論文の概要: Casting the Net! Revisiting MasterFace Impersonation Attacks
- arxiv url: http://arxiv.org/abs/2608.06952v1
- Date: Fri, 07 Aug 2026 08:28:03 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-08-10 16:21:25.415239
- Title: Casting the Net! Revisiting MasterFace Impersonation Attacks
- Title(参考訳): ネットをキャスト!MasterFaceの偽造攻撃を再開
- Authors: Seunghun Paik, Sunpill Kim, Chanwoo Hwang, Jae Hong Seo,
- Abstract要約: 顔認証は顔認識システム(FRS)の基本的なセキュリティ脅威である
パブリックな商用APIへの正当なアクセスさえも、敵がMasterFacesを通じて偽造率を増幅できることを示します。
当社の攻撃は、複数のオープンソースおよび商用APIベースのFRSの偽造率を、少なくとも30の認証トライアルで最大9.5$times$まで向上させることを実証している。
- 参考スコア(独自算出の注目度): 5.609125617225078
- License: http://creativecommons.org/licenses/by/4.0/
- Abstract: Impersonation is a fundamental security threat in face recognition systems (FRSs). While the security of FRSs has been challenged by various attack vectors, under realistic adversarial capabilities, e.g., a limited number of decision-only authentication trials and no internal system knowledge, most attack techniques become infeasible. As a result, impersonation by zero-effort impostors, characterized by false match rate (FMR), is commonly regarded as a standalone baseline. A few years ago, impersonation attacks based on MasterFaces emerged as a notable security threat that could break the barrier of the FMR-based baseline under such realistic constraints. However, they were believed not to yield impersonation above the standard FMR in modern FRSs, as discussed by multiple follow-up studies. In this paper, we demonstrate that even legitimate access to public commercial APIs allows an adversary to amplify impersonation rates through MasterFaces, resulting in a non-trivial impersonation attack beyond FMR on downstream applications built on top of these APIs. We observe that several real-world FRS deployments are implemented using commercial APIs, and that the backend service provider is publicly disclosed or trivially inferable. As a result, the adversary can purchase these pay-as-you-go API services without requiring any additional privilege over the target FRS. From this observation, we formalize the MasterFaces attack as a maximum coverage problem over the biometric representation space, which we call a NET, and show that the adversary can construct an API-tailored NET by leveraging the geometric structure of the representation space. We demonstrate that our attack amplifies the impersonation rates of several open-source and commercial API-based FRSs by up to 9.5$\times$ within at most 30 authentication trials, compared to those expected from the standard FMR.
- Abstract(参考訳): 顔認証は、顔認識システム(FRS)における基本的なセキュリティ脅威である。
FRSのセキュリティは、様々な攻撃ベクトルによって問題視されているが、現実的な敵の能力(例えば、限られた数の意思決定のみの認証試験と内部システム知識がない)の下では、ほとんどの攻撃技術は実現不可能である。
その結果、偽一致率(FMR)を特徴とするゼロ・エフォート・インポスタによる偽装は、一般的にスタンドアロンのベースラインとみなされる。
数年前、MasterFacesに基づく偽造攻撃は、このような現実的な制約の下でFMRベースのベースラインの障壁を破る可能性のある、注目すべきセキュリティ脅威として浮上した。
しかし、複数のフォローアップ研究で議論されているように、現代のFRSでは標準FMR以上の偽造は生じないと考えられていた。
本稿では、パブリックな商用APIへの正当なアクセスであっても、敵がMasterFacesを通じて偽造率を増幅することができ、その結果、これらのAPI上に構築された下流アプリケーション上でFMRを超えた非自明な偽造攻撃が発生することを実証する。
我々は,実世界のFRSデプロイメントが商用APIを使用して実装されていること,バックエンドサービスプロバイダが公開されていること,あるいは自明に推測可能であることを観察した。
その結果、敵はターゲットのFRSに対して追加の特権を必要とせずに、これらのペイ・アズ・ユー・ゴーのAPIサービスを購入することができる。
このことから,我々はMasterFaces攻撃を生体情報表現空間上での最大カバレッジ問題として定式化し,その表現空間の幾何学的構造を利用して,APIをカスタマイズしたNETを構築することができることを示す。
我々の攻撃は、標準のFMRで期待されるものと比較して、少なくとも30の認証トライアルで最大9.5$\times$まで、オープンソースおよび商用のAPIベースのFRSの偽造率を向上することを示した。
関連論文リスト
- Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents [93.19140872946842]
大規模言語モデル(LLM)によって駆動されるWebエージェントは、現実の環境にますますデプロイされる。
これにより、一見良質なコンテンツがエージェントの振る舞いを操作する敵の命令を埋め込む、プロンプト・インジェクション・アタックに対して脆弱になる。
実世界のWebエージェントシステムにおいて,損害を体系的に分類し,属性付けするベンチマークである textbfsysname を導入する。
論文 参考訳(メタデータ) (2026-06-11T14:12:43Z) - Non-Adaptive Adversarial Face Generation [18.28396766186067]
顔認識システムに対する敵対的な攻撃は、深刻なセキュリティとプライバシーの脅威を引き起こす。
対向顔合成顔画像を生成する新しい手法を提案する。
我々の方法は、AWSのComparteFaces APIに対して93%以上の高い成功率を達成する。
論文 参考訳(メタデータ) (2025-07-16T10:24:54Z) - Rethinking the Vulnerabilities of Face Recognition Systems:From a Practical Perspective [53.24281798458074]
顔認識システム(FRS)は、監視やユーザー認証を含む重要なアプリケーションにますます統合されている。
最近の研究によると、FRSの脆弱性は敵(例えば、敵パッチ攻撃)やバックドア攻撃(例えば、データ中毒の訓練)であることが明らかになっている。
論文 参考訳(メタデータ) (2024-05-21T13:34:23Z) - Attribute-Guided Encryption with Facial Texture Masking [64.77548539959501]
本稿では,顔認識システムからユーザを保護するために,顔テクスチャマスキングを用いた属性ガイド暗号化を提案する。
提案手法は,最先端の手法よりも自然な画像を生成する。
論文 参考訳(メタデータ) (2023-05-22T23:50:43Z) - Am I a Real or Fake Celebrity? Measuring Commercial Face Recognition Web
APIs under Deepfake Impersonation Attack [17.97648576135166]
人気企業の顔認識技術がDeepfake Impersonation(DI)攻撃にいかに脆弱であるかを実証します。
我々は、ターゲット(正確に一致)と非ターゲット(有名人と一致)の攻撃に対して、78.0%と99.9%の最大成功率を達成する。
論文 参考訳(メタデータ) (2021-03-01T08:40:10Z) - Measurement-driven Security Analysis of Imperceptible Impersonation
Attacks [54.727945432381716]
本稿では,ディープニューラルネットワークを用いた顔認識システムの実用性について検討する。
皮膚の色,性別,年齢などの要因が,特定の標的に対する攻撃を行う能力に影響を及ぼすことを示す。
また,攻撃者の顔のさまざまなポーズや視点に対して堅牢なユニバーサルアタックを構築する可能性についても検討した。
論文 参考訳(メタデータ) (2020-08-26T19:27:27Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。