利用公开商业API构建面部伪装,攻击率提升9.5倍。
Casting the Net! Revisiting MasterFace Impersonation Attacks

- 通过分析生物特征空间几何结构,定制化生成伪装样本
- 仅30次尝试即使攻击率提升至标准误识率的9.5倍
- 适用于依赖商用API的现实人脸识别系统
面部识别系统面临身份冒充的安全威胁。在仅有有限次数的仅决策认证尝试且无系统内部知识的现实攻击条件下,多数攻击方法不可行,因此以误识率(FMR)为基准的零成本冒充被视为基础防线。此前基于MasterFace的冒充攻击被认为无法突破此基准。本文证明,仅需合法访问公开商业API,攻击者即可通过MasterFace放大冒充成功率,在下游应用中实现显著超越FMR的攻击效果。我们观察到多个真实部署的人脸识别系统使用公开商业API,且后端服务提供商可被公开获取或轻易推断。攻击者可无需额外权限购买此类按需计费的API服务。基于此,我们将MasterFace攻击形式化为生物特征空间上的最大覆盖问题,称为NET,并展示攻击者可利用表示空间的几何结构构造针对API的定制化NET。实验表明,该攻击使多个开源及商用API基人脸识别系统的冒充率最高提升9.5倍,且仅需最多30次认证尝试。
原文摘要 · Abstract (English)
Impersonation is a fundamental security threat in face recognition systems (FRSs). While the security of FRSs has been challenged by various attack vectors, under realistic adversarial capabilities, e.g., a limited number of decision-only authentication trials and no internal system knowledge, most attack techniques become infeasible. As a result, impersonation by zero-effort impostors, characterized by false match rate (FMR), is commonly regarded as a standalone baseline. A few years ago, impersonation attacks based on MasterFaces emerged as a notable security threat that could break the barrier of the FMR-based baseline under such realistic constraints. However, they were believed not to yield impersonation above the standard FMR in modern FRSs, as discussed by multiple follow-up studies. In this paper, we demonstrate that even legitimate access to public commercial APIs allows an adversary to amplify impersonation rates through MasterFaces, resulting in a non-trivial impersonation attack beyond FMR on downstream applications built on top of these APIs. We observe that several real-world FRS deployments are implemented using commercial APIs, and that the backend service provider is publicly disclosed or trivially inferable. As a result, the adversary can purchase these pay-as-you-go API services without requiring any additional privilege over the target FRS. From this observation, we formalize the MasterFaces attack as a maximum coverage problem over the biometric representation space, which we call a NET, and show that the adversary can construct an API-tailored NET by leveraging the geometric structure of the representation space. We demonstrate that our attack amplifies the impersonation rates of several open-source and commercial API-based FRSs by up to 9.5$\times$ within at most 30 authentication trials, compared to those expected from the standard FMR.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。