Inverting Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models

Inverting Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models
复制标题

DOI:
10.1109/ijcb54206.2022.10007997
复制
发表时间:
2022-10
期刊:
2022 IEEE International Joint Conference on Biometrics (IJCB)
影响因子:
--
通讯作者:
Sohaib Ahmad;Kaleel Mahmood;Benjamin Fuller
Sohaib Ahmad;Kaleel Mahmood;Benjamin Fuller
中科院分区:
其他
文献类型:
--
作者:
Sohaib Ahmad;Kaleel Mahmood;Benjamin Fuller

文献摘要

被引文献

相似文献

认证系统容易受到模型反演攻击,其中对手能够近似目标机器学习模型的逆。生物识别模型是这种类型攻击的主要候选者。这是因为反转生物特征模型允许攻击者产生真实的生物特征输入来欺骗生物特征认证系统。进行成功的模型反演攻击的主要限制之一是所需的训练数据量。在这项工作中,我们专注于虹膜和面部生物识别系统,并提出了一种新的技术,大大减少了必要的训练数据量。通过利用多个模型的输出,我们能够以Ahmad和Fuller(IJCB 2020)的虹膜数据训练集大小的1/10和Mai等人(Pattern Analysis and Machine Intelligence 2019)的面部数据训练集大小的1/1000进行模型反转攻击。我们表示我们的新的攻击技术与对齐损失的结构随机。
Authentication systems are vulnerable to model inversion attacks where an adversary is able to approximate the inverse of a target machine learning model. Biometric models are a prime candidate for this type of attack. This is because inverting a biometric model allows the attacker to produce a realistic biometric input to spoof biometric authentication systems. One of the main constraints in conducting a successful model inversion attack is the amount of training data required. In this work, we focus on iris and facial biometric systems and propose a new technique that drastically reduces the amount of training data necessary. By leveraging the output of multiple models, we are able to conduct model inversion attacks with 1/10th the training set size of Ahmad and Fuller (IJCB 2020) for iris data and 1/1000th the training set size of Mai et al. (Pattern Analysis and Machine Intelligence 2019) for facial data. We denote our new attack technique as structured random with alignment loss.