Inverting Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models
Inverting Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models
复制标题
DOI:
10.1109/ijcb54206.2022.10007997
复制
发表时间:
2022-10
期刊:
影响因子:
--
通讯作者:
Sohaib Ahmad;Kaleel Mahmood;Benjamin Fuller
中科院分区:
文献类型:
--
作者:
Sohaib Ahmad;Kaleel Mahmood;Benjamin Fuller
Authentication systems are vulnerable to model inversion attacks where an adversary is able to approximate the inverse of a target machine learning model. Biometric models are a prime candidate for this type of attack. This is because inverting a biometric model allows the attacker to produce a realistic biometric input to spoof biometric authentication systems. One of the main constraints in conducting a successful model inversion attack is the amount of training data required. In this work, we focus on iris and facial biometric systems and propose a new technique that drastically reduces the amount of training data necessary. By leveraging the output of multiple models, we are able to conduct model inversion attacks with 1/10th the training set size of Ahmad and Fuller (IJCB 2020) for iris data and 1/1000th the training set size of Mai et al. (Pattern Analysis and Machine Intelligence 2019) for facial data. We denote our new attack technique as structured random with alignment loss.