Fingerprint Adversarial Presentation Attack in the Physical Domain

Casula R.;Orru' G.;Marcialis G. L.;Sansone C.
2021-01-01

Abstract

With the advent of the deep learning era, Fingerprint-based Authentication Systems (FAS) equipped with Fingerprint Presentation Attack Detection (FPAD) modules managed to avoid attacks on the sensor through artificial replicas of fingerprints. Previous works highlighted the vulnerability of FPADs to digital adversarial attacks. However, in a realistic scenario, the attackers may not have the possibility to directly feed a digitally perturbed image to the deep learning based FPAD, since the channel between the sensor and the FPAD is usually protected. In this paper we thus investigate the threat level associated with adversarial attacks against FPADs in the physical domain. By materially realising fakes from the adversarial images we were able to insert them into the system directly from the “exposed” part, the sensor. To the best of our knowledge, this represents the first proof-of-concept of a fingerprint adversarial presentation attack. We evaluated how much liveness score changed by feeding the system with the attacks using digital and printed adversarial images. To measure what portion of this increase is due to the printing itself, we also re-printed the original spoof images, without injecting any perturbation. Experiments conducted on the LivDet 2015 dataset demonstrate that the printed adversarial images achieve ∼ 100% attack success rate against an FPAD if the attacker has the ability to make multiple attacks on the sensor (10) and a fairly good result (∼ 28%) in a one-shot scenario. Despite this work must be considered as a proof-of-concept, it constitutes a promising pioneering attempt confirming that an adversarial presentation attack is feasible and dangerous.
2021
Inglese
Pattern Recognition. ICPR International Workshops and Challenges Virtual Event, January 10–15, 2021, Proceedings, Part VI
978-3-030-68779-3
978-3-030-68780-9
Springer
Cham
SVIZZERA
Alberto Del Bimbo, Rita Cucchiara, Stan Sclaroff, Giovanni Maria Farinella, Tao Mei, Marco Bertini, Hugo Jair Escalante, Roberto Vezzani
12666
530
543
14
https://link.springer.com/book/10.1007/978-3-030-68780-9
25th International Conference on Pattern Recognition, ICPR 2020
Esperti anonimi
10–15 Gennaio 2021
virtual event
internazionale
scientifica
Adversarial; FPAD; Liveness
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Marrone, S.; Casula, R.; Orru', G.; Marcialis, G. L.; Sansone, C.
273
5
4.1 Contributo in Atti di convegno
open
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
ICPR2020_AdvFinger.pdf

Open Access from 26/02/2022

Description: Paper
Type: versione post-print
Size 1.18 MB
Format Adobe PDF
1.18 MB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie