Lune

USENIX Security2025顶会

Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems

Bowen Hu, Kuo Wang, Chip-Hong Chang

出版方
2025年份

摘要

Facial recognition is the most prevalent biometric modality in commercial verification and identification systems (e.g. Windows Hello and Apple FaceID), which typically operate under near-infrared (NIR) illumination. Such systems are generally considered secure on the premise that no commercial screen display can readily enable a NIR-based video presentation attack. However, this work demonstrates a critical vulnerability of NIR biometric authentication systems by a presentation attack, named Red Bleed, mounted on a widely used commercial-off-the-shelf (COTS) enterprise-grade face authentication system through a custom-built liquid crystal display (LCD) that costs less than 400 USD. Due to the scarcity of NIR video samples, it is more feasible to sneak RGB images in the visible (VIS) spectrum through, for instance, covert secret photography, photos posted on social media or screen captures during video conferencing. Besides using live captured NIR video of the target subject's face, we also propose a novel identity-preserved NIR face generative framework that combines a Variational Autoencoder (VAE) to convert VIS images into the NIR domain for this attack. In conjunction with an advanced face swapping technique, an RGB video can be transformed into a video with NIR face, enabling a more sneaky and pragmatic 2D presentation attack on NIR face biometric authentication demonstrated on a commercially available Windows Hello face authentication module. The hardware design and source code supporting our findings will be made publicly available at https://github.com following paper acceptance and the corresponding Common Vulnerabilities and Exposures (CVE) release. This vulnerability has been reported to Microsoft and the vendors of the three evaluated COTS Windows Hello face recognition modules. The reported behavior has been confirmed by the Microsoft Security Response Center (MSRC), and a CVE is scheduled for public disclosure in June 2025.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper34

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