News: 1628581451

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Don't believe the hype that AI-generated 'master faces' can break into face recognition systems any time soon

(2021/08/10)


Analysis The idea of so-called “master faces,” a set of fake images generated by machine learning algorithms to crack into facial biometric systems by impersonating people, made splashy headlines last week. But a closer look at the research reveals clear weaknesses that make it unlikely to work in the real world.

“A master face is a face image that passes face-based identity-authentication for a large portion of the population,” the [1]paper released on arXiv, earlier this month, explained. “These faces can be used to impersonate, with a high probability of success, any user, without having access to any user-information.”

The trio of academics from Tel Aviv University go on to say they built a model that generated nine master faces capable of representing 40 per cent of the population that bypassed “three leading deep face recognition systems.” At first glance, it seems impressive and the claims pose clear security risks in applications that require facial identification.

[2]

First, the team employed Nvidia’s [3]StyleGAN system to create realistic-looking images of made-up faces. Each fake output was compared to one real photograph of the 5,749 different people represented in the Labeled Faces in the Wild (LFW) dataset. A separate classifier algorithm determines how similar the fake AI-generated faces look compared to the real ones in the dataset.

[4]

[5]

Images that score highly for similarity by the classifier are kept, and the others are discarded. These scores are used to train an evolutionary algorithm to create more and more spoof faces using StyleGAN that look like the people in the dataset.

[6]Regulating facial recognition technology? It's the 'Wild West out there,' says US law boffin

[7]Peers question experts over UK police use of AI, facial recognition tech

[8]Teen turned away from roller rink after AI wrongly identifies her as banned troublemaker

[9]20,000 proteins expressed by human genome predicted by DeepMind's AlphaFold now available to download

Over time, the researchers are able to find a set of master faces that represent as many of the images they can in the dataset. In short, they were able to come up with just nine images to represent 40 per cent of the 5,749 different people in the Labeled Faces in the Wild dataset.

Next, they used these master faces to spoof three face different facial recognition models: Dlib, FaceNet, and SphereFace. These systems ranked most highly in the contest that benchmarks the best face matching algorithms tested on the LFW dataset.

A quick look at the highest-scoring master faces capable of bypassing each of the three models, however, shows a clear limitation in the research. They’re pretty much all fake images of older Caucasian men, donning white hair, glasses, and mustaches. If these same types of images are able to represent a large population of the LFW dataset then surely the dataset must be somewhat flawed.

The best master face that was able to trick Dlib (left), FaceNet (middle), and SphereFace (right). Taken from Figure 4 in the paper.

Garbage in, garbage out

A disclaimer posted on the [10]website hosting the dataset confirms this: “Many groups are not well represented in LFW. For example, there are very few children, no babies, very few people over the age of 80, and a relatively small proportion of women. In addition, many ethnicities have very minor representation or none at all.”

The scores of the nine master faces reflect the limitations of the LFW dataset. Faces that are female, darker in skin tone, and younger are ranked lower and less likely to bypass the three models that were tested.

The nine master faces that represent 40 per cent of the LFW dataset. Notice how the scores are lower for people who are younger, female, or have darker skin tones. Taken from Figure 5 of the paper.

“While theoretically LFW could be used to assess performance for certain subgroups, the database was not designed to have enough data for strong statistical conclusions about subgroups. Simply put, LFW is not large enough to provide evidence that a particular piece of software has been thoroughly tested,” according to another disclaimer listed on the LFW’s website.

Although the idea of master faces capable of impersonating a vast proportion of peoples faces to unlock face recognition systems is interesting, the research here is just another case of a machine learning model trained and tested using flawed data. Garbage in, garbage out, as they say.

[11]

There is a lack of diversity in the LFW dataset, so the computer-generated master faces are more likely to cover a larger proportion of that dataset. It’s unlikely that these images would work as well in the real world.

And no real-world tests

“LFW indeed suffers from the limitations described in its official website, but in spite of these limitations, LFW is a widely used dataset in the academic literature for evaluating face recognition methods,” Tomer Friedlander, co-author of the paper and a researcher at the School of Electrical Engineering at Tel Aviv University, told The Register .

“Our paper presents a possible vulnerability of face recognition systems, which can be exploited by attackers. Therefore, it should be taken into consideration by both developers and users of face recognition methods. We have not tested our method against commercial face recognition systems, which are used in real life, so we cannot refer to systems in real life.”

