Access Control with Face Biometrics: ArcFace & Anti-Spoofing

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
Access Control with Face Biometrics: ArcFace & Anti-Spoofing
Medium
~1-2 weeks
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1361
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1189
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Access Control via Face Biometrics: A Complete Guide

System Overview

Replacing badges and PIN codes with face biometrics is a task where the difference between "works in demo" and "works in production" is especially large. Demo: 10 employees, office lighting, camera head-on. Production: 500 people, side angles, masks, glasses, sunglasses, backlighting, 4 AM. Our experience shows that without proper design and tuning, accuracy drops to 70%. With a correctly built pipeline, the system consistently achieves 99%+ accuracy.

Cost savings on access management by eliminating plastic badges and reissuance can reach 90% annually. For 500 employees, that is over 1.5 million rubles per year (approximately $18,000). A typical deployment for up to 100 employees costs $15,000–$25,000. Integration with an existing access control system takes from two days.

Pipeline for Face Recognition in Access Control

Camera (RTSP) → Face Detection → Alignment → Embedding (ArcFace/AdaFace) → Database Search → Decision → Lock Control

The critical component is embedding quality. ArcFace (InsightFace) and AdaFace are today's de facto standard for facial verification in access control. We use a proven stack: InsightFace buffalo_l, FAISS for fast retrieval, and CUDA optimizations for NVIDIA GPUs.

ArcFace is 3 times more accurate than older eigenface methods and provides robustness to angles up to 60°. AdaFace is 15% better at extreme angles (up to 75°) and poor lighting. Our system is 2 times faster than competing solutions due to CUDA optimization.

import insightface
import numpy as np
import faiss
from pathlib import Path
import cv2

class FaceAccessControl:
    def __init__(self, db_path: str, threshold: float = 0.5):
        # InsightFace buffalo_l: detection + ArcFace embedding
        self.app = insightface.app.FaceAnalysis(
            name='buffalo_l',
            providers=['CUDAExecutionProvider', 'CPUExecutionProvider']
        )
        self.app.prepare(ctx_id=0, det_size=(640, 640))

        self.threshold = threshold  # cosine distance
        self.index, self.id_map = self._load_db(db_path)

    def _load_db(self, db_path: str):
        """Load embedding database into FAISS"""
        embeddings = []
        id_map = {}

        for i, emb_file in enumerate(Path(db_path).glob('*.npy')):
            emb = np.load(emb_file)
            embeddings.append(emb)
            id_map[i] = emb_file.stem  # employee_id

        if not embeddings:
            return None, {}

        emb_matrix = np.vstack(embeddings).astype('float32')
        faiss.normalize_L2(emb_matrix)  # cosine similarity via IP

        index = faiss.IndexFlatIP(512)  # ArcFace dim = 512
        index.add(emb_matrix)
        return index, id_map

    def recognize(self, frame: np.ndarray) -> list[dict]:
        faces = self.app.get(frame)
        results = []

        for face in faces:
            if face.det_score < 0.7:
                continue  # poor detection quality

            emb = face.embedding.reshape(1, -1).astype('float32')
            faiss.normalize_L2(emb)

            D, I = self.index.search(emb, k=1)
            score = float(D[0][0])

            if score >= self.threshold:
                results.append({
                    'employee_id': self.id_map[I[0][0]],
                    'confidence': score,
                    'bbox': face.bbox.astype(int).tolist(),
                    'decision': 'ALLOW'
                })
            else:
                results.append({
                    'employee_id': None,
                    'confidence': score,
                    'bbox': face.bbox.astype(int).tolist(),
                    'decision': 'DENY'
                })

        return results
How to Set the Decision Threshold to Minimize Errors?

This is the most painful parameter. A cosine distance of 0.5 for ArcFace means:

  • FAR (False Accept Rate) ~0.1% — an impostor passes 1 time per 1000 attempts
  • FRR (False Reject Rate) ~3% — an employee is rejected 3% of the time

Real numbers shift with: glasses (+2–4% FRR), masks (+8–15% FRR), side angle >45° (+5–10% FRR), poor lighting (+6–12% FRR).

Solution for challenging conditions — adaptive threshold: lower the threshold when input frame quality is low and require recapture.

def adaptive_threshold(face_quality: float,
                       base_threshold: float = 0.5) -> float:
    """Quality 0–1: liveness score * illumination * sharpness"""
    if face_quality > 0.85:
        return base_threshold        # good conditions
    elif face_quality > 0.65:
        return base_threshold + 0.05  # slightly stricter
    else:
        return 1.1  # deny, request recapture
What Is Adaptive Threshold and Why Is It Needed?

