Skip to main navigation Skip to search Skip to main content

FingerFaker: Spoofing Attack on COTS Fingerprint Recognition Without Victim's Knowledge

  • Yijie Shen
  • , Zhe Ma
  • , Feng Lin
  • , Hao Yan
  • , Zhongjie Ba
  • , Li Lu
  • , Wenyao Xu
  • , Kui Ren
  • Zhejiang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Fingerprint recognition has been a vital security guard for various applications whose vulnerability has been explored by different works. However, previous works on spoofing fingerprint recognition rely on prior knowledge (e.g., photos and minutiae) of the target fingerprint, which fails to implement in practical scenarios. In this paper, we design a fingerprint spoofing attack, namely FingerFaker, to explore the vulnerability of fingerprint recognition, which can spoof automated fingerprint recognition systems (AFRSs) without prior knowledge of target fingerprints. Specifically, we propose a novel concept of "pseudo-minutiae-set"as an effective optimization object and design a two-stage scheme to optimize "pseudo-minutiaeset"leveraging a two-factor evolutionary strategy. In addition, we use a GAN-based training strategy with a minutiae loss function to pre-train a fingerprint generator to map a "pseudo-minutiae-set"into a fingerprint. We use 6342 fingerprint images to verify the performance of FingerFaker on spoofing the open-source AFRS, which shows a high attack success rate (ASR) of 97.78%. Meanwhile, we conduct a realistic case study on commercial off-the-shelf (COTS) AFRS, where FingerFaker also shows 94.22% ASR. Finally, we explore the impact of different conditions to guide the attack and propose countermeasures to mitigate the harm.

Original languageEnglish
Title of host publicationSenSys 2023 - Proceedings of the 21st ACM Conference on Embedded Networked Sensors Systems
PublisherAssociation for Computing Machinery, Inc
Pages167-180
Number of pages14
ISBN (Electronic)9798400704147
DOIs
StatePublished - Apr 26 2024
Event21st ACM Conference on Embedded Networked Sensors Systems, SenSys 2023 - Istanbul, Turkey
Duration: Nov 13 2023Nov 15 2023

Publication series

NameSenSys 2023 - Proceedings of the 21st ACM Conference on Embedded Networked Sensors Systems

Conference

Conference21st ACM Conference on Embedded Networked Sensors Systems, SenSys 2023
Country/TerritoryTurkey
CityIstanbul
Period11/13/2311/15/23

Keywords

  • fingerprint recognition
  • no prior-knowledge
  • spoofing attack

Fingerprint

Dive into the research topics of 'FingerFaker: Spoofing Attack on COTS Fingerprint Recognition Without Victim's Knowledge'. Together they form a unique fingerprint.

Cite this