课题基金 / 基金详情

SaTC: CORE: Small: Dictionary Attacks on Biometrics

SaTC: CORE: Small: Dictionary Attacks on Biometrics
SaTC:核心:小:对生物识别技术的字典攻击
批准号:
1956200
负责人:
Julian Togelius
金额:
$48.34万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2024-09-30

项目摘要

项目成果

Julian Togelius的其他基金

相似基金

相关文献

中文摘要
翻译
生物识别认证,可以让你通过指纹、声音或面部来识别自己,这是一种非常常见的认证机制。大多数智能手机和越来越多的其他设备和系统都具有某种形式的生物识别功能。这在一定程度上是因为它们被视为比密码更快、更容易、有时更安全的替代品。然而,最近的研究表明,作为生物识别认证系统核心的机器学习方法存在严重漏洞。特别是,有时可能使用所谓的“字典攻击”,其中可以找到一组现有令牌,这些令牌有很高的概率绕过身份验证系统。在这个项目中,研究人员将研究对各种生物识别系统的这种攻击,并找到有效的防御措施。该项目建立在研究人员使用现代机器学习方法寻找指纹和语音认证漏洞的工作基础上。所开发的方法将提高生物识别认证机制的整体安全性和可靠性。与众所周知的欺骗相比,字典攻击不依赖于目标个体的生物特征样本,例如语音记录或潜在指纹,而是利用特定生物特征模式(或其部署)的弱点。它们可以瞄准整个人群,并依赖于常见生物特征的偶然匹配。机器学习的最新进展,特别是生成式对抗网络(generative Adversarial Networks)等生成式模型,使生物识别技术的此类攻击成为可能。该项目的目标是系统地研究生物识别技术在常用的无监督和移动部署中的安全性,例如智能手机、家庭助理、物联网设备或语音通话。研究人员将重点研究新发现的针对指纹、声音和面部模式的字典攻击。调查人员将研究实际的威胁模型,并提出攻击检测和缓解策略。该项目将解决的问题集中在理解这种类型的漏洞及其相关的攻击,以及如何最好地防御它们:-什么是最实用的威胁模型,攻击者需要拥有什么能力?-攻击策略是否在不同的模式之间一般化?-确定的“典范”是否具有普遍性?它们在用户群和身份验证系统之间传输吗?-最佳缓解策略是什么?是否有可能可靠地检测所呈现的合成成分?-是否有可能改进注册策略以最大限度地提高安全性和/或警告用户已注册示例的较高脆弱性?该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Biometric authentication, that lets you identify yourself with for example your fingerprint, your voice, or your face, is a very common authentication mechanism these days. Most smartphones and a growing number of other devices and systems feature some form of biometrics. This is partly because they are seen as faster, easier and sometimes more secure alternatives to passwords. However, recent studies suggest that the machine learning methods at the core of biometric authentication systems have serious vulnerabilities. In particular, it is sometimes possible to use what's called a "dictionary attack", where a set of existing tokens can be found which together have a high probability of bypassing the authentication system. In this project, the researchers will study such attacks on various biometric systems, and also find effective defenses for them. The project builds on work where the investigators used modern machine learning approaches to find vulnerabilities in fingerprint and voice authentication. The methods developed will improve the overall security and reliability of biometric authentication mechanisms.In contrast to well-known spoofing, dictionary attacks do not rely on biometric samples of a targeted individual, e.g., voice recordings or latent prints, but instead exploit weaknessess of the specific biometric modality (or its deployment). They allow targeting of entire populations, and rely on fortuitous matches of common biometric features. Recent advances in machine learning, and in particular in generative models such as Generative Adversarial Networks, have made such attacks possible for biometrics. The goal of this project is to systematically study the security of biometrics in commonly used unsupervised and mobile deployments, e.g., in smartphones, home assistants, IoT devices, or voice calls. The researchers will focus on the newly discovered dictionary attacks on the fingerprint, voice and face modalities. Investigators will study practical threat models and propose attack detection and mitigation strategies. The project will address questions which are focused on understanding this type of vulnerability and its associated attacks, and how they can best be defended against:- What are the most practical threat models and what are the capabilities the attackers need to posess?- Do the attack strategies generalize between the modalities?- Are the identified "master-examples" universal? Do they transfer between user populations and authentication systems?- What is the optimal mitigation strategy? Is it possible to reliably detect the presented synthetic content?- Is it possible to improve the enrollment policy to maximize security and/or warn the user about higher vulnerability of the enrolled examples?This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/tifs.2022.3229583
发表时间: 2022-04
期刊: IEEE Transactions on Information Forensics and Security
影响因子: 6.8
作者: [M. Marras;Pawel Korus;Anubhav Jain;N. Memon]
通讯作者: M. Marras;Pawel Korus;Anubhav Jain;N. Memon
Diversity and Novelty MasterPrints: Generating Multiple DeepMasterPrints for Increased User Coverage
多样性和新颖性 MasterPrint:生成多个 DeepMasterPrint 以增加用户覆盖范围
DOI: 10.1109/biosig55365.2022.9897028
发表时间: 2022
期刊: 2022 International Conference of the Biometrics Special Interest Group (BIOSIG
影响因子: --
作者: [Charity, M, Memon, Nasir, Jiang, Zehua, Sen, Abhi, Togelius, Julian]
通讯作者: Togelius, Julian
DOI: 10.1109/ijcb54206.2022.10007967
发表时间: 2022-10
期刊: 2022 IEEE International Joint Conference on Biometrics (IJCB)
影响因子: --
作者: [Anubhav Jain;Nasir D. Memon;Julian Togelius]
通讯作者: Anubhav Jain;Nasir D. Memon;Julian Togelius
RI: Small: General Intelligence through Algorithm Invention and Selection
  • 批准号:
    1717324
  • 项目类别:
    Standard Grant
  • 资助金额:
    $42.7万
  • 财政年份:
    2017
  • 负责人:
    Julian Togelius
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: