On the Resilience of Biometric Authentication Systems against Random Inputs

01/13/2020
by   Benjamin Zi Hao Zhao, et al.
0

We assess the security of machine learning based biometric authentication systems against an attacker who submits uniform random inputs, either as feature vectors or raw inputs, in order to find an accepting sample of a target user. The average false positive rate (FPR) of the system, i.e., the rate at which an impostor is incorrectly accepted as the legitimate user, may be interpreted as a measure of the success probability of such an attack. However, we show that the success rate is often higher than the FPR. In particular, for one reconstructed biometric system with an average FPR of 0.03, the success rate was as high as 0.78. This has implications for the security of the system, as an attacker with only the knowledge of the length of the feature space can impersonate the user with less than 2 attempts on average. We provide detailed analysis of why the attack is successful, and validate our results using four different biometric modalities and four different machine learning classifiers. Finally, we propose mitigation techniques that render such attacks ineffective, with little to no effect on the accuracy of the system.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/10/2022

Hiding Your Signals: A Security Analysis of PPG-based Biometric Authentication

Recently, physiological signal-based biometric systems have received wid...
research
04/12/2023

On the Adversarial Inversion of Deep Biometric Representations

Biometric authentication service providers often claim that it is not po...
research
12/23/2022

Security and Interpretability in Automotive Systems

The lack of any sender authentication mechanism in place makes CAN (Cont...
research
07/27/2020

Swipe dynamics as a means of authentication: results from a Bayesian unsupervised approach

The field of behavioural biometrics stands as an appealing alternative t...
research
05/18/2020

DALock: Distribution Aware Password Throttling

Large-scale online password guessing attacks are wide-spread and continu...
research
09/22/2022

Privacy Attacks Against Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models

Authentication systems are vulnerable to model inversion attacks where a...
research
05/22/2019

Biometric Backdoors: A Poisoning Attack Against Unsupervised Template Updating

In this work, we investigate the concept of biometric backdoors: a templ...

Please sign up or login with your details

Forgot password? Click here to reset