{"title":"针对指纹认证系统的对抗性扰动","authors":"S. Marrone, Carlo Sansone","doi":"10.1109/ICB45273.2019.8987399","DOIUrl":null,"url":null,"abstract":"Fingerprint-based Authentication Systems (FAS) usage is increasing over the last years thanks to the growing availability of cheap and reliable scanners. In order to bypass a FAS by using a counterfeit fingerprint, a Presentation Attack (PA) can be used. As a consequence, a liveness detector able to discern authentic from fake biometry becomes almost essential in each FAS. Deep Learning based approaches demonstrated to be very effective against fingerprint presentation attacks, becoming the current state-of-the-art in liveness detection. However, it has been shown that it is possible to arbitrarily cause state-of-the-art CNNs to misclassify an image by applying on it a suitable small peturbation, often even imperceptible to human eyes. The aim of this work is to understand if and to what extent adversarial perturbation can affect FASs, as a preliminary step to develop an adversarial presentation attack. Results show that it is possible to exploit adversarial perturbation to mislead both the FAS liveness detector and the authentication system, by giving rise to images that are even almost imperceptible to human eyes.","PeriodicalId":430846,"journal":{"name":"2019 International Conference on Biometrics (ICB)","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Adversarial Perturbations Against Fingerprint Based Authentication Systems\",\"authors\":\"S. Marrone, Carlo Sansone\",\"doi\":\"10.1109/ICB45273.2019.8987399\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Fingerprint-based Authentication Systems (FAS) usage is increasing over the last years thanks to the growing availability of cheap and reliable scanners. In order to bypass a FAS by using a counterfeit fingerprint, a Presentation Attack (PA) can be used. As a consequence, a liveness detector able to discern authentic from fake biometry becomes almost essential in each FAS. Deep Learning based approaches demonstrated to be very effective against fingerprint presentation attacks, becoming the current state-of-the-art in liveness detection. However, it has been shown that it is possible to arbitrarily cause state-of-the-art CNNs to misclassify an image by applying on it a suitable small peturbation, often even imperceptible to human eyes. The aim of this work is to understand if and to what extent adversarial perturbation can affect FASs, as a preliminary step to develop an adversarial presentation attack. Results show that it is possible to exploit adversarial perturbation to mislead both the FAS liveness detector and the authentication system, by giving rise to images that are even almost imperceptible to human eyes.\",\"PeriodicalId\":430846,\"journal\":{\"name\":\"2019 International Conference on Biometrics (ICB)\",\"volume\":\"8 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 International Conference on Biometrics (ICB)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICB45273.2019.8987399\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 International Conference on Biometrics (ICB)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICB45273.2019.8987399","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Adversarial Perturbations Against Fingerprint Based Authentication Systems
Fingerprint-based Authentication Systems (FAS) usage is increasing over the last years thanks to the growing availability of cheap and reliable scanners. In order to bypass a FAS by using a counterfeit fingerprint, a Presentation Attack (PA) can be used. As a consequence, a liveness detector able to discern authentic from fake biometry becomes almost essential in each FAS. Deep Learning based approaches demonstrated to be very effective against fingerprint presentation attacks, becoming the current state-of-the-art in liveness detection. However, it has been shown that it is possible to arbitrarily cause state-of-the-art CNNs to misclassify an image by applying on it a suitable small peturbation, often even imperceptible to human eyes. The aim of this work is to understand if and to what extent adversarial perturbation can affect FASs, as a preliminary step to develop an adversarial presentation attack. Results show that it is possible to exploit adversarial perturbation to mislead both the FAS liveness detector and the authentication system, by giving rise to images that are even almost imperceptible to human eyes.