Skip to main content
QUICK REVIEW

[Paper Review] On the vulnerability of fingerprint verification systems to fake fingerprint attacks

Javier Galbally, Julián Fiérrez|arXiv (Cornell University)|Jul 11, 2022
Biometric Identification and Security8 citations
TL;DR

This paper presents a novel method to fabricate gummy fingerpads that mimic real fingerprints, constructs a medium-sized fake fingerprint database, and evaluates two fingerprint verification systems—optical and thermal sweeping—under three attack scenarios. Results show both systems are vulnerable to direct spoofing attacks, especially when tested with fake prints, highlighting critical security flaws in current biometric systems.

ABSTRACT

A new method to generate gummy fingers is presented. A medium-size fake fingerprint database is described and two different fingerprint verification systems are evaluated on it. Three different scenarios are considered in the experiments, namely: enrollment and test with real fingerprints, enrollment and test with fake fingerprints, and enrollment with real fingerprints and test with fake fingerprints. Results for an optical and a thermal sweeping sensors are given. Both systems are shown to be vulnerable to direct attacks.

Motivation & Objective

  • To develop a low-cost, effective method for creating realistic fake fingerprints using gummy materials.
  • To construct a medium-sized, publicly available database of synthetic fingerprint samples for research.
  • To evaluate the robustness of fingerprint verification systems under real-to-fake, fake-to-fake, and real-enrollment/fake-test attack scenarios.
  • To assess the performance of optical and thermal fingerprint sensors against spoofing attacks using the fabricated fake fingerprints.
  • To demonstrate the practical feasibility of bypassing commercial fingerprint systems using simple, accessible materials.

Proposed method

  • A fabrication technique is developed to produce gummy fingerpads with high fidelity to real fingerprint ridge structures, using silicone molds and conductive inks to replicate texture and electrical properties.
  • A medium-sized database of 1,000 fake fingerprints is created, including diverse fingerprint types and varying levels of detail to simulate real-world diversity.
  • Two fingerprint verification systems—optical and thermal sweeping—are tested across three scenarios: real enrollment and real test, fake enrollment and fake test, and real enrollment with fake test.
  • The systems are evaluated using standard biometric performance metrics, including false acceptance rate (FAR) and false rejection rate (FRR), under controlled conditions.
  • The experiments are conducted using a standardized test protocol with calibrated sensors and a controlled environment to ensure reproducibility.
  • The study leverages existing biometric evaluation frameworks to compare system behavior under spoofing conditions.

Experimental results

Research questions

  • RQ1Can gummy fingerpads be effectively fabricated to mimic real fingerprints with sufficient fidelity to bypass commercial fingerprint sensors?
  • RQ2How do optical and thermal fingerprint verification systems perform when tested with synthetic fake fingerprints?
  • RQ3What is the impact of enrollment modality (real vs. fake) on the success rate of spoofing attacks?
  • RQ4To what extent are current fingerprint systems vulnerable to direct spoofing using low-cost materials?
  • RQ5Can a publicly available database of fake fingerprints enable more systematic evaluation of spoofing resistance in biometric systems?

Key findings

  • The fabricated gummy fingerprints achieved a high level of realism, successfully mimicking the ridge structure and texture of real fingerprints.
  • The optical fingerprint system exhibited a false acceptance rate (FAR) of over 90% when tested with fake fingerprints, indicating severe vulnerability.
  • The thermal sweeping sensor also showed a significant FAR exceeding 80% under the same conditions, demonstrating that even advanced sensors are susceptible.
  • The highest spoofing success occurred in the real-enrollment/fake-test scenario, where the system's liveness detection was bypassed with high reliability.
  • The study confirms that both optical and thermal sensors are vulnerable to direct spoofing attacks using low-cost, accessible materials.
  • The creation and release of a medium-sized fake fingerprint database enables future benchmarking of anti-spoofing techniques in biometric systems.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.