Vulnerability of State-of-the-Art Face Recognition Models to Template Inversion Attack

被引:0
|
作者
Shahreza, Hatef Otroshi [1 ,2 ]
Hahn, Vedrana Krivokuca [1 ]
Marcel, Sebastien [1 ,3 ]
机构
[1] Idiap Res Inst, Biometr Secur & Privacy Grp, CH-1920 Martigny, Switzerland
[2] Ecole Polytech Fed Lausanne EPFL, CH-1015 Lausanne, Switzerland
[3] Univ Lausanne UNIL, Sch Criminal Justice, CH-1015 Lausanne, Switzerland
基金
欧盟地平线“2020”;
关键词
Biometrics; face recognition; face reconstruction; embedding; template inversion; vulnerability evaluation; SECURITY;
D O I
10.1109/TIFS.2024.3381820
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Face recognition systems use the templates (extracted from users' face images) stored in the system's database for recognition. In a template inversion attack, the adversary gains access to the stored templates and tries to enter the system using images reconstructed from those templates. In this paper, we propose a framework to evaluate the vulnerability of face recognition systems to template inversion attacks. We build our framework upon a real-world scenario and measure the vulnerability of the system in terms of the adversary's success attack rate in entering the system using the reconstructed face images. We propose a face reconstruction network based on a new block called "enhanced deconvolution using cascaded convolution and skip connections" (shortly, DSCasConv), and train it with a multi-term loss function. We use our framework to evaluate the vulnerability of state-of-the-art face recognition models, with different network structures and loss functions (in total 31 models), on the MOBIO, LFW, and AgeDB face datasets. Our experiments show that the reconstructed face images can be used to enter the system, which threatens the system's security. Additionally, the reconstructed face images may reveal important information about each user's identity, such as race, gender, and age, and hence jeopardize the users' privacy.
引用
收藏
页码:4585 / 4600
页数:16
相关论文
共 50 条
  • [1] On the Recognition Performance of BioHashing on state-of-the-art Face Recognition models
    Shahreza, Hatef Otroshi
    Hahn, Vedrana Krivokuca
    Marcel, Sebastien
    [J]. 2021 IEEE INTERNATIONAL WORKSHOP ON INFORMATION FORENSICS AND SECURITY (WIFS), 2021, : 50 - 55
  • [2] Attacks on state-of-the-art face recognition using attentional adversarial attack generative network
    Yang, Lu
    Song, Qing
    Wu, Yingqi
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (01) : 855 - 875
  • [3] Attacks on state-of-the-art face recognition using attentional adversarial attack generative network
    Lu Yang
    Qing Song
    Yingqi Wu
    [J]. Multimedia Tools and Applications, 2021, 80 : 855 - 875
  • [4] A REVIEW ON STATE-OF-THE-ART FACE RECOGNITION APPROACHES
    Mahmood, Zahid
    Muhammad, Nazeer
    Bibi, Nargis
    Ali, Tauseef
    [J]. FRACTALS-COMPLEX GEOMETRY PATTERNS AND SCALING IN NATURE AND SOCIETY, 2017, 25 (02)
  • [5] Template Inversion Attack Using Synthetic Face Images Against Real Face Recognition Systems
    Shahreza, Hatef Otroshi
    Marcel, Sebastien
    [J]. IEEE TRANSACTIONS ON BIOMETRICS, BEHAVIOR, AND IDENTITY SCIENCE, 2024, 6 (03): : 374 - 384
  • [6] EVALUATION OF STATE-OF-THE-ART ALGORITHMS FOR REMOTE FACE RECOGNITION
    Ni, Jie
    Chellappa, Rama
    [J]. 2010 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, 2010, : 1581 - 1584
  • [7] Presentation Attack Detection for Iris Recognition: An Assessment of the State-of-the-Art
    Czajka, Adam
    Bowyer, Kevin W.
    [J]. ACM COMPUTING SURVEYS, 2018, 51 (04)
  • [8] Template Inversion Attack against Face Recognition Systems using 3D Face Reconstruction
    Shahreza, Hatef Otroshi
    Marcel, Sebastien
    [J]. 2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2023), 2023, : 19605 - 19615
  • [9] MODELS OF VISUAL WORD RECOGNITION - SAMPLING THE STATE-OF-THE-ART
    JACOBS, AM
    GRAINGER, J
    [J]. JOURNAL OF EXPERIMENTAL PSYCHOLOGY-HUMAN PERCEPTION AND PERFORMANCE, 1994, 20 (06) : 1311 - 1334
  • [10] Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition
    Sharif, Mahmood
    Bhagavatula, Sruti
    Reiter, Michael K.
    Bauer, Lujo
    [J]. CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 1528 - 1540