Resist: Reconstruction of irises from templates

Resist: Reconstruction of irises from templates
复制标题

DOI:
10.1109/ijcb48548.2020.9304912
复制
发表时间:
2020-07
期刊:
2020 IEEE International Joint Conference on Biometrics (IJCB)
影响因子:
--
通讯作者:
Sohaib Ahmad;Benjamin Fuller
Sohaib Ahmad;Benjamin Fuller
中科院分区:
其他
文献类型:
--
作者:
Sohaib Ahmad;Benjamin Fuller

文献摘要

相似文献

虹膜识别系统将虹膜图像转换为特征向量。开创性的管道将图像分割为虹膜和非虹膜像素,将该区域归一化为固定维度的矩形,并提取存储并称为模板的特征(Dogman,2009)。此模板存储在系统中。可以对虹膜的未来读数进行变换,并与模板向量进行比较,以确定或验证个人的身份。由于模板通常存储在一起,因此它们是攻击者的宝贵目标。我们展示了如何在各种虹膜识别系统中倒置模板。我们的反转是基于卷积神经网络体系结构,我们称之为REST(从模板重建虹膜)。我们将REST应用于传统的Gabor过滤器管道、DenseNet(Huang等人,CVPR 2017)特征提取器,以及无需标准化即可工作的DenseNet架构。这两个DenseNet特征提取工具都基于最近的ThirdEye识别系统(Ahmad和Fuller,BTAS 2019)。当使用ND-0405数据集进行训练和测试时,重建图像对三个管道的等级1准确率分别为100%、76%和96%。我们方法的核心类似于自动编码器。为了获得高精度,该核心被集成到一个对抗性网络中(古德费罗等人,NeurIPS,2014)
Iris recognition systems transform an iris image into a feature vector. The seminal pipeline segments an image into iris and non-iris pixels, normalizes this region into a fixed-dimension rectangle, and extracts features which are stored and called a template (Daugman, 2009). This template is stored on a system. A future reading of an iris can be transformed and compared against template vectors to determine or verify the identity of an individual. As templates are often stored together, they are a valuable target to an attacker. We show how to invert templates across a variety of iris recognition systems. Our inversion is based on a convolutional neural network architecture we call RESIST (REconStructing IriSes from Templates). We apply RESIST to a traditional Gabor filter pipeline, to a DenseNet (Huang et al., CVPR 2017)feature extractor, and to a DenseNet architecture that works without normalization. Both DenseNet feature extractors are based on the recent ThirdEye recognition system (Ahmad and Fuller, BTAS 2019). When training and testing using the ND-0405 dataset, reconstructed images demonstrate a rank-1 accuracy of 100%, 76%, and 96% respectively for the three pipelines. The core of our approach is similar to an autoencoder. To obtain high accuracy this core is integrated into an adversarial network (Goodfellow et al., NeurIPS, 2014)