-quality, document-like images. Additionally, authorities typically only have access to morphed images in documents and live captures of individuals using these documents, not the original images used to create the morphs. To simulate this scenario for training StyleDemorpher, a dataset must include at least two distinct images of the same individual: one to generate the morph and another representing the person’s live capture at the ABC gate. This requirement limits the data available for training the face demorphing network. By initializing StyleDemorpher with weights from the encoder network, which already establishes a connection between the image and latent space, overfitting on a smaller dataset can be mitigated. This strategy is crucial for ensuring generalizability to unseen identities and various morphing methods not encountered during training. Before the design of the StyleDemorpher framework is detailed, it is essential to define several terms related to the dataset used in training. This dataset comprises quadruplets of images, denoted as (IA,I A′,I B,I AB) , and is further described in Sect. 4. The definitions of these images are as follows: 1 3 Page 5 of 22 113 R. Ismayilov et al. Networks (GANs) [41–43] as it helps these networks learn perceptual similarities between images. In this work, LPIPS [44] loss, which is based on the AlexNet [45] backbone, is utilized over the standard perceptual loss [46]. Early experiments and previous research [47] have shown that LPIPS loss better preserves image quality and sharpness. The LPIPS loss is defined in Eq. (9). LLPIPS (x, y)=∥F(x)−F(y)∥2, (9) where F represents the AlexNet perceptual feature extraction network. 3.3.3 Identity loss Identity loss is crucial during the training of both the ReStyle-ID and StyleDemorpher frameworks. This loss helps preserve identity-related features within the image, which is essential for the face demorphing procedure. The identity loss is defined in Eq (10). LID ( x, y )=1− Sc ( R ( M ( x )) ,R ( M ( y ))), (10) where Sc represents the cosine similarity metric, R is the pretrained ArcFace [38] network specialized in facial recognition and verification, and M is the pretrained MTCNN [35] network used for automatic face detection and cropping. identity IA′ in Iˆ B , is computed. The loss computation is further discussed in Sect. 3.3.7. 3.3 Loss function formulation This section introduces the individual loss functions used in training the ReStyle-ID and StyleDemorpher frameworks. Since most of the individual loss functions are utilized by both frameworks, a simpler notation is adopted using variables x and y, which represent two different images used in the computation of a specific loss. The final training objectives for both frameworks are then presented, utilizing framework-specific notations. 3.3.1 L2 loss Pixelwise L2 loss, also known as the Mean Squared Error (MSE) loss, is a fundamental and widely used loss function when training deep learning models. L2 loss is defined in Eq. (8). LL2 (x, y)=∥x−y∥2. (8) 3.3.2 Perceptual loss Perceptual loss is widely used in training Convolutional Neural Networks (CNNs) and Generative Adversarial Fig. 3 StyleDemorpher face demorphing framework. The framework initializes with weights from the pretrained ReStyle-ID encoder and processes the input morph image IAB and live capture image IA′ . The frozen ReStyle-ID encoder generates the latent code wAB for the morph, whereas the StyleDemorpher network SD calculates a residual code ∆SD . This residual code is added to wAB to estimate wˆ B , the latent code corresponding to identity B. The StyleGAN2 generator G reconstructs the image Iˆ B from wˆ B . During training, background removal and loss functions are employed to support the framework’s focus on recovering identity B 1 3 113 Page 6 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space where Ix is the target image being encoded, Iˆ y t+1 is the reconstructed image at iteration t, and λL2 =1.0 , λLPIPS =0.8 , λID =0.1 , and λMS-SSIM =0.4 are the weights scaling the contributions of individual loss functions. These weights are selected empirically based on identity similarity scores obtained from the validation data. 3.3.7 StyleDemorpher training objective The training objective of StyleDemorpher is similar to that of ReStyle-ID, with the addition of a new term corresponding to the inverse identity loss. While the L2, LPIPS, identity, and MS-SSIM loss functions aim to maximize the similarity between the target identity B and the predicted reconstruction Iˆ B , the inverse identity loss is computed between Iˆ B and IA′ to maximize the identity dissimilarity between these images, thereby removing the presence of identity A from the prediction. The training objective for StyleDemorpher is defined in Eq. (14). L StyleDemorpher ( Iˆ B, ˜ IB,I A′ )= λL2LL2 (˜ IB,Iˆ B ) +λLPIPSLLPIPS (˜ IB,Iˆ B) +λIDLID (˜ IB,Iˆ B) +λMS-SSIMLMS-SSIM ( ˜ IB,Iˆ B ) +λ InvIDLInvID ( IA ′ ,I ˆ B) , (14) where ˜ IB=G(E(IB)) corresponds to the image of the target identity B, IA′ is the live capture image of the criminal, Iˆ B is the predicted reconstruction of identity B, and λL2 =1.0 , λLPIPS =0.8 , λID =1.0 , λMS-SSIM =0.4 , and λInvID =0.25 are the weights scaling the contributions of individual loss functions. These weights have been selected empirically based on identity similarity and dissimilarity scores obtained from the validation data. Compared with that of ReStyle-ID, the weight of the identity loss, λID , is increased from 0.1 to 1.0 to better emphasize identity similarity when the identity B is reconstructed. 4 DemorphDB dataset This paper introduces the novel DemorphDB dataset, which was created for training deep learning models to perform face demorphing. DemorphDB is constructed from five datasets composed of full frontal facial images: FRGC [48], Eurecom-IST Face Dataset [49], Utrecht ECVP Dataset [50], Chicago Face Database [51–53], and Face Research Lab London Dataset [54]. Images from these datasets have been manually analyzed, retaining only high-quality, document-like images and excluding those with non-neutral expressions, closed eyes, blurriness, or poor illumination. An improvement introduced in this work, compared with [31] and [10], is the use of automatic face detection. Instead of performing a simple center crop of the face image before passing it to the ArcFace [38] network, the MTCNN [35] network detects the bounding box around the face. The cropping and resizing are then performed, and the resulting image is passed to the ArcFace network. This makes the loss implementation more robust, allowing it to handle images with varying poses or facial structures more accurately. 