USENIX Security2016Top-tier venue
Virtual U: Defeating Face Liveness Detection by Building Virtual Models from Your Public Photos
Yi Xu, True Price, Jan-Michael Frahm, Fabian Monrose
Abstract
In this paper, we introduce a novel approach to bypass modern face authentication systems. More specifically, by leveraging a handful of pictures of the target user taken from social media, we show how to create realistic, textured, 3D facial models that undermine the security of widely used face authentication solutions. Our framework makes use of virtual reality (VR) systems, incorporating along the way the ability to perform animations (e.g., raising an eyebrow or smiling) of the facial model, in order to trick liveness detectors into believing that the 3D model is a real human face. The synthetic face of the user is displayed on the screen of the VR device, and as the device rotates and translates in the real world, the 3D face moves accordingly. To an observing face authentication system, the depth and motion cues of the display match what would be expected for a human face.
We argue that such VR-based spoofing attacks constitute a fundamentally new class of attacks that point to a serious weaknesses in camera-based authentication systems: Unless they incorporate other sources of verifiable data, systems relying on color image data and camera motion are prone to attacks via virtual realism. To demonstrate the practical nature of this threat, we conduct thorough experiments using an end-to-end implementation of our approach and show how it undermines the security of several face authentication solutions that include both motion-based and liveness detectors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 44c32144-2fbe-45d1-b194-fb243df3a1c2Cited by top-tier papers10
- Face Flashing: a Secure Liveness Detection Protocol based on Light ReflectionsDi Tang, Zhe Zhou, Yinqian Zhang, Kehuan ZhangNDSS 2018 · 78 citations
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- rtCaptcha: A Real-Time CAPTCHA Based Liveness Detection SystemErkam Uzun, Simon Pak Ho Chung, Irfan Essa, Wenke LeeNDSS 2018 · 60 citations
- User Authentication via Electrical Muscle StimulationYuxin Chen, Zhuolin Yang, Ruben Abbou, Pedro Lopes et al.CHI 2021 · 35 citations
- Adversarial Privacy-preserving FilterJiaming Zhang, Jitao Sang, Xian Zhao, Xiaowen Huang et al.ACM MM 2020 · 35 citations
Related papers
- DepthFake: Spoofing 3D Face Authentication with a 2D PhotoZhihao Wu, Yushi Cheng, Jiahui Yang, Xiaoyu Ji et al.S&P 2023
- VVSec: Securing Volumetric Video Streaming via Benign Use of Adversarial PerturbationZhongze Tang, Xianglong Feng, Yi Xie, Huy Phan et al.ACM MM 2020 · 16 citations
- Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake EraChangjiang Li, Li Wang, Shouling Ji, Xuhong Zhang et al.USENIX Security 2022
- SAFARI: Speech-Associated Facial Authentication for AR/VR Settings via Robust VIbration SignaturesTianfang Zhang, Qiufan Ji, Zhengkun Ye, Md Mojibur Rahman Redoy Akanda et al.CCS 2024 · 8 citations
- AFace: Range-flexible Anti-spoofing Face Authentication via Smartphone Acoustic SensingZhaopeng Xu, Tong Liu, Ruobing Jiang, Pengfei Hu et al.UbiComp 2024 · 24 citations
