Benchmarking CLIP for Zero-Shot Face and Periocular Gender Estimation
Authors: Fernando Alonso-Fernandez, Kevin Hernandez-Diaz, Jose Maria Buades, Josef Bigun
Organizations: School of Information Technology, Halmstad University, Sweden · Computer Graphics and Vision and AI Group, University of Balearic Islands, Spain
We investigate CLIP for zero-shot gender estimation from full-face and periocular images. Three CLIP backbones are evaluated on 11,299 frontal images from Adience using image-text similarity with male/female prompts, achieving 95.54% full-face accuracy without task-specific training. For periocular, zero-shot predictions are strongly biased towards males, primarily due to a misaligned decision boundary. Threshold alignment substantially reduces this bias, reaching 85.29% accuracy. Linear SVMs trained on CLIP features provide only marginal gains, with a best periocular accuracy of 86.17%, approximately 2.8% above previous Adience results in the literature. Nevertheless, the gap with full-face performance confirms the greater difficulty of periocular gender estimation
Figures & tables
Fig. 1: Top left: CLIP model architecture (from [ 1 ] ). Top-right and bottom-left: our adaptation for face/periocular gender estimation. Bottom right: images from the Adience database (from [ 2 ] ).
Image encoder
Text encoder
Input
Input
Para-
Vector
Para-
Vector
Model
size
patches
Layers
meters
Size
Layers
meters
size
ViT-B/16
224 × 224
16 × 16
107
86.2M
512
104
63.4M
512
ViT-L/14
224 × 224
14 × 14
203
304M
768
104
123.7M
768
ResNet-50
384 × 384
-
437
167.4M
768
104
123.7M
768
TABLE I: CLIP models evaluated in this paper.
#
Face
Periocular
1
a face photograph of a man/woman
a photograph of a male/female eye
2
a face image of a man/woman
an image of a male/female eye
3
a photograph of a man/woman
an eye image of a man/woman
4
a photograph of a male/female person
an ocular image of a man/woman
5
a photograph of a male/female human face
an ocular image of a male/female eye
6
a portrait photo of a man/woman
a photograph of a male/female person’s eye
TABLE II: Prompts employed for face/periocular gender classification.
Fig. 2: Zero-shot face/periocular gender estimation accuracy per prompt on the Adience database for different CLIP backbones. The dots indicate the mean accuracy over the five cross-validation test folds, while error bars represent one standard deviation.
Fig. 3: Zero-shot face/periocular gender estimation accuracy on the Adience database for different CLIP backbones and downsampling values (mean accuracy over the five cross-validation test folds). Results correspond to the average encoding of all prompts.
Fig. 4: Histograms of zero-shot face/periocular scores on the test folds of the Adience database. Results correspond to the average encoding of all prompts.
Fig. 5: Face/periocular gender estimation accuracy per prompt after embeddings alignment on the Adience database for different CLIP backbones. The dots indicate the mean accuracy over the five cross-validation test folds, while error bars represent one standard deviation.
clipViTB16
FACE
PERIOCULAR
Features
Male
Female
Both
Male
Female
Both
sim (zero shot)
95.11 ± 1.19
93.1 ± 2.6
94.06 ± 1.32
97.7 ± 0.87
49.76 ± 1.21
72.36 ± 1.61
sim (aligned)
93.76 ± 2.53
93.99 ± 2.63
93.95 ± 1.28
81.59 ± 6.96
77.75 ± 2.02
79.66 ± 3.48
sim + SVM
94.37 ± 1.87
94 ± 2
94.21 ± 1.37
79.55 ± 5.59
80.12 ± 2.36
79.9 ± 3.35
I + SVM
94.13 ± 1.84
93.83 ± 2.17
94.01 ± 1.41
76.67 ± 4.55
82.69 ± 2.91
79.9 ± 3.21
TABLE III: Comparative summary of face/periocular gender classification on the Adience database with the different methods evaluated in this paper. Bold indicates the best accuracy per column.