3.3.4 Inverse identity loss Inverse identity loss is introduced to achieve the opposite effect as identity loss, as it attempts to maximize the dissimilarity between two identities. This loss is defined in Eq. (11). LInvID ( x, y ) = max (0 ,S c ( R ( M ( x )) ,R ( M ( y )))). (11) 3.3.5 MS-SSIM loss MS-SSIM evaluates the structural similarity between images at multiple scales, incorporating variations in image content at different resolutions [36]. This multi-scale approach enables MS-SSIM to capture structural information associated with facial images more robustly and accurately. It has a positive effect on identity reconstruction results for both the ReStyle-ID and StyleDemorpher frameworks. The MSSSIM loss is defined in Eq. (12). LMS-SSIM (x, y)=1−MS-SSIM (x, y). (12) 3.3.6 ReStyle-ID training objective The combined ReStyle-ID training objective consists of four individual loss terms aimed at maximizing the identity similarity between the input images and the reconstructions. L2, LPIPS, and identity loss are utilized, following the design choices of the ReStyle [10] framework, with an improvement in identity loss through automatic face detection. An additional MS-SSIM loss term is included to further improve identity similarity scores by considering the structural similarity of facial images. The training objective for ReStyle-ID is defined in Eq. (13). L ReStyle-ID ( Ix,Iˆyt+1 )= λL2LL2 ( Ix,Iˆyt+1 ) +λLPIPSLLPIPS (Ix,Iˆyt+1 ) +λIDLID ( Ix,Iˆyt+1 ) +λ MS-SSIMLMS-SSIM ( I x ,I ˆyt+1 ), (13) 1 3 Page 7 of 22 113 R. Ismayilov et al. preserving the identity information of both individuals within the morphs. Finally, StyleGAN2 morphs are also introduced and generated via the ReStyle-ID framework to obtain latent codes of the two identities and then morph them by averaging (Eq. (15)). I AB =G ( E ( IA )+ E ( IB ) 2). (15) DemorphDB comprises 36,983 morph images for each of the three morphing methods. Morph quality is evaluated in Appendix A, with examples shown in Fig. 8. All images (bona fide and morphs) are automatically white balance corrected via a pretrained network [56] and aligned and cropped via the FFHQ method [8]. 5 Experiments 5.1 Datasets 5.1.1 ReStyle-ID framework datasets The original ReStyle [10] framework was trained on the FFHQ [8] dataset. For training ReStyle-ID, the following datasets are used: FFHQ, CelebA-HQ [40] (training set), and a synthetic dataset of 6,652 document-like images, resulting in over 100,000 training images. The CelebA-HQ dataset is incorporated to increase identity diversity, whereas the synthetic dataset, generated via StyleGAN2 [8], is tailored to include frontal poses and neutral expressions for effective training on document-like images. To create this dataset, segmentation masks are automatically generated via a pretrained face parsing network [39] on DemorphDB images. These masks are then utilized by a pretrained pSp [31] network to encode random identities in StyleGAN2’s latent space. StyleGAN2 processes these encodings to generate the final synthetic images. The evaluation of the ReStyle-ID framework is performed on images from the DemorphDB dataset. One random image from each of the 1,653 bona fide identities is selected, forming the DemorphDB-Single evaluation dataset. 5.1.2 StyleDemorpher framework datasets The StyleDemorpher framework is trained using quadruplets of images from the DemorphDB dataset. Only UTW-NS and StyleGAN2 [8] morphs are used in training because UTW [13] morphs result in information loss due This resulted in DemorphDB containing images of 1,653 unique identities, 643 of which have two or more images. Apart from bona fide identity images, DemorphDB contains morphs generated automatically for training the StyleDemorpher framework. The images for the morphs are generated following the procedure in Algorithm 1, which uses the notations introduced in Sect. 3.2. This results in a dataset structured into quadruplets of images: ( IB , IA , IA′ , IAB ). Algorithm 1 DemorphDB Dataset Construction Procedure Three types of morphs are available in DemorphDB: UTW [13], UTW-NS, and StyleGAN2 [8]. UTW employs an automatic method for generating high-quality morphs by splicing [15]. This method crops the morphed image’s facial region and pastes it onto an original identity’s image, eliminating ghosting artifacts outside the face. In this work, the cropped face is pasted onto accomplice B’s image, simulating a scenario where the accomplice seeks a travel document via the morph. This increases the chance of acceptance, as the external facial features align with the morph. Notably, this method warps the geometry of facial parts and then swaps them, including the eyes and nose of the criminal while incorporating the accomplice’s mouth in the generated morphs. Owing to the swapping of facial parts, UTW [13] morphs eliminate information about the accomplice’s eyes and nose, leaving only their geometry. This can negatively impact face demorphing due to loss of information. To avoid this issue, UTW-NS (UTW - No Swapping) morphs are introduced, created without swapping facial regions, effectively 1 3 113 Page 8 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space where N is the total number of morph images, R(·,·) is the FRS matching score, τ is the FRS threshold at F[email protected]%, and I(·) denotes the indicator function (1 if the condition is true, 0 otherwise). 5.2.3 Restoration accuracy Restoration accuracy [7] evaluates if the recovered accomplice Iˆ B matches the true accomplice identity IB and does not match the criminal IA′ : Accuracy = ∑ N i=1 I ( R(Iˆ Bi,I Bi)>τ ∧R(Iˆ Bi,I A′ i)≤τ ) N, (17) where N is the number of demorphing attempts. 