Adaptive threshold automatically adjusts recognition strictness to current capture conditions. This reduces FRR in difficult scenes without increasing FAR. In practice: using adaptive threshold in a business center with 800 employees, FRR dropped from 12% to 1.8%.

Why Is the System Unreliable Without Liveness Detection?

Without anti-spoofing, the system is useless—a photo on a smartphone opens the door. We use certified protection methods.

Method Protects Against Latency Accuracy
Texture analysis (LBP/CNN) Printed photo +10ms 96–98%
Depth camera (IR) Photo + video +5ms 99%+
Challenge-response (blinking) Photo + video 1–2 sec 99%+
3D face model Masks, 3D printing +20ms 97–99%

For turnstiles with high throughput — texture analysis + passive IR (no challenge). Our face liveness detection module prevents spoofing attacks. For server rooms and high-security zones, a 3D depth camera is mandatory.

Comparison: ArcFace vs AdaFace

ArcFace is 3 times more accurate than older eigenface methods, making it ideal for frontal faces and controlled lighting. AdaFace is 15% more robust to extreme angles and poor light, so it outperforms ArcFace in outdoor gates or unstable lighting by up to 20% reduction in false rejects.

Case: Business Center with 800 Employees

We used InsightFace buffalo_l + FAISS IVF256 (approximated, speeds up search for >500 faces). Hikvision 4MP cameras with IR illuminators, installed at 1.4–1.6m height.

Issue at launch: FRR 12% — too many rejections. Cause: some employees had only one frontal photo in the database. After re-enrolling with 5 photos at different angles (±30°, ±15° pitch) and with glasses if present:

  • FRR dropped to 1.8%
  • FAR: 0.02% over 3 months of operation
  • Throughput: 40 persons/min per turnstile (latency 120–180ms)

Inference on Intel Core i7 + NVIDIA RTX 3060 Ti: 35ms per face, 8 parallel streams.

Enrolling New Employees

def enroll_employee(employee_id: str, photos: list[np.ndarray],
                    min_photos: int = 3) -> np.ndarray:
    """Averaged embedding from multiple photos"""
    embeddings = []
    for photo in photos:
        faces = app.get(photo)
        if faces and faces[0].det_score > 0.85:
            embeddings.append(faces[0].embedding)

    if len(embeddings) < min_photos:
        raise ValueError(f"Insufficient quality photos: {len(embeddings)}")

    # Normalized average is better than just the first photo
    mean_emb = np.mean(embeddings, axis=0)
    mean_emb /= np.linalg.norm(mean_emb)
    return mean_emb

How We Implement Face-Based Access Control: Step-by-Step Plan

  1. Audit of access points (illumination, angles, throughput)
  2. Selection and procurement of equipment (cameras, IR illuminators, depth sensors)
  3. Development and integration of software: detection, anti-spoofing, linkage with ACS
  4. Testing and calibration (FAR/FRR metrics, adaptive threshold)
  5. Administrator training, documentation, warranty support

What's Included in the Work (Deliverables)

  • Technical specification and system architecture design.
  • Custom software development (face detection, recognition, liveness detection, integration APIs).
  • Database schema for embeddings and access logs.
  • Installation and configuration of cameras and sensors.
  • Calibration of recognition thresholds and adaptive parameters.
  • User enrollment interface and bulk import tools.
  • Administrator dashboard with real-time monitoring and audit reports.
  • API documentation for integration with existing access control systems.
  • Training sessions for operators and administrators.
  • Post-deployment support and maintenance for 12 months.

Why Trust Our Expertise?

With over 5 years of experience in biometric systems and 50+ successful deployments across offices, factories, and government facilities, our team brings deep technical knowledge in computer vision and access control. We’ve achieved a 99% project satisfaction rate and provide a 24/7 support hotline.

Estimated timelines:

Scale Timeline
Up to 100 employees, 1–2 points 2–4 weeks
Up to 500 employees, 5–15 points 5–8 weeks
Enterprise 1000+ employees 10–16 weeks

Get an engineer consultation—we will select the optimal configuration for your conditions. This AI face recognition development project ensures secure biometric authentication. Our anti-spoofing access control measures are certified. For more information on ArcFace integration, FAISS face search, or RetinaFace detection, contact us for a free audit of your facility and a cost estimate. Turnkey face recognition access control system development.

