USENIX Security2024Top-tier venue
Biosignal Authentication Considered Harmful Today
Veena Krish, Nicola Paoletti, Milad Kazemi, Scott A. Smolka, Amir Rahmati
Abstract
User authentication systems based on cardiovascular biosignals have gained prominence in recent years, as these signals are presumed to be difficult to forge. We challenge this assumption by showing that an observer who has access to one type of cardiac data -such as a user's pulse waveform, readily obtainable from video and commercial smartwatches -can design a spoofing attack strong enough to fool authentication systems based on other cardiovascular biosignals. We present BioForge, an approach that leverages a cycle-consistent generative adversarial network to synthesize realistic physiological signals for a given user without relying on simultaneously collected supervision data. We evaluate BioForge on multiple open-access datasets and an array of verification systems, many of which can be fooled over 50% of the time in 10 or fewer attempts. Notably, we are able to fool systems that rely not just on heart rate and peak locations but also on the morphology of the waveforms. We additionally showcase how BioForge can be used to spoof authentication systems from biosignal data extracted from video clips of a target user. Our work demonstrates that authentication systems should not rely on the secrecy of cardiovascular biosignals.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Supervised Contrastive LearningPrannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna et al.NeurIPS 2020 · 7,049 citations
- The Way to my Heart is through Contrastive Learning: Remote Photoplethysmography from Unlabelled VideoJohn Gideon, Simon StentICCV 2021 · 153 citations
- CardioGAN: Attentive Generative Adversarial Network with Dual Discriminators for Synthesis of ECG from PPGPritam Sarkar, Ali EtemadAAAI 2021 · 99 citations
- Broken Hearted: How To Attack ECG BiometricsSimon Eberz, Nicola Paoletti, Marc Roeschlin, Andrea Patané et al.NDSS 2017 · 84 citations
Related papers
- TrueHeart: Continuous Authentication on Wrist-worn Wearables Using PPG-based BiometricsTianming Zhao, Yan Wang, Jian Liu, Yingying Chen et al.INFOCOM 2020 · 91 citations
- DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat RhythmsHua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie et al.ACM MM 2020 · 224 citations
- Attacking mmWave-enabled Chest Vibration Sensing via Actuator-induced MimicryXiaonan Guo, Yi Wei, Yuan Ge, Yucheng Xie et al.INFOCOM 2026
- Towards a Re-evaluation of Data Forging Attacks in PracticeMohamed Suliman, Anisa Halimi, Swanand Ravindra Kadhe, Nathalie Baracaldo et al.USENIX Security 2025
- SimGANs: Simulator-Based Generative Adversarial Networks for ECG Synthesis to Improve Deep ECG ClassificationTomer Golany, Kira Radinsky, Daniel FreedmanICML 2020 · 88 citations