5.2.4 Identity deviation metrics To evaluate identity separation after demorphing, we compute the Deviation of Criminal Identity (DCI), Deviation of Accomplice Identity (DAI) [22], and the newly introduced Deviation of Legitimate Identity (DLI): DCI =1 N N ∑ i=1 R(Iˆ Bi,I A′ i)−τ, (18) DAI =1 N N ∑ i=1 R(Iˆ Bi,I Bi)−τ, (19) DLI =1 N N ∑ i=1 R(Iˆ Ai,I Ai)−τ, (20) where N is the number of demorphing attempts, R(·,·) is the FRS matching score, and τ is the FRS threshold at F[email protected]%. A more negative DCI means Iˆ B is dissimilar to IA′ , indicating better removal of criminal traits. A higher positive DAI reflects stronger resemblance of Iˆ B to the accomplice IB , while a higher positive DLI confirms that when demorphing is applied to legitimate image pairs ( IA , IA′ ), the resulting demorphed image Iˆ A maintains the identity of the legitimate subject A. 5.2.5 Differential morphing attack detection (D-MAD) metrics To evaluate Differential Morphing Attack Detection (D-MAD), we use the setup in Fig. 4. From the document image and a trusted live capture, StyleDemorpher produces a demorphed image, which is then compared to the to swapping of the face parts. However, UTW morphs are included in the evaluation as an unseen morphing method. The subset of target images B from the Face Research Lab London (FRLL) [54] dataset is reserved for evaluation. Consequently, all morphs with the target demorphing identity B from the FRLL dataset are excluded from training. This results in an evaluation dataset containing 102 unseen target identities and 1020 morphed images. Since the FRLL dataset includes only one neutral expression image per individual, the images for the corresponding identity A ( IA , IA′ ) are still selected via Algorithm 1. To evaluate StyleDemorpher on unseen identities and morphing methods, the HNU-FM [57] and FRLL-Morphs [58, 59] datasets are used. The HNU-FM [57] dataset includes morphs generated via a landmark-based morphing method [60], with four protocols. Protocol I’s testing subset is selected for experiments because of its high attack success rate and equal blending of identities. This subset contains 378 morphed images from 16 males and 12 females. Two scenarios are analyzed: Scenario 1 uses neutral expression images without occlusions for trusted live captures ( IA′ ), whereas Scenario 2 uses images with altered expressions and occlusions. The FRLL-Morphs [58, 59] dataset, which is based on identities from FRLL [54], includes morphs created with five methods: OpenCV [60], FaceMorpher [61], WebMorph [62], AMSL [14], and StyleGAN2 [8]. For this dataset, only Scenario 2 is evaluated for IA′ images, as neutral expression images not directly involved in the morphing process are not present. 5.2 Evaluation metrics 5.2.1 Identity similarity scores We use three face recognition systems (FRSs), MobileFaceNet [63], ArcFace [38], and CurricularFace [64], which compute cosine similarity between face embeddings. Decision thresholds are set at False Acceptance Rate (FAR) of 0.1%, in line with Frontex guidelines [65]. These thresholds are calculated based on the DemorphDB dataset and equal to 0.6396 for MobileFaceNet, 0.4894 for ArcFace, and 0.2929 for CurricularFace. 5.2.2 Mated morph presentation match rate (MMPMR) MMPMR [66] measures the proportion of morphs IAB that successfully match both contributing identities IA and IB above the threshold τ : MMPMR = ∑ N i=1 I ( R ( IABi,I Ai ) >τ ∧R ( IABi,I Bi ) >τ ) N, (16) 1 3 Page 9 of 22 113 R. Ismayilov et al. The D-MAD performance of StyleDemorpher is highly dependent on the underlying FRS. Under ArcFace [38], StyleDemorpher consistently achieves lower D-EER and BPCER at fixed APCER values than Face Demorphing [4]. In contrast, when using CurricularFace [64], Face Demorphing [4] often outperforms StyleDemorpher. Although StyleDemorpher yielded better restoration accuracy, as well as higher DCI and DAI values in prior experiments, it achieved these gains at the cost of lower DLI values on bona fide non-morphed images. Since BPCER and DLI both capture performance on bona fide document images, StyleDemorpher’s strong focus on handling morphs degrades its performance on bona fide samples. Conversely, DCI scores and APCER are both influenced by morph images, such that higher (less negative) DCI values can lead to increased APCER. Table 8 suggests that these performance trade-offs are more pronounced with CurricularFace, which typically produces lower DCI scores (see Table 6) because of its ability to detect traces of criminal’s identity post-demorphing. Nevertheless, given that StyleDemorpher has never been trained on bona fide document images, Table 8 shows that StyleDemorpher-S can still provide comparable or even superior D-MAD performance relative to Face Demorphing [4]. Further improvements could be achieved by training StyleDemorpher with bona fide travel images that are not penalized by inverse identity loss (see Eq. 11). However, owing to the lack of a dataset containing at least two highquality document-like images per subject (comparable in size and quality to DemorphDB), this extension has not yet been investigated. identities as reconstruction targets or training on its morphing techniques. Despite this setup placing our model at a disadvantage, StyleDemorpher-S achieves competitive or superior performance across most evaluated morphing methods. When comparing results across the different morphing techniques within FRLL-Morphs, our approach consistently ranks among the top three in terms of accuracy, DCI, and DAI, often trailing only the Diffusion Autoencoder and FD-GAN, which were explicitly trained on this dataset. 5.5.5 D-MAD Differential Morphing Attack Detection (D-MAD) for face demorphing methods is often overlooked and not evaluated [6, 7, 21, 22]. This omission is acceptable only if a specialized D-MAD algorithm is first employed to identify morphed document images, and the demorphing algorithm is then applied to recover the accomplice’s hidden identity. In the absence of such specialized D-MAD algorithms, however, face demorphing methods themselves can serve as D-MAD approaches, as depicted in Fig. 4. To evaluate the D-MAD performance of StyleDemorpher, Table 8 reports the D-EER and BPCER values at fixed APCER thresholds of 1% and 5%, using the ArcFace [38] and CurricularFace [64] FRS models. The table does not include the No Demorphing scenario, for which the FRS requirement of F[email protected]% would no longer be satisfied because the decision threshold of the FRS would be increased to separate the morphed and bona fide scores. Table 8 Quantitative comparisons of D-MAD performance using ArcFace [38] and CurricularFace [64] FRS models across several datasets Dataset Demorphing Method D-EER (%) BPCER @ APCER (%) 5% 1% Arc [38] Cur [64] Arc [38] Cur [64] Arc [38] Cur [64] DemorphDB UTW [13] Face Demorphing [4] 1.961 0.294 0.784 0.000 2.451 0.098 StyleDemorpher-U (ours) 1.471 0.588 0.490 0.196 2.255 0.490 StyleDemorpher-S (ours) 1.275 0.196 0.196 0.000 1.667 0.098 DemorphDB StyleGAN2 [8] Face Demorphing [4] 4.706 0.294 4.216 0.000 8.333 0.098 StyleDemorpher-U (ours) 3.431 0.882 2.549 0.196 9.412 0.882 StyleDemorpher-S (ours) 2.059 0.392 0.392 0.000 3.627 0.196 HNU-FM Scenario 1 [57] Face Demorphing [4] 1.587 0.529 0.529 0.000 3.175 0.000 StyleDemorpher-U (ours) 1.323 0.529 1.323 0.000 2.116 0.265 StyleDemorpher-S (ours) 1.323 0.265 0.529 0.000 1.323 0.265 HNU-FM Scenario 2 [57] Face Demorphing [4] 7.143 0.794 7.672 0.529 18.783 0.794 StyleDemorpher-U (ours) 4.497 1.323 4.497 1.058 12.963 3.175 StyleDemorpher-S (ours) 3.439 1.058 2.910 0.529 