Rethinking the Vulnerabilities of Face Recognition Systems:From a Practical Perspective

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Jiahao, Shen, Zhiqiang, Pu, Yuwen, Zhou, Chunyi, Li, Changjiang, Li, Jiliang, Wang, Ting, Ji, Shouling
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916279970955264
author Chen, Jiahao
Shen, Zhiqiang
Pu, Yuwen
Zhou, Chunyi
Li, Changjiang
Li, Jiliang
Wang, Ting
Ji, Shouling
author_facet Chen, Jiahao
Shen, Zhiqiang
Pu, Yuwen
Zhou, Chunyi
Li, Changjiang
Li, Jiliang
Wang, Ting
Ji, Shouling
contents Face Recognition Systems (FRS) have increasingly integrated into critical applications, including surveillance and user authentication, highlighting their pivotal role in modern security systems. Recent studies have revealed vulnerabilities in FRS to adversarial (e.g., adversarial patch attacks) and backdoor attacks (e.g., training data poisoning), raising significant concerns about their reliability and trustworthiness. Previous studies primarily focus on traditional adversarial or backdoor attacks, overlooking the resource-intensive or privileged-manipulation nature of such threats, thus limiting their practical generalization, stealthiness, universality and robustness. Correspondingly, in this paper, we delve into the inherent vulnerabilities in FRS through user studies and preliminary explorations. By exploiting these vulnerabilities, we identify a novel attack, facial identity backdoor attack dubbed FIBA, which unveils a potentially more devastating threat against FRS:an enrollment-stage backdoor attack. FIBA circumvents the limitations of traditional attacks, enabling broad-scale disruption by allowing any attacker donning a specific trigger to bypass these systems. This implies that after a single, poisoned example is inserted into the database, the corresponding trigger becomes a universal key for any attackers to spoof the FRS. This strategy essentially challenges the conventional attacks by initiating at the enrollment stage, dramatically transforming the threat landscape by poisoning the feature database rather than the training data.
format Preprint
id arxiv_https___arxiv_org_abs_2405_12786
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Rethinking the Vulnerabilities of Face Recognition Systems:From a Practical Perspective
Chen, Jiahao
Shen, Zhiqiang
Pu, Yuwen
Zhou, Chunyi
Li, Changjiang
Li, Jiliang
Wang, Ting
Ji, Shouling
Cryptography and Security
Face Recognition Systems (FRS) have increasingly integrated into critical applications, including surveillance and user authentication, highlighting their pivotal role in modern security systems. Recent studies have revealed vulnerabilities in FRS to adversarial (e.g., adversarial patch attacks) and backdoor attacks (e.g., training data poisoning), raising significant concerns about their reliability and trustworthiness. Previous studies primarily focus on traditional adversarial or backdoor attacks, overlooking the resource-intensive or privileged-manipulation nature of such threats, thus limiting their practical generalization, stealthiness, universality and robustness. Correspondingly, in this paper, we delve into the inherent vulnerabilities in FRS through user studies and preliminary explorations. By exploiting these vulnerabilities, we identify a novel attack, facial identity backdoor attack dubbed FIBA, which unveils a potentially more devastating threat against FRS:an enrollment-stage backdoor attack. FIBA circumvents the limitations of traditional attacks, enabling broad-scale disruption by allowing any attacker donning a specific trigger to bypass these systems. This implies that after a single, poisoned example is inserted into the database, the corresponding trigger becomes a universal key for any attackers to spoof the FRS. This strategy essentially challenges the conventional attacks by initiating at the enrollment stage, dramatically transforming the threat landscape by poisoning the feature database rather than the training data.
title Rethinking the Vulnerabilities of Face Recognition Systems:From a Practical Perspective
topic Cryptography and Security
url https://arxiv.org/abs/2405.12786