突破高置信度:高安全阈值下的实用人脸冒充攻击
Breaking High Confidence: Practical Face Impersonation under High-Security Thresholds
浏览论文内容
中文总结 AI 辅助
本文针对高安全阈值下的人脸识别系统,提出首个实用的基于分数的冒充攻击,在LFW基准上对Amazon Rekognition的冒充成功率超92%,且在多开源FRSs上表现稳健。
中文摘要 AI 辅助
人脸识别系统(FRSs)正越来越多地部署在银行应用、机场身份核验等关键现实身份认证服务中,这要求其具备严格的安全配置,因此FRSs的安全漏洞受到了广泛关注。现有研究虽已深入探索FRSs的安全性,但此前的分析主要聚焦于中等安全阈值设置,不适用于高安全约束下运行的FRSs。本文中,我们提出了首个针对高安全阈值设置下FRSs的成功冒充攻击。在多种威胁模型中,我们聚焦于一种实用且具有挑战性的场景:严格速率限制下的基于分数的冒充攻击。为精准评估此类攻击的可行性,我们提供了原则性数学分析,刻画了攻击流程各阶段的差距。我们的方法显著提升了基于分数的攻击中的冒充能力,即使在提高的决策阈值下也能生效。在LFW基准上,每个身份仅需100个置信度分数查询的预算,我们的攻击在执法场景推荐的99置信度分数阈值下,对Amazon Rekognition的冒充成功率超过92%。我们进一步观察到,在多个开源FRSs上,于类似严格的决策阈值下,该攻击均表现出一致的鲁棒性能。
英文摘要
Face recognition systems (FRSs) are increasingly deployed in critical real-world services for authentication, such as banking applications and airport identity checks, necessitating stringent security configurations. Consequently, the security vulnerabilities of FRSs have garnered significant attention. While existing studies have extensively explored FRS security, prior analyses have primarily focused on medium-security threshold settings, which are not directly applicable to FRSs operating under high-security constraints. In this paper, we propose the first successful impersonation attack against FRSs under high-security threshold settings. Among various threat models, we focus on a practical and challenging scenario: score-based impersonation attacks under strict rate limits. To precisely evaluate the feasibility of such attacks, we provide a principled mathematical analysis characterizing the gaps in each stage of the attack pipeline. Our method significantly enhances impersonation capabilities in score-based attacks, even under elevated decision thresholds. On the LFW benchmark, with a budget of only 100 confidence score queries per identity, our attack achieves an impersonation success rate exceeding 92\% against Amazon Rekognition at a confidence score threshold of 99-recommended setting for law enforcement scenarios. We further observe consistently robust performance across multiple open-source FRSs evaluated at similarly stringent decision thresholds.
发表机构
- Research Institute for Natural Sciences(自然科学研究所)
- Hanyang University(汉阳大学)
机构由 AI 辅助整理,请以论文原文为准。