5.820 1.323 FRLL-Morphs AMSL [14] Face Demorphing [4] 1.289 0.000 1.289 0.000 1.289 0.000 StyleDemorpher-U (ours) 0.414 0.276 0.000 0.000 0.000 0.000 StyleDemorpher-S (ours) 0.230 0.138 0.000 0.000 0.000 0.000 Values in bold indicate the best results 1 3 113 Page 16 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space Appendix A: DemorphDB Morphs To evaluate the quality of the morphs in the DemorphDB dataset (see Fig. 8 for examples of the morphing methods), the Mated Morph Presentation Match Rate (MMPMR) [66] metric is utilized with the decision threshold of facial recognition systems (FRS) set to a False Acceptance Rate (FAR) of 0.1%. Table 9 shows the MMPMR values for the three morphing methods used in the DemorphDB dataset across three different FRS models. Higher percentage scores indicate higher quality morphs, as they more effectively deceive facial recognition systems into accepting both identities present within a morphed image. As shown, the StyleGAN2 [8] morphs result in the highest scores. This can be explained by StyleGAN2 creating morphs where the region outside the face is also morphed, whereas UTW [13] and UTW-NS morphs crop the morph and paste it into the image of one of the identities. Thus, the UTW and UTW-NS morphs scored higher when accepting the identity whose outer face region 6 Conclusions This work presents a new deep learning-based face demorphing framework, overcoming the limitations of existing landmark-based and deep learning-based methods such as artifacts, low resolution, limited training identities, long processing times, and weak generalizability across unseen datasets and morphing techniques [4–7, 21, 22]. Two interlinked frameworks are introduced to achieve accurate, highquality face demorphing. ReStyle-ID forms the first framework, drawing on concepts from [10]. It encodes real facial images into the StyleGAN2 [8] latent space with minimal identity loss. Key innovations include removing background distractions, automatically cropping faces using MTCNN [35] during identity loss computation, and adopting the MS-SSIM [36] loss function. In addition, the dataset is expanded with both real and synthetic images. Collectively, these enhancements enable ReStyle-ID to preserve identity more effectively and place encodings in well-defined regions of the StyleGAN2 latent space, laying the groundwork for subsequent demorphing. StyleDemorpher, the second framework, specializes in reconstructing the identity of an accomplice from morphed document images. A new dataset, DemorphDB, containing 1,653 unique identities, was created for training. To counter overfitting on this relatively small dataset, transfer learning [9] is applied, initializing StyleDemorpher’s weights from the pretrained ReStyle-ID encoder. By processing both the morph image and a trusted live capture image, StyleDemorpher is trained to maximize the resemblance to the target identity of the accomplice while minimizing similarity to the criminal identity captured in the live image. It accurately isolates the accomplice’s identity from the morph, validating its efficacy in face demorphing. This framework demonstrates high generalizability, performing effectively with identities and morphing methods unseen during training. However, StyleDemorpher negatively affects the analysis of bona fide documents if it is applied directly to nonmorphed images. Since it is trained exclusively on morphed data, it presupposes that all inputs are morphs. Thus, it is advised to be used only after confirming a document’s morphed nature, e.g., through Differential Morph Attack Detection (D-MAD) [70–72]. Future efforts will focus on generating larger synthetic datasets with multiple images per identity, allowing bona fide paired data in training and reducing the impact on authentic documents. This improvement would further enhance overall D-MAD performance. Table 9 MMPMR [66] values for different morphing methods and facial recognition systems (FRSs) FRS Model Morphing method UTW [13] (%) UTW-NS (%) StyleGAN2 [8] (%) MobileFaceNet [63] 21.89 21.25 49.59 ArcFace [38] 63.38 59.02 95.41 CurricularFace [64] 94.37 90.06 99.47 Higher values correspond to higher quality morphs, effectively capturing both identities within a morph image Fig. 8 Examples of the morphing methods utilized in the DemorphDB dataset. Person A and B model the identities of the criminal and the accomplice, respectively. The UTW [13] and UTW-NS morphs use the splicing technique, whereas the StyleGAN2 [8] morphs also attempt to morph identities outside the face region. Ghosting artifacts are more present in UTW-NS morphs, as they do not swap different face parts between identities such as UTW morphs 1 3 Page 17 of 22 113 R. Ismayilov et al. IA rather than IA′ . This is done so that the demorphing network can better understand the direct impact of IA on IAB and the indirect relationship between IA and IA′ . Appendix C: Restoration accuracy curves The restoration accuracy defined in Eq. 17 is evaluated at a fixed threshold τ corresponding to F[email protected]%. While this threshold provides a standardized operating point, it depends on the underlying dataset used to estimate FAR and may not generalize across different application contexts. To provide a more comprehensive evaluation, we plot restoration accuracy as a function of the FRS decision threshold in Fig. 9. These curves, generated using CurricularFace [64] FRS, highlight the performance of StyleDemorpher compared to both No Demorphing and Face Demorphing [4] baselines on three types of morphs from DemorphDB. Across all morph types, StyleDemorpher consistently achieves higher restoration accuracy over a wide range of thresholds. The gains are most pronounced for StyleGAN2 morphs, where StyleDemorpher delivers a clear improvement over prior work across all thresholds. For UTW and UTW-NS morphs, improvements are more modest but still consistent, especially around the F[email protected]% threshold (marked by the dotted red line). These results confirm that StyleDemorpher is not only effective at a fixed operating point but also robust across varying decision boundaries. Appendix D: Robustness against image corruptions To assess the robustness of the StyleDemorpher against various image distortions, four different types of corruptions are artificially introduced to the input images: brightness change, Gaussian noise, JPEG compression, and resizing. The first three follow the corruption taxonomy of [75], with severity level 3 selected to reflect realistic but moderately matches the morph, while the identity captured only within the inner face part scored lower. Additionally, different