IP Library › Granted Patent US 12,069,047
Granted Patent B2
US 12,069,047 · App. 17/951,864 · Granted Aug 20, 2024

Using an enrolled biometric dataset to detect adversarial examples in biometrics-based authentication system

Inventors: Yuhang Wu (Foster City, CA); Sunpreet Singh Arora (San Mateo, CA); Hao Yang (San Jose, CA)
Assignee: VISA INTERNATIONAL SERVICE ASSOCIATION
H04L63/0861G06N3/04G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,069,047
App. No.
17/951,864
Granted
Aug 20, 2024
Kind
B2
Abstract

Training an adversarial perturbation detector comprises accessing a training set comprising an enrolled biometric sample x i and a public biometric sample x of an enrolled user, and submitted biometric samples x′ of a second user, the submitted biometric samples x′ comprising perturbed adversarial samples x′+Δx′. A transformation function k(⋅) is provided having learnable a parameter θ and a classifier having a learnable parameter σ. The training set is used to learn the parameters θ and σ by inputting the training set to the transformation function k(⋅). The transformation function k(⋅) generates transformed enrolled samples k(x i ), a transformed public biometric sample k(x), and a transformed adversarial sample k(x′+Δx′). The classifier classifies the transformed adversarial sample k(x′+Δx′) as a success or as a fail based on the transformed enrolled samples k(x i ). Based on a result of the classification, the learnable parameters θ and σ are updated.

Claims (64)

1. A method of training an adversarial perturbation detector, the method comprising:

accessing from a storage device a training set comprising an enrolled biometric sample x i and a public biometric sample x of an enrolled user, and submitted biometric samples x′ of a second user, the submitted biometric samples x′ comprising perturbed adversarial samples x′+Δx′;

providing a transformation function k(⋅) having learnable a parameter θ and a classifier having a learnable parameter σ;

using the training set to learn the parameters θ and σ by inputting the training set to the transformation function k(⋅);

generating, by the transformation function k(⋅), transformed enrolled samples k(x i ), a transformed public biometric sample k(x), and a transformed adversarial sample k(x′+Δx′);

classifying, by the classifier with the learnable parameter σ, the transformed adversarial sample k(x′+Δx′) as a success or as a fail based on the transformed enrolled samples k(x i ); and

based on a result of the classification, updating the learnable parameters θ and σ.

2. The method of claim 1 further including improving security of a biometrics-based authentication system by:

receiving, by one or more servers, enrolled biometric samples x i of an enrolled user during an enrollment stage of the biometrics-based authentication system;

applying a function f(⋅) to the enrolled biometric samples x i to generate a biometric template f(x i );

creating, by the one or more servers, augmented biometric samples by adding perturbations to the enrolled biometric samples of the enrolled user;

receiving, by the one or more servers, during a request for authentication, submitted biometric samples x′ from a second user;

applying the function f(⋅) to the submitted biometric samples x′ to generate a biometric template f(x′);

comparing, by the one or more servers, the submitted biometric samples of the second user to the enrolled biometric samples and to the augmented biometric samples of the enrolled user based on predefined metrics by:

computing a distance between the biometric template f(x i ) of the enrolled user with the biometric template f(x′), and

responsive to determining that the distance is less than a first threshold, temporarily authorizing the request for authentication; and

based on the comparison, determining, by the one or more servers, that the submitted biometric samples of the second user have been modified to impersonate the enrolled user.

3. The method of claim 2 , further comprising: storing the enrolled biometric samples x i , the biometric template f(x i ) and the augmented biometric samples as an enrolled biometric dataset.

4. The method of claim 2 , wherein determining that the submitted biometric samples of the second user have been modified is activated only in response to the request for authentication being temporarily authorized.

5. The method of claim 4 , further comprising:

responsive to the request for authentication being temporarily authorized, receiving, by an adversarial perturbation detector, the enrolled biometric samples x i of the enrolled user and the submitted biometric samples of the second user, where the submitted biometric samples comprise perturbed adversarial samples x′+Δx′; and

responsive to detecting any perturbations, rejecting the request for authentication of the second user, and otherwise, granting the request for authentication and authorizing the second user.

6. The method of claim 5 , wherein determining that any perturbations are detected further comprises:

applying the transformation function k(⋅) to both the enrolled biometric samples x i and the perturbed adversarial samples x′+Δx′ to generate transformed enrolled samples k(x i ) and transformed adversarial sample k(x′+Δx′), which are in a transformed subspace;

computing a distance F between the transformed enrolled samples k(x i ) and the transformed adversarial sample k(x′+Δx′) in the transformed subspace; and

determining the transformed adversarial sample k(x′+ΣΔx′) is adversarial when the distance F is greater than a second threshold t′ indicating that one or more perturbations have been detected.

7. The method of claim 6 , wherein the enrolled biometric samples x i include augmented biometric samples x i ′ such that the enrolled biometric samples xi=[xi, xi′], and wherein the x i and x i ′ of the enrolled biometric samples are input to the transformation function k(⋅) using one of a parallel model and a sequential model.