It’s possible to adapt the model to better datasets that are more diverse to try and trick systems in the real world, he said. “We are interested in further exploring the possibility of using the master faces generated by our method in order to help protect existing facial recognition systems from such attacks. We leave this for future research.”

Don’t fall for the scaremongering headlines claiming these master faces can break into [12]“over 40 per cent of facial ID authentication systems” or that they’re [13]“wildly successful” . There’s little evidence to support those claims.

[14]

Friedlander told us the paper has been accepted into this year’s [15]IEEE International Conference on Automatic Face & Gesture Recognition conference to be held in December. ®

Get our [16]Tech Resources



[1] https://arxiv.org/abs/2108.01077

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRJOWpCeJW0mXzoPBVHg-AAAAE8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2018/12/14/ai_created_photos/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRJOWpCeJW0mXzoPBVHg-AAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRJOWpCeJW0mXzoPBVHg-AAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/07/15/us_facial_recognition_technology_regulation/

[7] https://www.theregister.com/2021/07/21/peers_review_role_of_tech/

[8] https://www.theregister.com/2021/07/16/facial_recognition_failure/

[9] https://www.theregister.com/2021/07/26/in_brief_ai/

[10] http://vis-www.cs.umass.edu/lfw/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRJOWpCeJW0mXzoPBVHg-AAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.unite.ai/master-faces-that-can-bypass-over-40-of-facial-id-authentication-systems/

[13] https://gizmodo.com/master-face-researchers-say-theyve-found-a-wildly-succ-1847420710

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRJOWpCeJW0mXzoPBVHg-AAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] http://iab-rubric.org/fg2021/

[16] https://whitepapers.theregister.com/



A poor justification

Mike 137

" ... in spite of these limitations, LFW is a widely used dataset in the academic literature ... "

I find this increasingly in non-outstanding scientific papers - reliance on "previous work" rather than employing methods and data sets specifically selected to further the ostensible objective - it's particularly common in statistical analyses, where often quite inappropriate methods are employed.

Unless this work was specifically intended to compare the method under test with other methods applied to the same data set, the only obvious justifications for using a data set with a significant recognised deficiency could be "it's available" or "it improves our chances of passing peer review". Neither is unduly conducive to production of convincing results.

Be careful what you look like

Tony W

OK the research is flawed and alarmist - but the basic idea looks as if it could be feasible so long as you are content to target a limited group of the population.

This highlights the fact that biometrics must be really good if it's to be used for anything important.

Re: Be careful what you look like

Pascal Monett

What the research really demonstrates is that, in our AI future, if you're white, you're screwed because everything will recognize you.

You want privacy and security ?

Better off coloured.

“three leading deep face recognition systems”

Pascal Monett

Deep face ? What the hell is that expression for ?

I get deep fake. Statistical analysis applied to creating an image (or video) and inserting another one. Okay, that's fine.

But there is no deep face. There is facial recognition, period.

Stop gargling yourselves with meaningless verbiage just to make you seem capable.

Biased Sample Group

TheInquisitor

TBF the sample group is biased, however biased correctly for impersonating the most high value access.

Sad but true: old white dude have the most access.

Seems like the entire dissent here hinges on only being proven effective with a biased sample group. That biased group however, happens to be the most likely to group to have highest levels of access.

The point of the study was that it's a clearly proven attack vector. You challenge other authors for sensationalizing their headlines that contradict yours, when you've clearly done the exact same. But then you even picked a very narrow, irrelevant, lane to challenge the research on.

The worst you can really say is that more work would need to be done, in order to impersonate non old white dudes... But if old white dudes hold most of the power... Why would attackers need to even bother?

I think you missed the point entirely, which is why your headline and content look nothing like the other articles.

Prime Time

elsergiovolador

So these technologies are not yet ready for prime time and yet somehow the sales people managed to convince barely literate people in power that they can fulfil their authoritarian fantasies. How is that not considered as a scam?

Biometrics for authentication

Filippo

Why are we using biometrics for authentication? Honest question. It's like a password that you cannot change, and that you leave everywhere you go. How is that a good idea?

If you think last Tuesday was a drag, wait till you see what happens tomorrow!