FRS models show varying levels of effectiveness. The simpler and less accurate MobileFaceNet [63] rejects a larger proportion of the morphs, whereas the more complex and accurate CurricularFace [64] model is often deceived by the morphs. This occurs because, being a better FRS, CurricularFace can detect the traces of both identities used to generate the morph more effectively, making it more susceptible to morphing attacks. Appendix B: Training details Both the ReStyle-ID and StyleDemorpher frameworks are trained on input images resized to 256 ×256 resolution, whereas the generated images at the output have 1024 ×1024 resolution. During the computation of losses, the output images are resized down to 256 ×256 , with the exception of identity ( λID ) and inverse identity ( λInvID ) losses, which require an input resolution of 112 ×112 and further cropping around the face region. The training is performed using the Ranger optimizer, which integrates the Lookahead technique [73] with the Rectified Adam [74] optimizer. A batch size of 6 is utilized, and all the experiments are executed on an NVIDIA RTX 4090 GPU. The ReStyle-ID framework is trained for 18 epochs with a learning rate of 0.0001, whereas the StyleDemorpher framework (both UTW-NS and StyleGAN2 morph variants) is trained for 20 epochs with a learning rate of 0.00001. Since StyleDemorpher is trained on the DemorphDB dataset with a limited number of target identities, regularization techniques are utilized to prevent overfitting. A weight decay of 0.0001 is applied and the map2style [31] networks (see Fig. 2) are modified to include dropout layers. Specifically, 4 dropout layers with a dropout rate of 0.2 are added to each of the 18 map2style networks after each Convolution-LeakyReLU block. Finally, it should be noted that only during StyleDemorpher training is the input image of identity A empirically set to have a 20% chance of being Fig. 9 Restoration accuracy [7] plotted against different FRS threshold values of CurricularFace [64]. The dotted red line corresponds to the F[email protected]% decision threshold. The results are presented for the cases of No Demorphing, Face Demorphing [4], and StyleDemorpher 1 3 113 Page 18 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space euwers; Methodology: Raul Ismayilov; Software: Raul Ismayilov, Ilias Batskos; Validation: Raul Ismayilov, Luuk Spreeuwers, Ilias Batskos; Formal analysis and investigation: Raul Ismayilov; Data Curation: Raul Ismayilov; Writing - Original Draft: Raul Ismayilov; Visualization: Raul Ismayilov; Supervision: Luuk Spreeuwers, Ilias Batskos. Funding This research was funded by the European Union under the Horizon Europe programme, Grant Agreement No. 101121280. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect the views of the EU/Executive Agency. Neither the EU nor the granting authority can be held responsible for them. Data availability The DemorphDB dataset can be shared upon request, provided that access has been granted to all underlying datasets that contribute to it. Since some of these datasets require license agreements, requesters must first obtain the necessary permissions before access to DemorphDB can be granted. Code availability The code used in this study will be made available upon request. Declarations Conflict of interest We declare that there are no Conflict of interest related to this research. Ethical approval This study does not involve research with human participants and/or animals. Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit h t t p : / / c r e a t i v e c o m m o n s . o r g / l i c e n s e s / b y / 4 . 0 /. References 1. Best Practice Technical Guidelines for Automated Border Control (ABC) Systems. FRONTEX (2015). h t t p s : / / b o o k s . g o o g l e . n l / b o o k s ? i d = b Y O N n Q A A C A A J 2. Ferrara, M., Franco, A., Maltoni, D.: The magic passport. In: IEEE International Joint Conference on Biometrics, pp. 1–7 (2014). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / B T A S . 2 0 1 4 . 6 9 9 6 2 4 0 3. Raghavendra, R., Raja, K.B., Busch, C.: Detecting morphed face images. In: 2016 IEEE 8th International Conference on Biometrics Theory, Applications and Systems (BTAS), pp. 1–7 (2016). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / B T A S . 2 0 1 6 . 7 7 9 1 1 6 9 4. Ferrara, M., Franco, A., Maltoni, D.: Face demorphing. IEEE Trans. Inf. For. Secur. 13(4), 1008–1017 (2018). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T I F S . 2 0 1 7 . 2 7 7 7 3 4 0 5. Ortega-Delcampo, D., Conde, C., Palacios-Alonso, D., Cabello, E.: Border control morphing attack detection with a convolutional neural network de-morphing approach. IEEE Access 8, 92301– 92313 (2020). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / A C C E S S . 2 0 2 0 . 2 9 9 4 1 1 2 challenging degradations. For resizing corruption, input images are downsampled from 256 ×256 to 128 ×128 and then upsampled back to the original resolution. Figure 10 presents visual examples of these image corruptions. To isolate the effect of these corruptions on the restoration process itself (rather than on the FRS), only the input images to the StyleDemorpher framework are corrupted. The restoration accuracy metric (see Eq. 17) is computed based on identity similarity scores between the demorphed image Iˆ B and both IB and IA′ . To ensure that any observed performance degradation is attributable solely to the demorphing process, the images IB and IA′ remain unaltered during evaluation. In other words, only Iˆ B is affected by the corrupted input images, allowing us to directly assess the quality of the restored image produced under degraded input conditions. Based on the results shown in Fig. 11, it can be seen that the majority of image corruptions have minimal effects on the restoration accuracy curves, with only brightness change and Gaussian noise image corruptions having any measurable impact. While the results are only shown for DemorphDB’s StyleGAN2 [8] morphs with CurricularFace [64] FRS, similar performance was observed across other morphing methods and FRS models. Therefore, these results show that the StyleDemorpher is highly generalizable and resilient to unknown image corruptions. Author contributions Conceptualization: Raul Ismayilov, Luuk SpreFig. 11 Restoration accuracy [7] plotted against different FRS threshold values of CirrucularFace [64]. The dotted red line corresponds to the F[email protected]% decision threshold. The results are presented for the cases of No Demorphing, and the use of StyleDemorpher on clean and corrupted by various image corruption methods images. StyleGAN2 [8] morphs of the DemorphDB dataset are utilized Fig. 10 Examples of image corruptions applied to the images before passing them through the StyleDemorpher framework 1 3 Page 19 of 22 113 R. Ismayilov et al. 195–222. Springer, Cham (2016). h t t p s : / / d o i . o r g / 1 0 . 