Skip to main content
QUICK REVIEW

[Paper Review] Video is All You Need: Attacking PPG-based Biometric Authentication

Lin Li, Chao Chen|arXiv (Cornell University)|Mar 2, 2022
User Authentication and Security Systems4 citations
TL;DR

This paper proposes a novel spoofing attack that uses remote photoplethysmography (rPPG) signals extracted from HD video clips to bypass PPG-based biometric authentication systems. By introducing a generative signal restoration model (SigR) that reconstructs rPPG waveforms to closely resemble genuine PPG signals, the attack achieves a 62% average success rate, demonstrating that publicly available videos pose a severe threat to PPG-based biometric security.

ABSTRACT

Unobservable physiological signals enhance biometric authentication systems. Photoplethysmography (PPG) signals are convenient owning to its ease of measurement and are usually well protected against remote adversaries in authentication. Any leaked PPG signals help adversaries compromise the biometric authentication systems, and the advent of remote PPG (rPPG) enables adversaries to acquire PPG signals through restoration. While potentially dangerous, rPPG-based attacks are overlooked because existing methods require the victim's PPG signals. This paper proposes a novel spoofing attack approach that uses the waveforms of rPPG signals extracted from video clips to fool the PPG-based biometric authentication. We develop a new PPG restoration model that does not require leaked PPG signals for adversarial attacks. Test results on state-of-art PPG-based biometric authentication show that the signals recovered through rPPG pose a severe threat to PPG-based biometric authentication.

Motivation & Objective

  • To investigate the feasibility of launching spoofing attacks on PPG-based biometric authentication systems using only video clips.
  • To address the challenge of waveform and timing discrepancies between rPPG signals extracted from video and genuine PPG signals.
  • To develop a signal restoration model that enables rPPG signals to mimic authentic PPG signals for successful biometric spoofing.
  • To evaluate the impact of video quality factors—frame rate, resolution, bit-rate, and beauty filters—on the success of such attacks.
  • To demonstrate that rPPG-based attacks are practical and pose a real-world threat to PPG-based biometric systems

Proposed method

  • Proposes a novel generative signal restoration model, SigR, to reconstruct PPG-like waveforms from rPPG signals extracted from facial video clips.
  • Trains SigR using paired real PPG signals (from fingertip oximeter) and corresponding rPPG signals (from video) to learn the mapping between rPPG and PPG waveforms.
  • Employs a conditional generative adversarial network (cGAN) framework to model the morphological features of PPG signals, including fiducial points (systolic peak, dicrotic notch) and first-order derivatives.
  • Uses the UBFC-PHYS dataset for training and evaluation, with subjects in 'resting', 'talking', and 'calculating' states to test robustness across physiological conditions.
  • Evaluates video quality factors by varying frame rate (20–60 FPS), resolution (720p–1080p), bit-rate, and applying beauty filters to assess their impact on rPPG quality and attack success.
  • Performs statistical analysis using Kolmogorov-Smirnov (KS) tests to compare the distribution of rPPG-derived features with original PPG features across different video conditions.

Experimental results

Research questions

  • RQ1Can rPPG signals extracted from HD video clips be used to successfully spoof PPG-based biometric authentication systems?
  • RQ2How effective is the proposed SigR model in restoring rPPG signals to resemble genuine PPG waveforms across different physiological states?
  • RQ3What is the impact of video quality factors—frame rate, resolution, bit-rate, and beauty filters—on the success of rPPG-based spoofing attacks?
  • RQ4To what extent do morphological features of the PPG waveform (e.g., dicrotic notch, fiducial points) influence the success of the attack?
  • RQ5Is the attack practical in real-world scenarios involving publicly shared high-quality videos from platforms like YouTube or TikTok?

Key findings

  • The proposed SigR model successfully restores rPPG signals to closely resemble genuine PPG waveforms, achieving a 62% average success rate in spoofing PPG-based biometric authentication.
  • The attack success rate is significantly higher than random guessing, with consistent performance across different physiological states (resting, talking, calculating), indicating robustness to physiological variation.
  • Video frame rate has a major impact on attack success: lower frame rates (e.g., 20 FPS) result in higher Kolmogorov-Smirnov (KS) test p-values, indicating greater waveform distortion and reduced spoofing effectiveness.
  • Frame size and beauty filters primarily affect the original PPG waveform features, while bit-rate has a lesser impact on signal fidelity.
  • rPPG signals extracted from the COHFACE dataset (lower quality: 20 FPS, 640×480, 255 Kbps) were insufficient to compromise biometric systems, highlighting the critical role of video quality in attack feasibility.
  • The study confirms that high-quality HD videos, commonly shared on social media platforms, can be exploited to extract usable rPPG signals, making the attack practical in real-world settings.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.