8. A non-transitory computer readable medium having stored thereon software instructions that, when executed by a processor, cause the processor to train an adversarial perturbation detector, the instructions comprising:

accessing from a storage device a training set comprising an enrolled biometric sample x i and a public biometric sample x of an enrolled user, and submitted biometric samples x′ of a second user, the submitted biometric samples x′ comprising perturbed adversarial samples x′+Δx′;

providing a transformation function k(⋅) having learnable a parameter θ and a classifier having a learnable parameter σ;

using the training set to learn the parameters θ and σ by inputting the training set to the transformation function k(⋅);

generating, by the transformation function k(⋅), transformed enrolled samples k(x i ), a transformed public biometric sample k(x), and a transformed adversarial sample k(x′+Δx′);

classifying, by the classifier with the learnable parameter σ, the transformed adversarial sample k(x′+Δx′) as a success or as a fail based on the transformed enrolled samples k(x i ); and

based on a result of the classification, updating the learnable parameters θ and σ.

9. The non-transitory computer readable medium of claim 8 further comprising instructions for improving security of a biometrics-based authentication system by:

receiving, by one or more servers, enrolled biometric samples x i of an enrolled user during an enrollment stage of the biometrics-based authentication system;

applying a function f(⋅) to the enrolled biometric samples x; to generate a biometric template f(x i );

creating, by the one or more servers, augmented biometric samples by adding perturbations to the enrolled biometric samples of the enrolled user;

receiving, by the one or more servers, during a request for authentication, submitted biometric samples x′ from a second user;

applying the function f(⋅) to the submitted biometric samples x′ to generate a biometric template f(x′);

comparing, by the one or more servers, the submitted biometric samples of the second user to the enrolled biometric samples and to the augmented biometric samples of the enrolled user based on predefined metrics by:

computing a distance between the biometric template f(x i ) of the enrolled user with the biometric template f(x′), and

responsive to determining that the distance is less than a first threshold, temporarily authorizing the request for authentication; and

based on the comparison, determining, by the one or more servers, that the submitted biometric samples of the second user have been modified to impersonate the enrolled user.

10. The non-transitory computer readable medium of claim 9 , further comprising: storing the enrolled biometric samples x i , the biometric template f(x i ) and the augmented biometric samples as an enrolled biometric dataset.

11. The non-transitory computer readable medium of claim 8 , wherein determining that the submitted biometric samples of the second user have been modified is activated only in response to the request for authentication being temporarily authorized.

12. The non-transitory computer readable medium of claim 11 , further comprising:

responsive to the request for authentication being temporarily authorized, receiving, by an adversarial perturbation detector, the enrolled biometric samples x i of the enrolled user and the submitted biometric samples of the second user, where the submitted biometric samples comprise perturbed adversarial samples x′+Δx′; and

responsive to detecting any perturbations, rejecting the request for authentication of the second user, and otherwise, granting the request for authentication and authorizing the second user.

13. The non-transitory computer readable medium of claim 12 , wherein determining that any perturbations are detected further comprises:

applying the transformation function k(⋅) to both the enrolled biometric samples x i and the perturbed adversarial samples x′+Δx′ to generate transformed enrolled samples k(x i ) and a transformed adversarial sample k(x′+Δx′), which are in a transformed subspace;

computing a distance F between the transformed enrolled samples k(x i ) and the transformed adversarial sample k(x′+Δx′) in the transformed subspace; and

determining the transformed adversarial sample k(x′+ΣΔx′) is adversarial when the distance F is greater than a second threshold t′ indicating that one or more perturbations have been detected.

14. The non-transitory computer readable medium of claim 13 , wherein the enrolled biometric samples x i include augmented biometric samples xi′ such that the enrolled biometric samples xi=[xi, xi′], and wherein the x i and x i ′ of the enrolled biometric samples are input to the transformation function k(⋅) using one of a parallel model and a sequential model.

15. A system, comprising:

a memory;

a processor coupled to the memory; and

a software component executed by the processor that is configured to:

access from a storage device a training set comprising an enrolled biometric sample x i and a public biometric sample x of an enrolled user, and submitted biometric samples x′ of a second user, the submitted biometric samples x′ comprising perturbed adversarial samples x′+Δx′;

provide a transformation function k(⋅) having learnable a parameter θ and a classifier having a learnable parameter σ;

use the training set to learn the parameters θ and σ by inputting the training set to the transformation function k(⋅);

generate, by the transformation function k(⋅), transformed enrolled samples k(x i ), a transformed public biometric sample k(x), and a transformed adversarial sample k(x′+Δx′);

classify, by the classifier with the learnable parameter σ, the transformed adversarial sample k(x′+Δx′) as a success or as a fail based on the transformed enrolled samples k(x i ); and

based on a result of the classification, updating the learnable parameters θ and σ.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: WU, YUHANG; ARORA, SUNPREET SINGH; YANG, HAO
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 061198/0288 →
Continuity (2)
Continuation 16685203 · Nov 15, 2019
Related Publication 20230012235A1 · Jan 12, 2023
Cited By (1)
US 12,736,933