1 0 0 7 / 9 7 8 - 3 - 3 1 9 - 2 8 5 0 1 - 6 _ 9 . h t t p s : / / d o i . o r g / 1 0 . 1 0 0 7 / 9 7 8 - 3 - 3 1 9 - 2 8 5 0 1 - 6 _ 9 21. Long, M., Zhou, J., Zhang, L.-B., Peng, F., Zhang, D.: Adff: Adaptive de-morphing factor framework for restoring accomplice’s facial image. IET Image Proc. 18(2), 470–480 (2024). h t t p s : / / d o i . o r g / 1 0 . 1 0 4 9 / i p r 2 . 1 2 9 6 2 22. Long, M., Yao, Q., Zhang, L.-B., Peng, F.: Face de-morphing based on diffusion autoencoders. IEEE Trans. Inf. For. Secur. 19, 3051–3063 (2024). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T I F S . 2 0 2 4 . 3 3 5 9 0 2 9 23. Preechakul, K., Chatthee, N., Wizadwongsa, S., Suwajanakorn, S.: Diffusion autoencoders: Toward a meaningful and decodable representation. 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 10609–10619 (2021) 24. Karras, T., Laine, S., Aila, T.: A style-based generator architecture for generative adversarial networks. IEEE Trans. Pattern Anal. Mach. Intell. 43(12), 4217–4228 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T P A M I . 2 0 2 0 . 2 9 7 0 9 1 9 25. Radford, A., Metz, L., Chintala, S.: Unsupervised Representation Learning with Deep Convolutional Generative Adversarial Networks (2016). h t t p s : / / a r x i v . o r g / a b s / 1 5 1 1 . 0 6 4 3 4 26. Brock, A., Donahue, J., Simonyan, K.: Large Scale GAN Training for High Fidelity Natural Image Synthesis (2019). h t t p s : / / a r x i v . o r g / a b s / 1 8 0 9 . 1 1 0 9 6 27. Xia, W., Zhang, Y., Yang, Y., Xue, J.-H., Zhou, B., Yang, M.-H.: Gan inversion: a survey. IEEE Trans. Pattern Anal. Mach. Intell. 45(3), 3121–3138 (2023). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T P A M I . 2 0 2 2 . 3 1 8 1 0 7 0 28. Abdal, R., Qin, Y., Wonka, P.: Image2stylegan: How to embed images into the stylegan latent space? In: 2019 IEEE/CVF International Conference on Computer Vision (ICCV), pp. 4431–4440 (2019). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I C C V . 2 0 1 9 . 0 0 4 5 3 29. Zhu, P., Abdal, R., Qin, Y., Femiani, J., Wonka, P.: Improved StyleGAN Embedding: Where are the Good Latents? (2021). h t t p s : / / a r x i v . o r g / a b s / 2 0 1 2 . 0 9 0 3 6 30. Tov, O., Alaluf, Y., Nitzan, Y., Patashnik, O., Cohen-Or, D.: Designing an encoder for stylegan image manipulation. ACM Trans. Graph. (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 4 5 / 3 4 5 0 6 2 6 . 3 4 5 9 8 3 8 31. Richardson, E., Alaluf, Y., Patashnik, O., Nitzan, Y., Azar, Y., Shapiro, S., Cohen-Or, D.: Encoding in style: a stylegan encoder for image-to-image translation. In: 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2287– 2296 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R 4 6 4 3 7 . 2 0 2 1 . 0 0 2 3 2 32. Abdal, R., Zhu, P., Mitra, N.J., Wonka, P.: Styleflow: attributeconditioned exploration of stylegan-generated images using conditional continuous normalizing flows. ACM Trans. Graphics 40(3), 1–21 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 4 5 / 3 4 4 7 6 4 8 33. Khodadadeh, S., Ghadar, S., Motiian, S., Lin, W.-A., Bölöni, L., Kalarot, R.: Latent to latent: A learned mapper for identity preserving editing of multiple face attributes in stylegan-generated images. In: 2022 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV), pp. 3677–3685 (2022). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / W A C V 5 1 4 5 8 . 2 0 2 2 . 0 0 3 7 3 34. Le, M.-H., Carlsson, N.: Styleid: identity disentanglement for anonymizing faces. Proc. Priv. Enhancing Technol. 2023, 264– 278 (2022) 35. Zhang, K., Zhang, Z., Li, Z., Qiao, Y.: Joint face detection and alignment using multitask cascaded convolutional networks. IEEE Signal Process. Lett. 23(10), 1499–1503 (2016). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / l s p . 2 0 1 6 . 2 6 0 3 3 4 2 36. Wang, Z., Simoncelli, E.P., Bovik, A.C.: Multiscale structural similarity for image quality assessment. In: The Thrity-Seventh Asilomar Conference on Signals, Systems & Computers, 2003, vol. 2, pp. 1398–14022 (2003). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / A C S S C . 2 0 0 3 . 1 2 9 2 2 1 6 37. Lin, T.-Y., Dollar, P., Girshick, R., He, K., Hariharan, B., Belongie, S.: Feature pyramid networks for object detection. In: 6. Banerjee, S., Ross, A.: Conditional identity disentanglement for differential face morph detection. In: 2021 IEEE International Joint Conference on Biometrics (IJCB), pp. 1–8 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I J C B 5 2 3 5 8 . 2 0 2 1 . 9 4 8 4 3 5 5 7. Peng, F., Zhang, L.-B., Long, M.: Fd-gan: Face de-morphing generative adversarial network for restoring accomplice’s facial image. IEEE Access 7, 75122–75131 (2019). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / A C C E S S . 2 0 1 9 . 2 9 2 0 7 1 3 8. Karras, T., Laine, S., Aittala, M., Hellsten, J., Lehtinen, J., Aila, T.: Analyzing and improving the image quality of stylegan. In: 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 8107–8116 (2020). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R 4 2 6 0 0 . 2 0 2 0 . 0 0 8 1 3 9. Pan, S.J., Yang, Q.: A survey on transfer learning. IEEE Trans. Knowl. Data Eng. 22(10), 1345–1359 (2010). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T K D E . 2 0 0 9 . 1 9 1 10. Alaluf, Y., Patashnik, O., Cohen-Or, D.: Restyle: A residualbased stylegan encoder via iterative refinement. In: 2021 IEEE/ CVF International Conference on Computer Vision (ICCV), pp. 6691–6700 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I C C V 4 8 9 2 2 . 2 0 2 1 . 0 0 6 6 4 11. Rogers, D.F., Adams, J.A.: Mathematical Elements for Computer Graphics, 2nd edn. McGraw-Hill Higher Education, New York, NY, USA (1989) 12. Ferrara, M., Franco, A., Maltoni, D.: Decoupling texture blending and shape warping in face morphing. In: 2019 International Conference of the Biometrics Special Interest Group (BIOSIG), pp. 1–5 (2019) 13. Batskos, I., Spreeuwers, L.: Improving fully automated landmark-based face morphing. In: 2024 12th International Workshop on Biometrics and Forensics (IWBF), pp. 1–6 (2024). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I W B F 6 2 6 2 8 . 2 0 2 4 . 1 0 5 9 3 9 8 5 14. Neubert, T., Makrushin, A., Hildebrandt, M., Kraetzer, C., Dittmann, J.: Extended stirtrace benchmarking of biometric and forensic qualities of morphed face images. IET Biometrics 7(4), 325–332 (2018). h t t p s : / / d o i . o r g / 1 0 . 1 0 4 9 / i e t - b m t . 