arXiv:2509.03108cs.CV2025-09

黑客可植入隐蔽后门,让伪造人脸骗过识别系统。

Backdoor Poisoning Attack Against Face Spoofing Attack Detection Methods

  • 将伪造人脸特征嵌入真人图像,无视觉变化
  • 在公开数据集上使检测系统误判率升至90%以上
  • 揭示现有防伪系统存在被恶意攻破的隐患

人脸识别系统对环境变化和噪声具有鲁棒性,因此可能被用户照片等欺骗攻击利用。为防止此类攻击,必须在识别前判断输入图像是真实活体还是伪造图像。现有大多数防伪检测方法依赖深度学习,需大量训练数据。若恶意数据被注入部分训练集,特定伪造攻击可能被错误分类为真实活体,导致误报。本文提出一种新型后门投毒攻击方法,展示防伪检测中后门威胁的潜在风险。该方法将伪造人脸特征嵌入真实人脸图像,不产生可见视觉差异,使特定伪造攻击可绕过检测。在公开数据集上的实验表明,该方法对现有防伪检测系统构成现实威胁。

原文摘要 · Abstract (English)

Face recognition systems are robust against environmental changes and noise, and thus may be vulnerable to illegal authentication attempts using user face photos, such as spoofing attacks. To prevent such spoofing attacks, it is crucial to discriminate whether the input image is a live user image or a spoofed image prior to the face recognition process. Most existing spoofing attack detection methods utilize deep learning, which necessitates a substantial amount of training data. Consequently, if malicious data is injected into a portion of the training dataset, a specific spoofing attack may be erroneously classified as live, leading to false positives. In this paper, we propose a novel backdoor poisoning attack method to demonstrate the latent threat of backdoor poisoning within face anti-spoofing detection. The proposed method enables certain spoofing attacks to bypass detection by embedding features extracted from the spoofing attack's face image into a live face image without inducing any perceptible visual alterations. Through experiments conducted on public datasets, we demonstrate that the proposed method constitutes a realistic threat to existing spoofing attack detection systems.

安全攻防后门攻击防伪检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。