TY - GEN
T1 - FingerFaker
T2 - 21st ACM Conference on Embedded Networked Sensors Systems, SenSys 2023
AU - Shen, Yijie
AU - Ma, Zhe
AU - Lin, Feng
AU - Yan, Hao
AU - Ba, Zhongjie
AU - Lu, Li
AU - Xu, Wenyao
AU - Ren, Kui
N1 - Publisher Copyright:
© 2023 Copyright is held by the owner/author(s). Publication rights licensed to ACM.
PY - 2024/4/26
Y1 - 2024/4/26
N2 - Fingerprint recognition has been a vital security guard for various applications whose vulnerability has been explored by different works. However, previous works on spoofing fingerprint recognition rely on prior knowledge (e.g., photos and minutiae) of the target fingerprint, which fails to implement in practical scenarios. In this paper, we design a fingerprint spoofing attack, namely FingerFaker, to explore the vulnerability of fingerprint recognition, which can spoof automated fingerprint recognition systems (AFRSs) without prior knowledge of target fingerprints. Specifically, we propose a novel concept of "pseudo-minutiae-set"as an effective optimization object and design a two-stage scheme to optimize "pseudo-minutiaeset"leveraging a two-factor evolutionary strategy. In addition, we use a GAN-based training strategy with a minutiae loss function to pre-train a fingerprint generator to map a "pseudo-minutiae-set"into a fingerprint. We use 6342 fingerprint images to verify the performance of FingerFaker on spoofing the open-source AFRS, which shows a high attack success rate (ASR) of 97.78%. Meanwhile, we conduct a realistic case study on commercial off-the-shelf (COTS) AFRS, where FingerFaker also shows 94.22% ASR. Finally, we explore the impact of different conditions to guide the attack and propose countermeasures to mitigate the harm.
AB - Fingerprint recognition has been a vital security guard for various applications whose vulnerability has been explored by different works. However, previous works on spoofing fingerprint recognition rely on prior knowledge (e.g., photos and minutiae) of the target fingerprint, which fails to implement in practical scenarios. In this paper, we design a fingerprint spoofing attack, namely FingerFaker, to explore the vulnerability of fingerprint recognition, which can spoof automated fingerprint recognition systems (AFRSs) without prior knowledge of target fingerprints. Specifically, we propose a novel concept of "pseudo-minutiae-set"as an effective optimization object and design a two-stage scheme to optimize "pseudo-minutiaeset"leveraging a two-factor evolutionary strategy. In addition, we use a GAN-based training strategy with a minutiae loss function to pre-train a fingerprint generator to map a "pseudo-minutiae-set"into a fingerprint. We use 6342 fingerprint images to verify the performance of FingerFaker on spoofing the open-source AFRS, which shows a high attack success rate (ASR) of 97.78%. Meanwhile, we conduct a realistic case study on commercial off-the-shelf (COTS) AFRS, where FingerFaker also shows 94.22% ASR. Finally, we explore the impact of different conditions to guide the attack and propose countermeasures to mitigate the harm.
KW - fingerprint recognition
KW - no prior-knowledge
KW - spoofing attack
UR - https://www.scopus.com/pages/publications/85192725283
U2 - 10.1145/3625687.3625783
DO - 10.1145/3625687.3625783
M3 - Conference contribution
AN - SCOPUS:85192725283
T3 - SenSys 2023 - Proceedings of the 21st ACM Conference on Embedded Networked Sensors Systems
SP - 167
EP - 180
BT - SenSys 2023 - Proceedings of the 21st ACM Conference on Embedded Networked Sensors Systems
PB - Association for Computing Machinery, Inc
Y2 - 13 November 2023 through 15 November 2023
ER -