扩大范围!重新审视MasterFace模拟攻击
Casting the Net! Revisiting MasterFace Impersonation Attacks
- Hanyang University(汉阳大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文重新审视MasterFace模拟攻击,发现合法访问公共商业API可构建适配API的NET,在最多30次验证内将多个FRS的模拟成功率放大9.5倍,突破标准FMR基准。
AI中文摘要:
模拟攻击是人脸识别系统(FRS)中的一种基本安全威胁。尽管FRS的安全性受到了各种攻击向量的挑战,但在现实的对抗能力下,例如仅能进行有限次数的仅决策型身份验证尝试、无法获取系统内部知识,大多数攻击技术都会变得不可行。因此,零 effort 冒充者(以错误匹配率FMR为特征)的模拟攻击通常被视为独立的基准。几年前,基于MasterFaces的模拟攻击作为一种显著的安全威胁出现,能够在这种现实约束下突破基于FMR的基准。然而,多项后续研究讨论认为,在现代FRS中,此类攻击无法产生超过标准FMR的模拟成功率。在本文中,我们证明,即使合法访问公共商业API,攻击者也能通过MasterFaces放大模拟成功率,在构建于这些API之上的下游应用中实现远超FMR的重要模拟攻击。我们观察到,多个现实世界的FRS部署使用商业API实现,且后端服务提供商是公开披露的或可轻易推断的。因此,攻击者可以购买这些按需付费的API服务,无需对目标FRS拥有额外权限。基于这一观察,我们将MasterFaces攻击形式化为生物特征表示空间上的最大覆盖问题,将其命名为NET,并证明攻击者可以利用表示空间的几何结构构建适配API的NET。我们证明,与标准FMR预期的结果相比,我们的攻击在最多30次身份验证尝试内,可将多个开源和基于商业API的FRS的模拟成功率放大多达9.5倍。
英文摘要:
Impersonation is a fundamental security threat in face recognition systems (FRSs). While the security of FRSs has been challenged by various attack vectors, under realistic adversarial capabilities, e.g., a limited number of decision-only authentication trials and no internal system knowledge, most attack techniques become infeasible. As a result, impersonation by zero-effort impostors, characterized by false match rate (FMR), is commonly regarded as a standalone baseline. A few years ago, impersonation attacks based on MasterFaces emerged as a notable security threat that could break the barrier of the FMR-based baseline under such realistic constraints. However, they were believed not to yield impersonation above the standard FMR in modern FRSs, as discussed by multiple follow-up studies. In this paper, we demonstrate that even legitimate access to public commercial APIs allows an adversary to amplify impersonation rates through MasterFaces, resulting in a non-trivial impersonation attack beyond FMR on downstream applications built on top of these APIs. We observe that several real-world FRS deployments are implemented using commercial APIs, and that the backend service provider is publicly disclosed or trivially inferable. As a result, the adversary can purchase these pay-as-you-go API services without requiring any additional privilege over the target FRS. From this observation, we formalize the MasterFaces attack as a maximum coverage problem over the biometric representation space, which we call a NET, and show that the adversary can construct an API-tailored NET by leveraging the geometric structure of the representation space. We demonstrate that our attack amplifies the impersonation rates of several open-source and commercial API-based FRSs by up to 9.5$\times$ within at most 30 authentication trials, compared to those expected from the standard FMR.