Casting the Net! Revisiting MasterFace Impersonation Attacks
Seunghun Paik, Sunpill Kim, Chanwoo Hwang, Jae Hong Seo
Abstract
Impersonation is a fundamental security threat in face recognition systems (FRSs). While the security of FRSs has been challenged by various attack vectors, under realistic adversarial capabilities, e.g., a limited number of decision-only authentication trials and no internal system knowledge, most attack techniques become infeasible. As a result, impersonation by zero-effort impostors, characterized by false match rate (FMR), is commonly regarded as a standalone baseline. A few years ago, impersonation attacks based on MasterFaceswhich exploit non-uniformity in biometric distribution-emerged as a notable security threat that could break the barrier of the FMRbased baseline under such realistic constraints. However, they were believed not to yield impersonation above the standard FMR in modern FRSs, as discussed by multiple follow-up studies.
In this paper, we demonstrate that even legitimate access to public commercial APIs allows an adversary to amplify impersonation rates through MasterFaces, resulting in a non-trivial impersonation attack beyond FMR on downstream applications built on top of these APIs. We observe that several real-world FRS deployments are implemented using commercial APIs, and that the backend service provider is publicly disclosed or trivially inferable. As a result, the adversary can purchase these pay-as-you-go API services without requiring any additional privilege over the target FRS. Motivated by this observation, we formalize the MasterFaces attack as a maximum coverage problem over the biometric representation space, which we call a net, and show that the adversary can construct an API-tailored net by leveraging the geometric structure of the representation space. Through experiments, we demonstrate that our attack amplifies the impersonation rates of several open-source and commercial API-based FRSs by up to 9.5× within at most 30 authentication trials, compared to those expected from the standard FMR. Overall, we revive the MasterFaces attack as posing a potential vulnerability against real-world FRSs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 49f50e4a-b88f-4cad-98dc-1c9e7a60efa5Builds on22
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- AdaFace: Quality Adaptive Margin for Face RecognitionMinchul Kim, Anil K. Jain, Xiaoming LiuCVPR 2022 · 509 citations
- Racial Faces in the Wild: Reducing Racial Bias by Information Maximization Adaptation NetworkMei Wang, Weihong Deng, Jiani Hu, Xunqiang Tao et al.ICCV 2019 · 379 citations
- Who is Real Bob? Adversarial Attacks on Speaker Recognition SystemsGuangke Chen, Sen Chen, Lingling Fan, Xiaoning Du et al.S&P 2021 · 239 citations
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding et al.NeurIPS 2022 · 84 citations
Related papers
- Scores Tell Everything about Bob: Non-adaptive Face Reconstruction on Face Recognition SystemsSunpill Kim, Yong Kiam Tan, Bora Jeong, Soumik Mondal et al.S&P 2024 · 11 citations
- Am I a Real or Fake Celebrity? Evaluating Face Recognition and Verification APIs under Deepfake Impersonation AttackShahroz Tariq, Sowon Jeon, Simon S. WooWWW 2022 · 33 citations
- UniID: Spoofing Face Authentication System by Universal IdentityZhihao Wu, Yushi Cheng, Shibo Zhang, Xiaoyu Ji et al.NDSS 2024
- Non-Adaptive Adversarial Face GenerationSunpill Kim, Seunghun Paik, Chanwoo Hwang, Minsu Kim et al.NeurIPS 2025 · 5 citations
- On the Resilience of Biometric Authentication Systems against Random InputsBenjamin Zi Hao Zhao, Hassan Jameel Asghar, Mohamed Ali KâafarNDSS 2020