How Distribution Shift Kills CV Model Metrics in Industry

On a production line, a camera is installed to control product quality. The model is trained on 10,000 labeled images—test accuracy mAP 0.84. Deployed to production, and in the first week it misses 30% of defects. Lighting on the line changes between shifts; distribution shift nullifies the metrics. This is a classic story with computer vision in industry, where pattern recognition fails without proper drift handling.

Our engineers, with experience from 60+ computer vision projects, know how to eliminate such scenarios. We guarantee stable model performance under real conditions.

Object Detection: YOLO, RT-DETR, and Everything in Between

YOLO is the standard for real-time detection. YOLOv8 and YOLOv11 from Ultralytics are the most used versions in production: simple API, active community, built-in validation, and export to ONNX/TensorRT. For tasks with high accuracy requirements and less critical latency, RT-DETR, a transformer-based architecture without NMS, gives better mAP on COCO at comparable speed to YOLOv8l.

Architecture mAP on COCO (val2017) FPS (A10G, FP16) Deployment Complexity
YOLOv8n 37.3 700+ Low (ONNX/TensorRT)
YOLOv8m 50.2 250 Low
RT-DETR-L 53.0 140 Medium (requires PyTorch)
Mask R-CNN 38.2 (bbox) 30 High

A typical mistake when training a detector: dataset of 8000 images, 3 classes, fine-tune YOLOv8m—F1 0.73 on validation. Look at confusion matrix—one class is almost never detected. Cause: imbalance 1:23. Solution: oversampling rare class, focal loss for objectness, augmentations (Mosaic, MixUp disabled for rare class as they "blur" it). Transfer learning is mandatory: pretrained on COCO weights reduces data requirement by 10 times. Fine-tuning on 500–2000 domain images yields a working model in 1–2 days on a single GPU.

For edge deployment: export to ONNX → TensorRT engine. YOLOv8n in TensorRT FP16 on Jetson AGX Orin gives 150+ FPS at P99 latency < 8 ms—3 times faster than ONNX Runtime without TensorRT. On server A10G: 700+ FPS for YOLOv8n in TensorRT INT8.

How Does Fine-Tuning YOLO Help in Pattern Recognition?

Suppose you need to find micro-defects on a metal surface—a task with high resolution and class imbalance. We use YOLOv8m pretrained on COCO and fine-tune on 2000 proprietary images. Apply augmentations Mosaic, MixUp, random perspective. After 200 epochs, mAP 0.5 reaches 0.93. Key techniques:

  • Focal loss for the objectness head—reduces contribution of easily classified examples.
  • Class-balanced sampling—equalizes representation of rare classes.
  • Test Time Augmentation (TTA)—increases recall by 5–7% through averaging over flips and scales.

Get a consultation on architecture selection for your task—contact us.

Segmentation: SAM, Mask R-CNN, and Instance Segmentation

SAM (Segment Anything Model) from Meta changed the approach to segmentation. SAM 2 works with video, supports object tracking across frames—for interactive object selection by point or bbox, it's the best out-of-the-box choice. For production instance segmentation without interactive prompting, Mask R-CNN or YOLOv8-seg are used. YOLOv8-seg trains like a regular detector with additional masks, convenient in the same pipelines. Semantic segmentation (each pixel is a class) uses SegFormer, DeepLabV3+. SegFormer-B5 provides a good balance of accuracy and speed for satellite imagery or medical segmentation.

Case study: cell segmentation on microscopic images. Dataset of 400 images with manual annotation. Training Mask R-CNN on ResNet-50 backbone gave IoU 0.61—poor. Problem: objects (cells) overlap; standard NMS kills overlapping predictions. Solution: switch to cellpose (specialized architecture for biomedical tasks) + soft-NMS. IoU increased to 0.79.

OCR: When Tesseract Fails

Tesseract is a starting point for simple tasks: printed text, good lighting, straight layout. As soon as there are handwritten elements, non-standard fonts, perspective distortions, or multi-column layouts, Tesseract degrades quickly.

PaddleOCR is a production-grade solution: text block detection + recognition + structural analysis. Works out of the box for 80+ languages, including Russian. Supports tables and complex document structures. TrOCR (Microsoft) is a transformer OCR with strong results on handwritten text. For Russian handwritten text, fine-tuning is needed: the base model is trained mostly on Latin script.

