突破高安全阈值限制,实现高效人脸伪造攻击
Breaking High Confidence: Practical Face Impersonation under High-Security Thresholds

- 基于分数的攻击策略,在严格速率限制下精准操纵识别结果
- 仅用100次查询即在LFW上达成92%以上伪造成功率
- 适用于高安全场景下的真实攻击评估,适合安全研究者参考
人脸识别系统(FRS)被广泛应用于银行和机场等关键场景的身份认证,需配置高安全阈值。现有研究多聚焦中等安全设置,难以适配高安全环境。本文首次实现针对高安全阈值设置下的有效伪造攻击。我们聚焦于实际且挑战性强的分数驱动型攻击,受严格速率限制。通过数学分析刻画攻击链各阶段的差距,显著提升分数攻击的伪造能力。在LFW基准上,每身份仅100次置信度查询,即可在亚马逊Rekognition 99%阈值(执法推荐设置)下实现超过92%的伪造成功率。在多个开源FRS上也表现出一致稳健性能,验证了攻击在严苛条件下的可行性。
原文摘要 · Abstract (English)
Face recognition systems (FRSs) are increasingly deployed in critical real-world services for authentication, such as banking applications and airport identity checks, necessitating stringent security configurations. Consequently, the security vulnerabilities of FRSs have garnered significant attention. While existing studies have extensively explored FRS security, prior analyses have primarily focused on medium-security threshold settings, which are not directly applicable to FRSs operating under high-security constraints. In this paper, we propose the first successful impersonation attack against FRSs under high-security threshold settings. Among various threat models, we focus on a practical and challenging scenario: score-based impersonation attacks under strict rate limits. To precisely evaluate the feasibility of such attacks, we provide a principled mathematical analysis characterizing the gaps in each stage of the attack pipeline. Our method significantly enhances impersonation capabilities in score-based attacks, even under elevated decision thresholds. On the LFW benchmark, with a budget of only 100 confidence score queries per identity, our attack achieves an impersonation success rate exceeding 92\% against Amazon Rekognition at a confidence score threshold of 99-recommended setting for law enforcement scenarios. We further observe consistently robust performance across multiple open-source FRSs evaluated at similarly stringent decision thresholds.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。