Toward Robotic Robbery on the Touch Screen

Toward Robotic Robbery on the Touch Screen
复制标题

DOI:
10.1145/2898353
复制
发表时间:
2016-05
期刊:
ACM Transactions on Information and System Security (TISSEC)
影响因子:
--
通讯作者:
Abdul Serwadda;V. Phoha;Zibo Wang;R. Kumar;Diksha Shukla
Abdul Serwadda;V. Phoha;Zibo Wang;R. Kumar;Diksha Shukla
中科院分区:
其他
文献类型:
--
作者:
Abdul Serwadda;V. Phoha;Zibo Wang;R. Kumar;Diksha Shukla

文献摘要

被引文献

相似文献

尽管大量的研究前沿使用触摸手势作为智能手机上的连续认证机制,但很少有研究评估这些系统在受到复杂对手攻击时的行为。在这篇文章中,我们提出了两个乐高驱动的机器人攻击基于触摸的身份验证:人口统计驱动的攻击和用户定制的攻击。人口统计驱动的攻击是基于从大量用户中收集的模式,而用户定制的攻击是基于从受害者那里窃取的样本发起的。这两次攻击都是由一个乐高机器人发起的,该机器人接受了如何在触摸屏上滑动的训练。使用七个验证算法和一个大的用户数据集,我们表明,攻击导致系统的平均错误接受率(FAR)增加了五倍,相对于标准的零努力冒名顶替者攻击下看到的平均FAR。这篇文章展示了机器人对基于触摸的身份验证构成的威胁,并提供了令人信服的证据,说明为什么零努力攻击应该停止作为基于触摸的身份验证系统的基准。
Despite the tremendous amount of research fronting the use of touch gestures as a mechanism of continuous authentication on smart phones, very little research has been conducted to evaluate how these systems could behave if attacked by sophisticated adversaries. In this article, we present two Lego-driven robotic attacks on touch-based authentication: a population statistics--driven attack and a user-tailored attack. The population statistics--driven attack is based on patterns gleaned from a large population of users, whereas the user-tailored attack is launched based on samples stolen from the victim. Both attacks are launched by a Lego robot that is trained on how to swipe on the touch screen. Using seven verification algorithms and a large dataset of users, we show that the attacks cause the system’s mean false acceptance rate (FAR) to increase by up to fivefold relative to the mean FAR seen under the standard zero-effort impostor attack. The article demonstrates the threat that robots pose to touch-based authentication and provides compelling evidence as to why the zero-effort attack should cease to be used as the benchmark for touch-based authentication systems.