提出新型模糊提取器,有效防御人脸模型反演攻击。
Model Inversion meets Cryptographic Fuzzy Extractors
- 将密码学模糊提取器引入机器学习隐私保护,抵御反演攻击。
- 发现现有方案安全弱,实测可高成功率还原原始人脸。
- 新方案兼顾性能、安全与精度,适合实际人脸认证系统。
模型反演攻击对依赖机器学习的隐私敏感应用构成挑战。例如,人脸识别系统使用现代机器学习模型从用户人脸图像生成嵌入向量并存储。一旦泄露,反演攻击可准确重建用户面部。模糊提取器(FE)是一种密码学原语,具备防御模型反演攻击的特性,提供无需重训练模型的攻击无关安全性。迄今为止,尚未对适用于现代基于机器学习的人脸识别系统中容忍ℓ₂噪声的ℓ₂-FE方案进行系统性密码分析。本文首次深入分析现有ℓ₂-FE方案,发现其安全性较弱,并展示了端到端的反演攻击,能以高成功率恢复受保护的原始人脸。随后,我们提出一种简单但全新的候选方案,并形式化证明其安全性。该构造是首个在实际运行时间、更强安全性与可用准确性之间取得平衡的设计,适用于主流机器学习人脸认证系统。
原文摘要 · Abstract (English)
Model inversion attacks pose an open challenge to privacy-sensitive applications that use machine learning (ML) models. For example, face authentication systems use modern ML models to compute embedding vectors from face images of the enrolled users and store them. If leaked, inversion attacks can accurately reconstruct user faces from the leaked vectors. A fuzzy extractor (FE) is a cryptographic primitive with properties that can help defend against model inversion, offering attack-agnostic security without requiring any re-training of the ML model it protects. To date, no systematic cryptanalysis of existing FE schemes that tolerate $\ell_2$ noise, as needed in modern ML-based face recognition systems, has been conducted. We perform the first in-depth security analysis of existing $\ell_2$-FE schemes showing that they offer weak security. We also show end-to-end inversion attacks that achieve high success rates in recovering original faces that are meant to be protected by FE schemes. We then offer a simple but new candidate scheme and prove its security formally. Our construction offers the first design point that offers practical runtime, stronger security, and usable accuracy for use in commodity ML-based face authentication.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。