通过分析用户会话元数据,识别虚拟摄像头注入攻击。
Virtual camera detection: Catching video injection attacks in remote biometric systems
- 基于会话元数据训练机器学习模型检测虚拟摄像头。
- 实验证明能有效识别视频注入攻击,降低绕过活体检测风险。
- 适合关注远程生物识别安全的开发者和安全研究人员。
基于人脸识别的远程生物认证系统在各类网络应用中日益普及,而面部分析反欺骗(FAS)是其关键组成部分。新兴威胁中的视频注入攻击,借助深度伪造和虚拟摄像头软件等技术,对系统完整性构成严重挑战。尽管虚拟摄像头检测(VCD)显示出潜在防御能力,但现有研究对其实际部署与评估仍缺乏深入探讨。本文提出一种基于机器学习的VCD方法,重点在于其设计与验证。模型利用真实用户会话期间采集的元数据进行训练。实证结果表明,该方法能有效识别视频注入行为,显著降低恶意用户绕过FAS系统的风险。
原文摘要 · Abstract (English)
Face anti-spoofing (FAS) is a vital component of remote biometric authentication systems based on facial recognition, increasingly used across web-based applications. Among emerging threats, video injection attacks -- facilitated by technologies such as deepfakes and virtual camera software -- pose significant challenges to system integrity. While virtual camera detection (VCD) has shown potential as a countermeasure, existing literature offers limited insight into its practical implementation and evaluation. This study introduces a machine learning-based approach to VCD, with a focus on its design and validation. The model is trained on metadata collected during sessions with authentic users. Empirical results demonstrate its effectiveness in identifying video injection attempts and reducing the risk of malicious users bypassing FAS systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。