FACE
Ref
Features
Male
Female
Both
this paper:
clipViTB16
95.11 ± 1.19
93.1 ± 2.6
94.06 ± 1.32
sim zero shot
clipViTL14
97.55 ± 1
93.71 ± 2.2
95.54 ± 1.52
clipR50
94.85 ± 2.01
89.71 ± 2.6
92.17 ± 1.28
this paper:
clipViTB16
93.76 ± 2.53
93.99 ± 2.63
93.95 ± 1.28
sim aligned
clipViTL14
95.58 ± 2.05
96.08 ± 1.48
95.87 ± 1.58
TABLE IV: Summary of the best reported accuracy of the experiments of this paper. The SVM combinations shown are those with the best overall accuracy in Table III . The table also includes results of recent works using the Adience database. Different works may not employ the same number of images per fold, so results may not be completely comparable.
Adversarial attacks pose a challenge to the reliability of deep learning models, motivating effective detection methods. Existing techniques often rely on attack-specific assumptions, access to adversarial samples, or knowledge of the underlying classifier (white-box). We propose A4D Attack- and Architecture-Agnostic Adversarial Detector, a completely black-box, zero-shot adversarial attack detection framework that utilizes prompt-based similarity scores derived from CLIP. To the best of our knowledge this is the first attempt to utilize CLIP for such a task. The method is based on two key observations: (i) CLIP is sensitive even to small imperceptible non-semantic perturbations; (ii) The shift in CLIP embedding space is not arbitrary and can be used as a robust attack indicator. Experiments across multiple attacks, datasets and classifiers validate that A4D achieves SOTA detection results in the attack-agnostic and classifier-agnostic setting.
Hodaya Krakover, Meir Yossef Levi, Eyal Gofer +1
Technion - Israel Institute of Technology, Haifa, Israel
Reducing the modality gap between image and text representations in CLIP is widely expected to improve cross-modal alignment and downstream performance. However, a smaller average image-text gap does not necessarily lead to consistent accuracy gains. We analyze this mismatch from the perspective of the decision structure in zero-shot classification, i.e. selecting the most similar class-text prototype for an input image. Zero-shot accuracy depends not only on average image--text alignment, but also on class-wise decision margins. Using Linear correction as an analytically tractable case, we show that modality gap correction can alter the relative decision structure among classes and cause predictions to concentrate on a small subset of classes. We refer to this output-space failure mode as prediction-level hubness. Furthermore, experiments across multiple datasets show that accuracy degradation under gap correction is consistently associated with increased prediction concentration, both for Linear correction and for learning-based correction methods. This provides a systematic explanation of why modality gap reduction does not consistently improve CLIP zero-shot accuracy from the perspective of downstream decision structure. Our results suggest that gap correction should be evaluated not only by average alignment, but also by its impact on downstream prediction structure.
Contrastive language-audio pretraining (CLAP) enables zero-shot audio classification, but standard inference classifies each clip in isolation and ignores the structure of the unlabeled test set. We present the first systematic study of TransCLIP-style transductive inference for CLAP: a text-anchored spherical Gaussian-mixture EM that refines zero-shot posteriors using the audio-embedding statistics of the test batch, with no labels, no gradients, and negligible compute (about 15 ms on one CPU core for 2,000 clips). Across ESC-50, UrbanSound8K, and VocalSound, this consistently improves top-1 accuracy by +4.6 to +9.2 points over the zero-shot baseline (e.g., 89.1 -> 94.8% on ESC-50, 73.8 -> 81.8% on UrbanSound8K). We further show that the gain (i) is governed by a simple operating boundary -- roughly 2.5 test samples per class per batch are required, with diminishing returns beyond ~5; (ii) is complementary to entropy-guided prompt weighting, with the combination reaching 96.2% on ESC-50; and (iii) attenuates but remains positive under long-tailed batches (+4.9 -> +3.1 points at a 20:1 imbalance), which we report as an explicit limitation. We also document a negative result: on TUT Urban Acoustic Scenes 2018, where zero-shot CLAP is near chance, transduction has no signal to amplify.