神经生物标志物识别系统的对抗性脆弱性
Adversarial Vulnerabilities of Neural Biomarker Identification Systems
浏览论文内容
中文总结 AI 辅助
本文针对脑电图生物识别系统,开发了无需知晓系统的自适应攻击算法,测试6个公开数据集发现不同神经特征方法脆弱性差异大,记录条件影响欺骗攻击脆弱性,还给出改进建议。
中文摘要 AI 辅助
人们对将脑电图(EEG)信号用作生物识别凭证的兴趣日益浓厚,但迄今为止,针对这类生物识别技术的可靠性和安全性的研究甚少。先前的对抗性测试主要聚焦于深度学习分类器,并假设攻击者可完全访问该分类器模型,这使得其他更受欢迎的神经特征方法类别,以及攻击者仅能获取分类器黑盒访问权限这一更现实的情况未得到研究。在本文中,我们开发了一系列自适应攻击算法,这些算法通过对窃取的脑电图记录进行针对性修改来欺骗认证系统,且无需了解认证系统本身。我们在涵盖三种记录条件(对视觉刺激作出反应、想象手部动作以及静息状态)的6个公开数据集上进行测试,结果显示不同的特征方法对对抗性攻击的脆弱程度存在显著差异。我们表明,欺骗攻击的脆弱性受记录条件的影响极大,且差异取决于记录时的任务。最后,我们基于对抗性测试的结果,为改进神经特征生物识别技术提供了建议。
英文摘要
There is growing interest in the proposed use of EEG signals as biometric credentials, but thus far there has been little research on the reliability and security of such biometrics. Prior adversarial tests have focused on deep-learning classifiers and assumed attackers have full access to the classifier model. This has left unexamined other, more popular categories of neural signature methods as well as the more realistic case of an adversary having only black-box access to a classifier. In this paper we develop a collection of adaptive attack algorithms which learn to fool an authentication system via targeted alterations of stolen EEG recordings, without requiring any knowledge of the authentication system itself. Tested on 6 public datasets spanning three recording conditions (reacting to visual stimuli, imagining hand movements, and resting), it reveals that different signaturing approaches vary significantly in their degrees of vulnerability to adversarial attacks. We show that vulnerability to spoofing attack is greatly impacted by the recording conditions, with significant variation depending on task at time of recording. Finally, we provide recommendations for improving neural signature biometrics based on the results of our adversarial testing.
发表机构
- Cerberus Neurosecurity Research Institute (CNRI)(塞伯里斯神经安全研究所)
- University of Luxembourg(卢森堡大学)
- Cognitive Security Institute(认知安全研究所)
机构由 AI 辅助整理,请以论文原文为准。