Skip to main content
QUICK REVIEW

[论文解读] Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake Era

Changjiang Li, Li Wang|arXiv (Cornell University)|Feb 22, 2022
Face recognition and analysis被引用 13
一句话总结

本文提出 LiveBugger,一种基于深度伪造技术的新型框架,用于在真实场景中评估面部活体验证(FLV)的安全性。研究发现,大多数商业 FLV API 对深度伪造攻击高度脆弱,且缺乏有效的反深度伪造防御机制;作者进一步提出一种两阶段攻击方法,可将成功率提升高达 70%,并展示了在真实应用中的实际利用效果。

ABSTRACT

Facial Liveness Verification (FLV) is widely used for identity authentication in many security-sensitive domains and offered as Platform-as-a-Service (PaaS) by leading cloud vendors. Yet, with the rapid advances in synthetic media techniques (e.g., deepfake), the security of FLV is facing unprecedented challenges, about which little is known thus far. To bridge this gap, in this paper, we conduct the first systematic study on the security of FLV in real-world settings. Specifically, we present LiveBugger, a new deepfake-powered attack framework that enables customizable, automated security evaluation of FLV. Leveraging LiveBugger, we perform a comprehensive empirical assessment of representative FLV platforms, leading to a set of interesting findings. For instance, most FLV APIs do not use anti-deepfake detection; even for those with such defenses, their effectiveness is concerning (e.g., it may detect high-quality synthesized videos but fail to detect low-quality ones). We then conduct an in-depth analysis of the factors impacting the attack performance of LiveBugger: a) the bias (e.g., gender or race) in FLV can be exploited to select victims; b) adversarial training makes deepfake more effective to bypass FLV; c) the input quality has a varying influence on different deepfake techniques to bypass FLV. Based on these findings, we propose a customized, two-stage approach that can boost the attack success rate by up to 70%. Further, we run proof-of-concept attacks on several representative applications of FLV (i.e., the clients of FLV APIs) to illustrate the practical implications: due to the vulnerability of the APIs, many downstream applications are vulnerable to deepfake. Finally, we discuss potential countermeasures to improve the security of FLV. Our findings have been confirmed by the corresponding vendors.

研究动机与目标

  • 系统评估先进深度伪造技术背景下,真实世界中面部活体验证(FLV)API 的安全性。
  • 识别并分析影响基于深度伪造攻击在已部署 FLV 系统中有效性的关键因素。
  • 通过在真实世界应用中开展概念验证攻击,展示 FLV 漏洞的实际利用。
  • 基于实证结果,为提升 FLV 服务对现代合成媒体威胁的防御能力,提供可操作的改进建议。

提出的方法

  • 设计并实现 LiveBugger,一种可定制、自动化的框架,集成最先进的深度伪造技术,用于真实世界 FLV 安全性评估。
  • 利用 LiveBugger 对主流云 PaaS 服务提供商的代表性商业 FLV API 进行大规模实证评估。
  • 通过改变深度伪造技术、输入质量及人口统计偏差(如性别、种族)等因素,深入分析攻击的有效性。
  • 提出一种两阶段攻击策略,根据 FLV 系统行为优化深度伪造生成,使绕过成功率最高提升 70%。
  • 在真实客户端应用上实施概念验证攻击,以验证 FLV 漏洞的实际影响。
  • 与厂商合作确认研究发现,并基于实证结果提供安全改进建议。

实验结果

研究问题

  • RQ1RQ1:在真实部署的系统中,面部活体验证(FLV)对基于深度伪造的攻击有多脆弱?
  • RQ2RQ2:不同深度伪造技术在绕过 FLV 系统方面的有效性有何差异?
  • RQ3RQ3:影响基于深度伪造攻击在 FLV API 上成功率的关键因素有哪些?
  • RQ4RQ4:从业者如何在新兴深度伪造威胁背景下提升 FLV 系统的安全性?

主要发现

  • 大多数商业 FLV API 未实施有效的反深度伪造检测机制,使其极易受到合成媒体攻击。
  • 即使对于声称具备深度伪造检测能力的 FLV 系统,其防御措施也极不稳定——部分能检测高质量伪造,却无法识别低质量伪造。
  • FLV 系统中的人口统计偏差可被攻击者利用,基于性别或种族选择更易受攻击的目标。
  • 对深度伪造模型进行对抗性训练,可显著提升其绕过 FLV 系统的能力。
  • 输入质量对不同深度伪造技术的攻击成功率影响各异,部分方法对低质量输入更具鲁棒性。
  • 定制化的两阶段攻击方法相比基线方法,可将绕过 FLV 系统的成功率提升高达 70%。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。