2 0 1 7 . 0 1 4 7 15. Makrushin, A., Neubert, T., Dittmann, J.: Automatic Generation and Detection of Visually Faultless Facial Morphs. In: Proceedings of the 12th International Joint Conference on Computer Vision, Imaging and Computer Graphics Theory and Applications - Volume 6: VISAPP, (VISIGRAPP 2017), pp. 39–50. SciTePress, Porto, Portugal (2017). h t t p s : / / d o i . o r g / 1 0 . 5 2 2 0 / 0 0 0 6 1 3 1 1 0 0 3 9 0 0 5 0 . INSTICC 16. Damer, N., Saladié, A.M., Braun, A., Kuijper, A.: Morgan: Recognition vulnerability and attack detectability of face morphing attacks created by generative adversarial network. In: 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS), pp. 1–10 (2018). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / B T A S . 2 0 1 8 . 8 6 9 8 5 6 3 17. Zhang, H., Venkatesh, S., Ramachandra, R., Raja, K., Damer, N., Busch, C.: Mipgan—generating strong and high quality morphing attacks using identity prior driven gan. IEEE Trans. Biom. Behav. Identity Sci. 3(3), 365–383 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T B I O M . 2 0 2 1 . 3 0 7 2 3 4 9 18. Damer, N., Fang, M., Siebke, P., Kolf, J.N., Huber, M., Boutros, F.: Mordiff: Recognition vulnerability and attack detectability of face morphing attacks created by diffusion autoencoders. In: 2023 11th International Workshop on Biometrics and Forensics (IWBF), pp. 1–6 (2023). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I W B F 5 7 4 9 5 . 2 0 2 3 . 1 0 1 5 7 8 6 9 19. Venkatesh, S., Ramachandra, R., Raja, K., Busch, C.: Face morphing attack generation and detection: a comprehensive survey. IEEE Trans. Technol. Soc. 2(3), 128–145 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T T S . 2 0 2 1 . 3 0 6 6 2 5 4 20. Ferrara, M., Franco, A., Maltoni, D.: In: Bourlai, T. (ed.) On the Effects of Image Alterations on Face Recognition Accuracy, pp. 1 3 113 Page 20 of 22 StyleDemorpher: high-quality face demorphing via StyleGAN2’s latent space 53. Lakshmi, B., Wittenbrink, B., Correll, J., Ma, D.S.: The india face set: international and cultural boundaries impact face impressions and perceptions of category membership. Front. Psychol. 12, 161 (2020). h t t p s : / / d o i . o r g / 1 0 . 3 3 8 9 / f p s y g . 2 0 2 1 . 6 2 7 6 7 8 54. DeBruine, L.M., Jones, B.C.: Face research lab london set. (2017). Accessed: 2024-12-12. h t t p s : / / a p i . s e m a n t i c s c h o l a r . o r g / C o r p u s I D : 1 4 8 8 1 2 1 5 1 55. King, D.E.: Dlib-ml: a machine learning toolkit. J. Mach. Learn. Res. 10, 1755–1758 (2009) 56. Afifi, M., Price, B., Cohen, S., Brown, M.S.: When color constancy goes wrong: Correcting improperly white-balanced images. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1535–1544 (2019) 57. Zhang, L.-B., Cai, J., Peng, F., Long, M.: A benchmark database for the comparison of face morphing detection methods. In: 2021 International Conference on Electronic Information Technology and Smart Agriculture (ICEITSA), pp. 393–401 (2021). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I C E I T S A 5 4 2 2 6 . 2 0 2 1 . 0 0 0 8 2 58. Sarkar, E., Korshunov, P., Colbois, L., Marcel, S.: Vulnerability analysis of face morphing attacks from landmarks and generative adversarial networks. arXiv preprint (2020) 59. Sarkar, E., Korshunov, P., Colbois, L., Marcel, S.: Are gan-based morphs threatening face recognition? In: ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 2959–2963 (2022). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / I C A S S P 4 3 9 2 2 . 2 0 2 2 . 9 7 4 6 4 7 7 60. Mallick, S.: Face Morph using OpenCV — C++ / Python — LearnOpenCV. Accessed: 2024-12-12 (2016). h t t p s : / / l e a r n o p e n c v . c o m / f a c e - m o r p h - u s i n g - o p e n c v - c p p - p y t h o n / 61. Quek, A.: Facemorpher. Accessed: 2024-12-12 (2019). h t t p s : / / g i t h u b . c o m / a l y s s a q / f a c e _ m o r p h e r 62. DeBruine, L.: debruine/webmorph: Beta release 2. h t t p s : / / d o i . o r g / 1 0 . 5 2 8 1 / z e n o d o . 1 1 6 2 6 7 0. Zenodo, Accessed: 2024-12-12 (2018) 63. Chen, S., Liu, Y., Gao, X., Han, Z.: Mobilefacenets: Efficient cnns for accurate real-time face verification on mobile devices. In: Biometric Recognition, pp. 428–438. Springer, Cham (2018) 64. Huang, Y., Wang, Y., Tai, Y., Liu, X., Shen, P., Li, S., Li, J., Huang, F.: Curricularface: Adaptive curriculum learning loss for deep face recognition. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2020) 65. Frontex: Best Practice Operational Guidelines for Automated Border Control (ABC) Systems – Research and Development Unit. Publications Office of the European Union, Warsaw, Poland (2012). https://doi.org/10.2819/26969 66. Scherhag, U., Nautsch, A., Rathgeb, C., Gomez-Barrero, M., Veldhuis, R.N.J., Spreeuwers, L., Schils, M., Maltoni, D., Grother, P., Marcel, S., Breithaupt, R., Ramachandra, R., Busch, C.: Biometric systems under morphing attacks: Assessment of morphing techniques and vulnerability reporting. In: 2017 International Conference of the Biometrics Special Interest Group (BIOSIG), pp. 1–7 (2017). h t t p s : / / d o i . o r g / 1 0 . 2 3 9 1 9 / B I O S I G . 2 0 1 7 . 8 0 5 3 4 9 9 67. International Organization for Standardization and International Electrotechnical Commission: International standard iso/iec cd 20059.2: Methodologies to evaluate the resistance of biometric recognition systems to morphing attacks. Technical report, ISO/ IEC (2023) 68. Banerjee, S., Jaiswal, P., Ross, A.: Facial de-morphing: Extracting component faces from a single morph. 2022 IEEE International Joint Conference on Biometrics (IJCB), 1–10 (2022) 69. Face++ Compare API. h t t p s : / / w w w . f a c e p l u s p l u s . c o m / f a c e - c o m p a r i n g /. Accessed: July 2025 70. Scherhag, U., Rathgeb, C., Merkle, J., Busch, C.: Deep face representations for differential morphing attack detection. IEEE Trans. Inf. For. Secur. 15, 3625–3639 (2020). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / T I F S . 2 0 2 0 . 2 9 9 4 7 5 0 Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2017) 38. Deng, J., Guo, J., Yang, J., Xue, N., Kotsia, I., Zafeiriou, S.: Arcface: additive angular margin loss for deep face recognition. IEEE Trans. Pattern Anal. Mach. Intell. 44(10), 5962–5979 (2022). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / t p a m i . 2 0 2 1 . 3 0 8 7 7 0 9 39. Lee, C.-H., Liu, Z., Wu, L., Luo, P.: Maskgan: Towards diverse and interactive facial image manipulation. In: 2020 IEEE/ CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 5548–5557 (2020). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R 4 2 6 0 0 . 2 0 2 0 . 