用普通无线电设备干扰人脸识别,暴露硬件漏洞。
Intentional Electromagnetic Interference Attacks on Facial Recognition

- 用常见无线电设备制造电磁干扰,攻击人脸识别硬件
- 测试发现主流人脸识别模型易受电磁干扰影响
- 提供带/不带干扰的图像数据集,供安全测试
现有计算机视觉攻击多在数字域进行,而生物识别领域中,针对生物传感器的物理呈现攻击占据主导地位,带来显著风险。本文揭示了生物传感器物理到数字转换链路中的关键漏洞,提出一种标准化方法,用于评估人脸识别系统对硬件攻击的鲁棒性,超越并可能补充ISO/IEC 30107标准定义的呈现攻击。具体而言,本文(a)证明仅需常用射频(RF)设备即可实施有意电磁干扰;(b)评估了当前先进的人脸识别方法对基于射频的攻击的脆弱性;(c)构建了一个包含有无电磁干扰下采集的人脸图像的数据集,作为测试现代人脸匹配器应对射频干扰的新基准。
原文摘要 · Abstract (English)
Attacks on general computer vision algorithms are often relegated to the digital domain, with the optimization performed purely in the digital world and then translated to physical mediums for implementation. In the field of biometrics, including facial recognition, physical presentation attacks targeting biometric sensors are dominant and present significant opportunity and risk. This paper highlights a critical vulnerability in the physical-to-digital pipeline of biometric sensors and provides a standardized approach for testing facial recognition system robustness against hardware attacks, going beyond and potentially complementing presentation attacks (as defined in ISO/IEC 30107 standard series). Specifically, in this work we (a) demonstrate that intentional electromagnetic interference is possible to be conducted with commonly accessible radio frequency (RF) equipment, (b) assess the robustness of state-of-the-art face recognition methods against RF-based attacks, and (c) provide a dataset composed of face images captured with and without electromagnetic interference to serve as a new benchmark for testing modern face matchers against RF-sourced interference.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。