ProxyPrints: From Database Breach to Spoof, A Plug-and-Play Defense for Biometric Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hacmon, Yaniv, Gorelik, Keren, Gressel, Gilad, Mirsky, Yisroel
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915621537579008
author Hacmon, Yaniv
Gorelik, Keren
Gressel, Gilad
Mirsky, Yisroel
author_facet Hacmon, Yaniv
Gorelik, Keren
Gressel, Gilad
Mirsky, Yisroel
contents Fingerprint recognition systems are widely deployed for authentication and forensic applications, but the security of stored fingerprint data remains a critical vulnerability. While many systems avoid storing raw fingerprint images in favor of minutiae-based templates, recent research shows that these templates can be reverse-engineered to reconstruct realistic fingerprint images, enabling physical spoofing attacks that compromise user identities with no means of remediation. We present ProxyPrints, the first practical defense that brings cancellable biometrics to existing fingerprint recognition systems without requiring modifications to proprietary matching software. ProxyPrints acts as a transparent middleware layer between the fingerprint scanner and the matching algorithm, transforming each scanned fingerprint into a consistent, unlinkable alias. This transformation allows biometric identities to be revoked and replaced in the event of a breach, without affecting authentication accuracy. Additionally, ProxyPrints provides organizations with breach detection capabilities by enabling the identification of out-of-band spoofing attempts involving compromised aliases. We evaluate ProxyPrints on standard benchmark datasets and commercial fingerprint recognition systems, demonstrating that it preserves matching performance while offering strong security and revocability. Our open-source implementation includes tools for alias generation and deployment in real-world pipelines, making ProxyPrints a drop-in, scalable solution for fingerprint data protection.
format Preprint
id arxiv_https___arxiv_org_abs_2511_12739
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ProxyPrints: From Database Breach to Spoof, A Plug-and-Play Defense for Biometric Systems
Hacmon, Yaniv
Gorelik, Keren
Gressel, Gilad
Mirsky, Yisroel
Cryptography and Security
Fingerprint recognition systems are widely deployed for authentication and forensic applications, but the security of stored fingerprint data remains a critical vulnerability. While many systems avoid storing raw fingerprint images in favor of minutiae-based templates, recent research shows that these templates can be reverse-engineered to reconstruct realistic fingerprint images, enabling physical spoofing attacks that compromise user identities with no means of remediation. We present ProxyPrints, the first practical defense that brings cancellable biometrics to existing fingerprint recognition systems without requiring modifications to proprietary matching software. ProxyPrints acts as a transparent middleware layer between the fingerprint scanner and the matching algorithm, transforming each scanned fingerprint into a consistent, unlinkable alias. This transformation allows biometric identities to be revoked and replaced in the event of a breach, without affecting authentication accuracy. Additionally, ProxyPrints provides organizations with breach detection capabilities by enabling the identification of out-of-band spoofing attempts involving compromised aliases. We evaluate ProxyPrints on standard benchmark datasets and commercial fingerprint recognition systems, demonstrating that it preserves matching performance while offering strong security and revocability. Our open-source implementation includes tools for alias generation and deployment in real-world pipelines, making ProxyPrints a drop-in, scalable solution for fingerprint data protection.
title ProxyPrints: From Database Breach to Spoof, A Plug-and-Play Defense for Biometric Systems
topic Cryptography and Security
url https://arxiv.org/abs/2511.12739