Skilled Impostor Attacks Against Fingerprint Verification Systems And Its Remedy
Carsten Gottschlich

TL;DR
This paper introduces a new skilled impostor attack against fingerprint verification systems, revealing that traditional evaluation methods underestimate vulnerabilities, and proposes a new protocol for more accurate performance assessment applicable to various biometric systems.
Contribution
The study presents a novel skilled impostor attack method and a new evaluation protocol that better assesses biometric system security and usability trade-offs.
Findings
Active attackers can succeed with over 89% probability against systems tuned at 0.1% false acceptance rate
Traditional evaluation protocols underestimate fingerprint system vulnerabilities
The proposed protocol is applicable to multiple biometric modalities
Abstract
Fingerprint verification systems are becoming ubiquitous in everyday life. This trend is propelled especially by the proliferation of mobile devices with fingerprint sensors such as smartphones and tablet computers, and fingerprint verification is increasingly applied for authenticating financial transactions. In this study we describe a novel attack vector against fingerprint verification systems which we coin skilled impostor attack. We show that existing protocols for performance evaluation of fingerprint verification systems are flawed and as a consequence of this, the system's real vulnerability is systematically underestimated. We examine a scenario in which a fingerprint verification system is tuned to operate at false acceptance rate of 0.1% using the traditional verification protocols with random impostors (zero-effort attacks). We demonstrate that an active and intelligent…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBiometric Identification and Security · User Authentication and Security Systems · Advanced Steganography and Watermarking Techniques
