首次系统验证:一个后门模型即可攻破完整人脸识别系统
SoK: On the Survivability of Backdoor Attacks on Unconstrained Face Recognition Systems
- 整合多类攻击,构建端到端后门威胁链
- 20种配置下仅需1个后门模型即能破坏全系统
- 适合安全研究者与系统开发者参考防御
深度学习驱动的人脸识别系统广泛应用,带来诸多安全挑战。尽管已有研究揭示了孤立组件的后门漏洞,但对真实世界无约束流程中的后门攻击仍缺乏系统研究。本文首次对完整人脸识别系统进行系统级分析与度量,综合现有针对人脸检测器、反欺骗模块和特征提取器的监督学习后门攻击方法,揭示端到端系统级脆弱性。通过全面分析20种流水线配置与15种攻击场景,发现攻击者仅需植入一个后门模型即可破坏整个系统。最后,我们讨论此类攻击的影响,并为相关方提出最佳实践与应对策略。
原文摘要 · Abstract (English)
The widespread deployment of Deep Learning-based Face Recognition Systems raises many security concerns. While prior research has identified backdoor vulnerabilities on isolated components, Backdoor Attacks on real-world, unconstrained pipelines remain underexplored. This SoK paper presents the first comprehensive system-level analysis and measurement of the impact of Backdoor Attacks on fully-fledged Face Recognition Systems. We combine the existing Supervised Learning backdoor literature targeting face detectors, face antispoofing, and face feature extractors to demonstrate a system-level vulnerability. By analyzing 20 pipeline configurations and 15 attack scenarios in a holistic manner, we reveal that an attacker only needs a single backdoored model to compromise an entire Face Recognition System. Finally, we discuss the impact of such attacks and propose best practices and countermeasures for stakeholders.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。