USENIX Security2025Top-tier venue
Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems
Bowen Hu, Kuo Wang, Chip-Hong Chang
Abstract
Facial recognition is the most prevalent biometric modality in commercial verification and identification systems (e.g. Windows Hello and Apple FaceID), which typically operate under near-infrared (NIR) illumination. Such systems are generally considered secure on the premise that no commercial screen display can readily enable a NIR-based video presentation attack. However, this work demonstrates a critical vulnerability of NIR biometric authentication systems by a presentation attack, named Red Bleed, mounted on a widely used commercial-off-the-shelf (COTS) enterprise-grade face authentication system through a custom-built liquid crystal display (LCD) that costs less than 400 USD. Due to the scarcity of NIR video samples, it is more feasible to sneak RGB images in the visible (VIS) spectrum through, for instance, covert secret photography, photos posted on social media or screen captures during video conferencing. Besides using live captured NIR video of the target subject's face, we also propose a novel identity-preserved NIR face generative framework that combines a Variational Autoencoder (VAE) to convert VIS images into the NIR domain for this attack. In conjunction with an advanced face swapping technique, an RGB video can be transformed into a video with NIR face, enabling a more sneaky and pragmatic 2D presentation attack on NIR face biometric authentication demonstrated on a commercially available Windows Hello face authentication module. The hardware design and source code supporting our findings will be made publicly available at https://github.com following paper acceptance and the corresponding Common Vulnerabilities and Exposures (CVE) release. This vulnerability has been reported to Microsoft and the vendors of the three evaluated COTS Windows Hello face recognition modules. The reported behavior has been confirmed by the Microsoft Security Response Center (MSRC), and a CVE is scheduled for public disclosure in June 2025.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1969e5ac-1c0e-41fb-9a4d-3cdea34c6fd2Builds on34
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
Related papers
- Spoofing Real-world Face Authentication Systems through Optical SynthesisYueli Yan, Zhice YangS&P 2023
- The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face RecognitionYe Wang, Zeyan Liu, Bo Luo, Rongqing Hui et al.CCS 2024 · 2 citations
- Physically-Based Face Rendering for NIR-VIS Face RecognitionYunqi Miao, Alexandros Lattas, Jiankang Deng, Jungong Han et al.NeurIPS 2022 · 11 citations
- Virtual U: Defeating Face Liveness Detection by Building Virtual Models from Your Public PhotosYi Xu, True Price, Jan-Michael Frahm, Fabian MonroseUSENIX Security 2016 · 94 citations
- Am I a Real or Fake Celebrity? Evaluating Face Recognition and Verification APIs under Deepfake Impersonation AttackShahroz Tariq, Sowon Jeon, Simon S. WooWWW 2022 · 33 citations
