Vulnerability of Face Recognition Systems Against Composite Face Reconstruction Attack
Rounding confidence score is considered trivial but a simple and effective countermeasure to stop gradient descent based image reconstruction attacks. However, its capability in the face of more sophisticated reconstruction attacks is an uninvestigated research area. In this paper, we prove that, the face reconstruction attacks based on composite faces can reveal the inefficiency of rounding policy as countermeasure. We assume that, the attacker takes advantage of face composite parts which helps the attacker to get access to the most important features of the face or decompose it to the independent segments. Afterwards, decomposed segments are exploited as search parameters to create a search path to reconstruct optimal face. Face composition parts enable the attacker to violate the privacy of face recognition models even with a blind search. However, we assume that, the attacker may take advantage of random search to reconstruct the target face faster. The algorithm is started with random composition of face parts as initial face and confidence score is considered as fitness value. Our experiments show that, since the rounding policy as countermeasure can't stop the random search process, current face recognition systems are extremely vulnerable against such sophisticated attacks. To address this problem, we successfully test Face Detection Score Filtering (FDSF) as a countermeasure to protect the privacy of training data against proposed attack.
Code (0)
등록된 구현이 없습니다.
Tasks
Face DetectionFace RecognitionFace ReconstructionImage ReconstructionReconstruction AttackMethods 이 논문이 사용한 방법론
Similar Papers 제목 키워드 기반
Vulnerability of 3D Face Recognition Systems to Morphing Attacks
In recent years face recognition systems have been brought to the mainstream due to development in hardware and software. Consistent efforts are being made to make them better and more secure. This has also brought devel…
Face RecognitionImage MorphingDeep Composite Face Image Attacks: Generation, Vulnerability and Detection
Face manipulation attacks have drawn the attention of biometric researchers because of their vulnerability to Face Recognition Systems (FRS). This paper proposes a novel scheme to generate Composite Face Image Attacks (C…
Face Morphing Attack DetectionFace RecognitionFace Reconstruction from Facial Templates by Learning Latent Space of a Generator Network
In this paper, we focus on the template inversion attack against face recognition systems and propose a new method to reconstruct face images from facial templates. Within a generative adversarial network (GAN)-based fra…
Controllable Evaluation and Generation of Physical Adversarial Patch on Face Recognition
Recent studies have revealed the vulnerability of face recognition models against physical adversarial patches, which raises security concerns about the deployed face recognition systems. However, it is still challenging…
3D Face ModellingFace RecognitionIs Face Recognition Safe from Realizable Attacks?
Face recognition is a popular form of biometric authentication and due to its widespread use, attacks have become more common as well. Recent studies show that Face Recognition Systems are vulnerable to attacks and can l…
Face Recognition