The Many-faced God: Attacking Face Verification System with Embedding and Image Recovery

The Many-faced God: Attacking Face Verification System with Embedding and Image Recovery
复制标题

DOI:
10.1145/3485832.3485840
复制
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Mingtian Tan;Zhe Zhou;Zhou Li
Mingtian Tan;Zhe Zhou;Zhou Li
中科院分区:
其他
文献类型:
--
作者:
Mingtian Tan;Zhe Zhou;Zhou Li

文献摘要

相似文献

人脸识别系统(FVS)可以自动识别一个人的身份,已经越来越多地应用于现实世界中。其成功的关键是包含人脸嵌入,这是一种可以通过深度神经网络检测同一个人的相似照片的技术。我们发现,分数显示在一起的验证结果可以被对手用来“制造”一个脸通过FVS。具体地,嵌入可以用分数以高精度反转。对手可以使用我们开发的一种新的机器学习技术进一步学习受害者的外观,我们称之为嵌入反向GAN。该攻击在嵌入和图像恢复方面非常有效。通过对FVS的2个查询,对手可以以40%的成功率绕过FVS。当查询数量增加到20时,几乎每次都可以绕过FVS。重建的人脸图像也与受害者的相似。
Face verification system (FVS), which can automatically verify a person’s identity, has been increasingly deployed in the real-world settings. Key to its success is the inclusion of face embedding, a technique that can detect similar photos of the same person by deep neural networks. We found the score displayed together with the verification result can be utilized by an adversary to “fabricate” a face to pass FVS. Specifically, embeddings can be reversed at high accuracy with the scores. The adversary can further learn the appearance of the victim using a new machine-learning technique developed by us, which we call embedding-reverse GAN. The attack is quite effective in embedding and image recovery. With 2 queries to a FVS, the adversary can bypass the FVS at 40% success rate. When the query number raises to 20, FVS can be bypassed almost every time. The reconstructed face image is also similar to victim’s.