GAN-generated facial images that are capable of impersonating multiple IDs
unite.ai
unite.ai
As it turns out, that _is_ another feature of high-dimensional geometry. The details depend on how many dimensions your images have, the similarity metric being used, how big your database, is, ....
For a brief illustration, consider standard euclidean space. If your images have D dimensions, ignoring some pathological cases you can find a point equidistant from D+1 of them (and if you have more dimensions to work with you have a lot of points to choose from). If D+1 < (40% of database) then you've accomplished your goal.
Note: It is possible for such a point to be arbitrarily far from the rest of your database (in context, that it would look nothing like a face). Spare dimensions can give you enough freedom to place it "in the middle" of your database in some sense, not just some point in the middle of nowhere that's an equally bad match for everything.
I've used DLib very extensively in the wild. It's fast, has decent python integration and is easy to use.
But it get confused pretty easily. I've had even the CNN model confuse a blurry photo of a clock for a face.
It's useful enough to build facial recognizers that mostly work ok. But if you are using it for a facial authentication system... it's a pretty bad idea to say the least.
Turns out to actually mean "three CNN-based face descriptors: SphereFace, FaceNet and Dlib", which best I can tell are two academic projects and an open-source library.
By far the largest deployed facial authentication system is of course Face ID, which this has zero/zilch/no chance at all of working against.
What a terrible, terrible headline.
But to say it has no chance to work against Face ID is just saying YOU don't know how to make it work.
It is short sighted, to say it delicately.
An intelligent enough person will understand there are millions even more intelligent and highly motivated people and there is no way to be sure about what they can't do short of breaking physics laws.
All neural nets are vulnerable to adversarial examples. It's a fundamental property they hold, because they're essentially stacked linear models. So (for example) they get more confident about their predictions when given a sufficiently out-of-domain input - adversarial training is essentially just finding paths that trigger an out-of-domain response.
I don't see how an additional transformation before input precludes that.
Or do you mean attacking the inner network somehow from inside the system?
You don't need to produce the correct 3d surface if the surface recogniser is neural - you just need to produce a 3d surface that's adversarial. The adversarial surface could be completely unrealistic, like these adversarial images. (Although the adversarial generator could also be trained with "realism" as a constraint.)
Are they able to detect depth independent of the surface of a presented image? That would make it harder, but the point of failure then is just figuring out a way to dynamically fool them. I wouldn't be confident saying that's impossible.
Don't you think you are too enthusiastic saying 3D facial authentication cannot be fooled?
It is basically an exercise in projecting right image, something that already a large number of people are working on.
That is not what was said. The commenter stated that THIS 2D GAN method has no chance against FaceID, and if you understand the way FaceID works you would understand they are absolutely correct.
FaceID shines dots on the user’s face and measures the distortion of those dots across the facial topology. Using this method on a 2D surface will result in no distortion, and therefore fail.
I am responding to this comment:
"By far the largest deployed facial authentication system is of course Face ID, which this has zero/zilch/no chance at all of working against."
"zero", "zilch", "no chance" -- suggest overconfidence to me. This is not healthy when discussing any authentication system and especially one based on trained model where we don't exactly understand relation between input and output.
So his statement is entirely correct. This model has absolutely no chance of fooling the current most popular facial detection system.
It creates a key that doesn't even fit in the lock, much less have the correct pin heights.
If your point is that this approach and architecture might contribute to a model that can beat FaceID, that's entirely valid to say as well.
Don't you think you are too enthusiastic saying 3D facial authentication cannot be fooled?
Where did I say that?
>I’m not sure what demographic I fitted, but I am glad I have left it.
I think you already got it figured.
The older I get the more every authority figure everywhere leaves me alone. I was probably more 'innocent' as a teenager, though.
The less the world in general messes with me, and it's by far the best thing about getting older.
I never stole anything, but I never worked at Nordstrom so who the hell am I to judge.
Amazing the difference cutting your hair short and not wearing band shirts changes things =/
(Would like to say I'm incredibly lucky in this regard as I'm a white male).
Now all we really need to do is print copies of these faces and drop em all over China.
It seems to me that this "just" expands the parameter space as a way to make defeating the algorithm much harder. I don't see how, in principle, that makes Face ID invulnerable to this type of attack.
Given that Face ID is only accessible using Apple devices which lock-up after a number of failed attempts, training a sufficiently sophisticated GAN might be problematic. But a motivated attacker might, for example, use a device farm or a reverse-engineered implementation of Face ID.
a) defeat Face ID
b) look like the result of a horrific teletransporter accident.
[1] https://www.apple.com/business-docs/FaceID_Security_Guide.pd... (page 3)
I’ve read it before but hadn’t recalled that detail about the randomized layout. TIL!
Face ID disables itself after 5 failed attempts, falling back to a password. In my experience, if you point it at something that’s definitely not a real face (but looks like one), it disables immediately.
Can someone tell me more about this? What various "brands"? I know only the scipy package.
[0] https://www.wired.com/story/flawed-facial-recognition-system...
I hate how phones have made posts on the web so incomprehensible, but I usually double check