Casting the Net! Revisiting MasterFace Impersonation Attacks
Seunghun Paik, Sunpill Kim, Chanwoo Hwang, Jae Hong Seo
摘要
Impersonation is a fundamental security threat in face recognition systems (FRSs). While the security of FRSs has been challenged by various attack vectors, under realistic adversarial capabilities, e.g., a limited number of decision-only authentication trials and no internal system knowledge, most attack techniques become infeasible. As a result, impersonation by zero-effort impostors, characterized by false match rate (FMR), is commonly regarded as a standalone baseline. A few years ago, impersonation attacks based on MasterFaceswhich exploit non-uniformity in biometric distribution-emerged as a notable security threat that could break the barrier of the FMRbased baseline under such realistic constraints. However, they were believed not to yield impersonation above the standard FMR in modern FRSs, as discussed by multiple follow-up studies.
In this paper, we demonstrate that even legitimate access to public commercial APIs allows an adversary to amplify impersonation rates through MasterFaces, resulting in a non-trivial impersonation attack beyond FMR on downstream applications built on top of these APIs. We observe that several real-world FRS deployments are implemented using commercial APIs, and that the backend service provider is publicly disclosed or trivially inferable. As a result, the adversary can purchase these pay-as-you-go API services without requiring any additional privilege over the target FRS. Motivated by this observation, we formalize the MasterFaces attack as a maximum coverage problem over the biometric representation space, which we call a net, and show that the adversary can construct an API-tailored net by leveraging the geometric structure of the representation space. Through experiments, we demonstrate that our attack amplifies the impersonation rates of several open-source and commercial API-based FRSs by up to 9.5× within at most 30 authentication trials, compared to those expected from the standard FMR. Overall, we revive the MasterFaces attack as posing a potential vulnerability against real-world FRSs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper22
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- AdaFace: Quality Adaptive Margin for Face RecognitionMinchul Kim, Anil K. Jain, Xiaoming LiuCVPR 2022 · 被引用 509 次
- Racial Faces in the Wild: Reducing Racial Bias by Information Maximization Adaptation NetworkMei Wang, Weihong Deng, Jiani Hu, Xunqiang Tao 等ICCV 2019 · 被引用 379 次
- Who is Real Bob? Adversarial Attacks on Speaker Recognition SystemsGuangke Chen, Sen Chen, Lingling Fan, Xiaoning Du 等S&P 2021 · 被引用 239 次
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding 等NeurIPS 2022 · 被引用 84 次
相关 Paper
- Scores Tell Everything about Bob: Non-adaptive Face Reconstruction on Face Recognition SystemsSunpill Kim, Yong Kiam Tan, Bora Jeong, Soumik Mondal 等S&P 2024 · 被引用 11 次
- Am I a Real or Fake Celebrity? Evaluating Face Recognition and Verification APIs under Deepfake Impersonation AttackShahroz Tariq, Sowon Jeon, Simon S. WooWWW 2022 · 被引用 33 次
- UniID: Spoofing Face Authentication System by Universal IdentityZhihao Wu, Yushi Cheng, Shibo Zhang, Xiaoyu Ji 等NDSS 2024
- Non-Adaptive Adversarial Face GenerationSunpill Kim, Seunghun Paik, Chanwoo Hwang, Minsu Kim 等NeurIPS 2025 · 被引用 5 次
- On the Resilience of Biometric Authentication Systems against Random InputsBenjamin Zi Hao Zhao, Hassan Jameel Asghar, Mohamed Ali KâafarNDSS 2020
