Analysis of Master Vein Attacks on Finger Vein Recognition Systems

Analysis of Master Vein Attacks on Finger Vein Recognition Systems
复制标题

DOI:
10.1109/wacv56688.2023.00194
复制
发表时间:
2022-10
期刊:
2023 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV)
影响因子:
--
通讯作者:
H. Nguyen;Trung-Nghia Le;J. Yamagishi;I. Echizen
H. Nguyen;Trung-Nghia Le;J. Yamagishi;I. Echizen
中科院分区:
其他
文献类型:
--
作者:
H. Nguyen;Trung-Nghia Le;J. Yamagishi;I. Echizen

文献摘要

相似文献

手指静脉识别(FVR)系统已经在商业上用于客户验证,特别是在ATM中。因此,必须测量它们对各种攻击方法的鲁棒性,特别是当使用手工制作的FVR系统而没有任何对策方法时。在本文中,我们是文献中第一个介绍主静脉攻击的人,在这种攻击中,我们制作了一个静脉外观的图像,以便它可以通过FVR系统与尽可能多的身份进行错误匹配。我们提出了两种方法来生成主静脉用于攻击这些系统。第一种方法使用了隐变量进化算法的自适应算法,并提出了生成模型(β-VAE和WGAN-GP模型的多阶段组合)。第二种使用对抗性机器学习攻击方法来攻击基于CNN的强代理识别系统。这两种方法可以很容易地结合起来,以提高他们的攻击能力。实验结果表明,所提出的方法单独和一起实现的错误接受率高达73.29%和88.79%,分别对三浦的手工制作的FVR系统。我们还指出,Miura的系统很容易受到WGAN-GP模型生成的非静脉样本的影响,错误接受率高达94.21%。研究结果对此类系统的鲁棒性提出了警告,并建议应将主静脉攻击视为一项重要的安全措施。
Finger vein recognition (FVR) systems have been commercially used, especially in ATMs, for customer verification. Thus, it is essential to measure their robustness against various attack methods, especially when a handcrafted FVR system is used without any countermeasure methods. In this paper, we are the first in the literature to introduce master vein attacks in which we craft a vein-looking image so that it can falsely match with as many identities as possible by the FVR systems. We present two methods for generating master veins for use in attacking these systems. The first uses an adaptation of the latent variable evolution algorithm with a proposed generative model (a multi-stage combination of β-VAE and WGAN-GP models). The second uses an adversarial machine learning attack method to attack a strong surrogate CNN-based recognition system. The two methods can be easily combined to boost their attack ability. Experimental results demonstrated that the proposed methods alone and together achieved false acceptance rates up to 73.29% and 88.79%, respectively, against Miura’s hand-crafted FVR system. We also point out that Miura’s system is easily compromised by non-vein-looking samples generated by a WGAN-GP model with false acceptance rates up to 94.21%. The results raise the alarm about the robustness of such systems and suggest that master vein attacks should be considered an important security measure.