0 0 5 5 9 40. Karras, T., Aila, T., Laine, S., Lehtinen, J.: Progressive growing of GANs for improved quality, stability, and variation. In: International Conference on Learning Representations (2018). h t t p s : / / o p e n r e v i e w . n e t / f o r u m ? i d = H k 9 9 z C e A b 41. Dosovitskiy, A., Brox, T.: Generating images with perceptual similarity metrics based on deep networks. In: Lee, D., Sugiyama, M., Luxburg, U., Guyon, I., Garnett, R. (eds.) Advances in Neural Information Processing Systems, vol. 29. Curran Associates, Inc., Red Hook, NY, USA (2016). h t t p s : / / p r o c e e d i n g s . n e u r i p s . c c / p a p e r _ fi l e s / p a p e r / 2 0 1 6 / fi l e / 3 7 1 b c e 7 d c 8 3 8 1 7 b 7 8 9 3 b c d e e d 1 3 7 9 9 b 5 - P a p e r . p d f 42. Ledig, C., Theis, L., Huszár, F., Caballero, J., Cunningham, A., Acosta, A., Aitken, A., Tejani, A., Totz, J., Wang, Z., Shi, W.: Photo-realistic single image super-resolution using a generative adversarial network. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 105–114 (2017). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R . 2 0 1 7 . 1 9 43. Gatys, L.A., Ecker, A.S., Bethge, M.: Image style transfer using convolutional neural networks. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 2414– 2423 (2016). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R . 2 0 1 6 . 2 6 5 44. Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition, pp. 586–595 (2018). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R . 2 0 1 8 . 0 0 0 6 8 45. Krizhevsky, A., Sutskever, I., Hinton, G.E.: Imagenet classification with deep convolutional neural networks. In: Advances in Neural Information Processing Systems, vol. 25. Curran Associates, Inc., Red Hook, NY, USA (2012) 46. Johnson, J., Alahi, A., Fei-Fei, L.: Perceptual losses for real-time style transfer and super-resolution. In: Computer Vision – ECCV 2016, pp. 694–711. Springer, Cham (2016) 47. Guan, S., Tai, Y., Ni, B., Zhu, F., Huang, F., Yang, X.: Collaborative Learning for Faster StyleGAN Embedding (2020). h t t p s : / / a r x i v . o r g / a b s / 2 0 0 7 . 0 1 7 5 8 48. Phillips, P.J., Flynn, P.J., Scruggs, T., Bowyer, K.W., Chang, J., Hoffman, K., Marques, J., Min, J., Worek, W.: Overview of the face recognition grand challenge. In: 2005 IEEE Computer Society Conference on Computer Vision and Pattern Recognition (CVPR’05), vol. 1, pp. 947–9541 (2005). h t t p s : / / d o i . o r g / 1 0 . 1 1 0 9 / C V P R . 2 0 0 5 . 2 6 8 49. Sepas-Moghaddam, A., Chiesa, V., Correia, P.L., Pereira, F., Dugelay, J.: The ist-eurecom light field face database. In: International Workshop on Biometrics and Forensics, IWBF 2017, Coventry, UK (2017) 50. Hancock, P.: Psychological Image Collection at Stirling (PICS). Accessed: 2024-12-12 (2008). http://pics.psych.stir.ac.uk 51. Ma, D.S., Correll, J., Wittenbrink, B.: The chicago face database: a free stimulus set of faces and norming data. Behav. Res. Methods 47, 1122–1135 (2015). h t t p s : / / d o i . o r g / 1 0 . 3 7 5 8 / s 1 3 4 2 8 - 0 1 4 - 0 5 3 2 - 5 52. Ma, D.S., Kantner, J., Wittenbrink, B.: Chicago face database: multiracial expansion. Behav. Res. Methods (2020). h t t p s : / / d o i . o r g / 1 0 . 3 7 5 8 / s 1 3 4 2 8 - 0 2 0 - 0 1 4 8 2 - 5 1 3 Page 21 of 22 113 R. Ismayilov et al. Luuk Spreeuwers is an associate professor at the Department of Electrical Engineering, Mathematics and Computer Science, University of Twente, Netherlands. He received the PhD degree in 1992 from the University of Twente. He has previously worked at the International Institute for Aerospace and Earth Sciences in Enschede, the Hungarian Academy of Sciences in Budapest, and the University Medical Centre Utrecht on projects involving 3-D image analysis, aerial imagery, and medical imaging. He currently leads the Computer Vision and Biometrics subgroup within the Data Management and Biometrics chair, supervising research in biometrics, 2D/3D face recognition, morphing attack detection, computer vision, and pattern recognition. He has authored over 100 publications in international journals and conferences. Ilias Batskos obtained his PhD in 2025 from the Department of Electrical Engineering, Mathematics and Computer Science, University of Twente, Netherlands. His dissertation focused on the problem of face image morphing in identification documents, with contributions in morph generation, prevention, forensic analysis, and detection. His research interests are in biometric security, face morphing attack detection, and computer vision. 71. Borghi, G., Pancisi, E., Ferrara, M., Maltoni, D.: A double siamese framework for differential morphing attack detection. Sensors (2021). h t t p s : / / d o i . o r g / 1 0 . 3 3 9 0 / s 2 1 1 0 3 4 6 6 72. Chaudhary, B., Aghdaie, P., Soleymani, S., Dawson, J., Nasrabadi, N.M.: Differential morph face detection using discriminative wavelet sub-bands. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Workshops, pp. 1425–1434 (2021) 73. Zhang, M., Lucas, J., Ba, J., Hinton, G.E.: Lookahead optimizer: k steps forward, 1 step back. In: Wallach, H., Larochelle, H., Beygelzimer, A., Alché-Buc, F., Fox, E., Garnett, R. (eds.) Advances in Neural Information Processing Systems, vol. 32. Curran Associates, Inc., Red Hook, NY, USA (2019). h t t p s : / / p r o c e e d i n g s . n e u r i p s . c c / p a p e r _ fi l e s / p a p e r / 2 0 1 9 / fi l e / 9 0 f d 4 f 8 8 f 5 8 8 a e 6 4 0 3 8 1 3 4 f 1 e e a a 0 2 3 f - P a p e r . p d f 74. Liu, L., Jiang, H., He, P., Chen, W., Liu, X., Gao, J., Han, J.: On the Variance of the Adaptive Learning Rate and Beyond. (2020). Publisher Copyright: © 2020 8th International Conference on Learning Representations, ICLR 2020. All rights reserved.; 8th International Conference on Learning Representations, ICLR 2020 ; Conference date: 30-04-2020 75. Hendrycks, D., Dietterich, T.: Benchmarking neural network robustness to common corruptions and perturbations. In: International Conference on Learning Representations (2019). h t t p s : / / o p e n r e v i e w . n e t / f o r u m ? i d = H J z 6 t i C q Y m Publisher's Note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. Raul Ismayilov is a PhD candidate at the Department of Electrical Engineering, Mathematics and Computer Science, University of Twente, Netherlands. He completed both his BSc and MSc at the same university, specialising in Computer Vision and Biometrics. The work presented in this paper is a revised version of his MSc thesis. His research interests focus on deep learning, computer vision, and biometric analysis of facial data, with particular attention to face demorphing and synthetic face generation. 1 3 113 Page 22 of 22