paper-with-me

Papers

Multiple-Identity Image Attacks Against Face-based Identity Verification

2019-06-20 · Jerone T. A. Andrews, Thomas Tanay, Lewis D. Griffin

Facial verification systems are vulnerable to poisoning attacks that make use of multiple-identity images (MIIs)---face images stored in a database that resemble multiple persons, such that novel images of any of the constituent persons are verified as matching the identity of the MII. Research on this mode of attack has focused on defence by detection, with no explanation as to why the vulnerability exists. New quantitative results are presented that support an explanation in terms of the geometry of the representations spaces used by the verification systems. In the spherical geometry of those spaces, the angular distance distributions of matching and non-matching pairs of face representations are only modestly separated, approximately centred at 90 and 40-60 degrees, respectively. This is sufficient for open-set verification on normal data but provides an opportunity for MII attacks. Our analysis considers ideal MII algorithms, demonstrating that, if realisable, they would deliver faces roughly 45 degrees from their constituent faces, thus classed as matching them. We study the performance of three methods for MII generation---gallery search, image space morphing, and representation space inversion---and show that the latter two realise the ideal well enough to produce effective attacks, while the former could succeed but only with an implausibly large gallery to search. Gallery search and inversion MIIs depend on having access to a facial comparator, for optimisation, but our results show that these attacks can still be effective when attacking disparate comparators, thus securing a deployed comparator is an insufficient defence.

📄 PDF Abstract BibTeX arXiv:1906.08507

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

MIPGAN -- Generating Strong and High Quality Morphing Attacks Using Identity Prior Driven GAN

2020-09-03 · Haoyu Zhang, Sushma Venkatesh, Raghavendra Ramachandra, Kiran Raja 외

Face morphing attacks target to circumvent Face Recognition Systems (FRS) by employing face images derived from multiple data subjects (e.g., accomplices and malicious actors). Morphed images can be verified against cont…

Face GenerationFace RecognitionGenerative Adversarial NetworkMORPH

Universal Adversarial Spoofing Attacks against Face Recognition

2021-10-02 · Takuma Amada, Seng Pei Liew, Kazuya Kakizaki, Toshinori Araki

We assess the vulnerabilities of deep face recognition systems for images that falsify/spoof multiple identities simultaneously. We demonstrate that, by manipulating the deep feature representation extracted from a face …

Face RecognitionFace Verification

Towards Assessing and Characterizing the Semantic Robustness of Face Recognition

2022-02-10 · Juan C. Pérez, Motasem Alfarra, Ali Thabet, Pablo Arbeláez 외

Deep Neural Networks (DNNs) lack robustness against imperceptible perturbations to their input. Face Recognition Models (FRMs) based on DNNs inherit this vulnerability. We propose a methodology for assessing and characte…

Face Recognition

Arc2Morph: Identity-Preserving Facial Morphing with Arc2Face

2026-02-18 · Nicolò Di Domenico, Annalisa Franco, Matteo Ferrara, Davide Maltoni arxiv

Face morphing attacks are widely recognized as one of the most challenging threats to face recognition systems used in electronic identity documents. These attacks exploit a critical vulnerability in passport enrollment …

Face Recognition

TetraLoss: Improving the Robustness of Face Recognition against Morphing Attacks

2024-01-21 · Mathias Ibsen, Lázaro J. González-Soler, Christian Rathgeb, Christoph Busch

Face recognition systems are widely deployed in high-security applications such as for biometric verification at border controls. Despite their high accuracy on pristine data, it is well-known that digital manipulations,…

Face Recognition