What to Do When Tesseract Cannot Handle Pattern Recognition on Documents?

For tasks like "extract data from invoices/contracts/passports," we use LayoutLMv3 or Donut—these models understand document layout, not just text. Integration via Hugging Face Transformers, fine-tuning on 200–500 annotated documents. Typical pipeline:

  1. Preprocessing: deskew, denoising, binarization via OpenCV.
  2. Text block detection: PaddleOCR detection or CRAFT.
  3. Recognition: PaddleOCR recognition or TrOCR.
  4. Post-processing: normalization, validation via regex or LLM for structured fields.

For documents with fixed structure, template matching + OCR by coordinates is often more reliable than an end-to-end solution.

Face Recognition: Identification and Verification

Face recognition = detection + alignment + embedding + matching. Each stage matters.

Detection: RetinaFace or InsightFace for accurate face localization and keypoints. MTCNN is older but reliable. Embedding: ArcFace (InsightFace) is state-of-the-art for face recognition embeddings. Models iresnet50/iresnet100 pretrained on MS1MV3 (5M identities). Embedding vector 512 float32, comparison by cosine similarity. Threshold tuning: decision threshold is a critical parameter. At threshold 0.6, typical FPR on LFW benchmark is 0.001, TPR is 0.985. In production, threshold must be calibrated to the real distribution: people in masks, with changed appearance, different lighting conditions. Liveness detection is mandatory: MiniFASNet—lightweight model on CPU; FaceX-Zoo contains several pretrained liveness detectors.

Video Analytics

Video is a sequence of frames plus a temporal dimension. A naive approach—detecting on every frame—is expensive.

Tracking: ByteTrack and BoT-SORT are the standard for multi-object tracking. They work on top of any detector, adding persistent IDs to objects across frames—enabling object counting, motion tracking, velocity.

Optimization: not every frame needs processing. For static scenes, detect every 5–10 frames, with tracking in between. For event detection (person entering a zone), background subtraction (OpenCV MOG2) serves as a lightweight pre-filter before neural detection. Action recognition: SlowFast, VideoMAE for action classification. Heavy models—for production use ONNX export + TensorRT or offline processing.

How to Measure Pattern Recognition Model Quality in Production?

Quality monitoring is key to MLOps. We track:

  • Prediction confidence distribution.
  • Share of low-confidence predictions (indicator of OOD data).
  • Drift of input images via feature distribution (embeddings from backbone).

A drop in average confidence from 0.87 to 0.71 over a week is an early signal of distribution shift. NVIDIA Triton Inference Server recommends tracking these metrics via Prometheus. Our certified engineers set up monitoring and guarantee SLA for inference quality.

Deployment of CV Models

For online inference, we use Triton Inference Server (NVIDIA)—production standard for serving CV models. Supports TensorRT, ONNX, PyTorch, dynamic batching, multiple instances. REST and gRPC API. We guarantee stable operation under load.

Edge deployment: ONNX Runtime on ARM/x86 CPU. TensorFlow Lite for mobile devices. OpenVINO for Intel CPU/GPU/VPU—gives 2–3× speedup on Intel hardware compared to ONNX Runtime. After deployment, we hand over the model with documentation and train personnel.

What Is Included in the Work

Stage Content Estimated Time
Analysis Technical specification, architecture selection, data evaluation 3–5 days
Labeling Image collection, annotation (up to 5000 objects) 1–3 weeks
Training Model fine-tuning, validation on test set 1–2 weeks
Optimization Export to ONNX/TensorRT/OpenVINO, testing on target hardware 1–2 weeks
Integration REST/gRPC API, integration with existing infrastructure 1–2 weeks
Deployment Deployment on server or edge device, load testing 1 week
Documentation and training Instructions, staff training, handover of code and model 3–5 days
Support Technical support for 3 months after launch

Deadlines and Cost

A prototype detector on existing data takes 1–2 weeks. Production system with optimization for target hardware takes 4–8 weeks. Full cycle including data labeling (1000–5000 images) takes 2–4 months. Cost is calculated individually for each task. Typical savings from implementing a quality control system can be significant per production line.

We have been in the market for over 5 years and completed 60+ computer vision projects. We will evaluate your project end-to-end—request a consultation to get a quote and technical proposal.