[Paper Review] On the Risk of Cancelable Biometrics
This paper reveals that the distance-preserving property in cancelable biometrics (CB) inherently creates a vulnerability to pre-image attacks, enabling attackers to reconstruct original biometric templates even across different transformation functions. The authors propose a generalized pre-image attack and a cross-transformation attack that achieve high success rates (e.g., 84.05% SAR on face data), demonstrating that existing CB schemes are insecure despite their design goals of irreversibility and revocability.
Cancelable biometrics (CB) employs an irreversible transformation to convert the biometric features into transformed templates while preserving the relative distance between two templates for security and privacy protection. However, distance preservation invites unexpected security issues such as pre-image attacks, which are often neglected.This paper presents a generalized pre-image attack method and its extension version that operates on practical CB systems. We theoretically reveal that distance preservation property is a vulnerability source in the CB schemes. We then propose an empirical information leakage estimation algorithm to access the pre-image attack risk of the CB schemes. The experiments conducted with six CB schemes designed for the face, iris and fingerprint, demonstrate that the risks originating from the distance computed from two transformed templates significantly compromise the security of CB schemes. Our work reveals the potential risk of existing CB systems theoretically and experimentally.
Motivation & Objective
- To identify and analyze the security risks introduced by the distance-preserving property in cancelable biometric systems.
- To propose a generalized pre-image attack that operates under Kerckhoffs’s assumption and is effective across different transformation functions.
- To develop a practical cross-transformation attack that bypasses security by exploiting distance preservation between transformed templates.
- To quantify information leakage in CB schemes using mutual information based on distance preservation.
- To evaluate the security of six well-known CB schemes across face, iris, and fingerprint modalities under these new attack models.
Proposed method
- Proposes a generic pre-image attack that leverages the distance-preserving nature of CB matchers to reverse-transform templates to approximate original biometric features.
- Introduces a cross-transformation attack that uses a pre-image reconstructed from one CB system to attack a different CB system with a distinct transformation function.
- Employs the Blahut–Arimoto algorithm to estimate information leakage from the distance-preserving property using mutual information between original and transformed templates.
- Uses deep features (e.g., InsightFace) and standard biometric templates (e.g., IrisCode, fingerprint minutiae) as input to evaluate attack feasibility across modalities.
- Employs a query-based attack model requiring knowledge of transformation parameters and repeated access to the matcher function to optimize reconstruction.
- Evaluates attack success via Successive Attack Rate (SAR), measuring the proportion of successfully matched pre-images to original templates.
Experimental results
Research questions
- RQ1How does the distance-preserving property in cancelable biometric systems create a vulnerability to pre-image attacks?
- RQ2Can a pre-image attack be generalized to work across different transformation functions, even when the target system uses a different scheme?
- RQ3To what extent does information leakage occur in CB schemes due to distance preservation, and how can it be quantified?
- RQ4What is the empirical success rate of pre-image attacks on real-world CB systems across face, iris, and fingerprint modalities?
- RQ5Does higher accuracy in CB systems correlate with increased security risk, or can low-accuracy systems still be vulnerable?
Key findings
- The distance-preserving property in CB matchers is a fundamental vulnerability, enabling effective pre-image reconstruction even under Kerckhoffs’s assumption.
- The cross-transformation attack achieves a 84.05% Successive Attack Rate (SAR) on face data when attacking BioHashing with a compromised IFO system, demonstrating cross-scheme feasibility.
- On iris data, the IFO-based system achieved 81.32% SAR when attacking a Bloom filter-protected system, indicating poor concealment of original template information.
- NMDSH with α=0.5 showed better resistance (23.27% SAR) than other schemes, suggesting parameter tuning can improve security, but not eliminate risk.
- The information leakage estimation method based on mutual information successfully quantifies the risk of distance preservation, revealing that even accurate CB schemes are vulnerable.
- High-accuracy CB schemes (e.g., BioHashing EER=5.29%) are not necessarily secure, as they achieve high SAR (85.54%), proving that accuracy does not imply security.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.