Facial recognition systems are beginning to be everywhere controlling access to restricted areas, but they still have weak points. With this trick we can trick the system into thinking that we are someone else.
The research teams of cybersecurity companies like McAfee They not only deal with fixing security gaps or defeating hackers’ attacks, they are also ahead of their movements and looking for those breaches. That is what this team has done with a facial recognition system.
Systems like this are found in airports, at the entrances to offices or centers where it is necessary to control who has access. Investigators have engineered an attack to fool the program that could be used at an airport to search passengers’ passports. The objective is that the system identify an individual as another who did have permission to access and thus be able to sneak in.
To do this, an image translation algorithm has been used, the CycleGAN. He is a specialist in transform real images with another styleFor example, you can turn a photograph of a port into what might be mistaken as a painting by Monet. He is also capable of disguising horses into zebras or transforming a summer image of a mountain range into a snow-covered winter postcard.
With this tool, as shown in this video, the McAfee team used 1,500 photos of the two potential faces they wanted to work with to fool the facial recognition system. CycleGAN mixed these images until getting a different but similar face that the airport algorithm could not detect. Finally the algorithm identified person A as passenger B and the alarms did not go off.
We must not put our hands to our heads, from McAfee they assure that an attack of this type on an airport is very complicated. The investigators at no time had access to a real system that controls airports and transportation stations, instead used a similar open source algorithm.
Could a similar attack work on a real facial recognition system? Yes, but for this they warn that it is necessary to have great resources and a lot of time. Programs like CycleGAN require very powerful computers and professionals with a lot of experience.a on the subject in order to get results.
Some taxis in Japan have in the back (where the passenger sits), a tablet that is capable of doing facial recognition to estimate our gender, age and other characteristics.
The McAfee team simply wants warn about vulnerabilities in facial recognition systems and, therefore, the need for a greater investment with which to improve them and keep them up to date against possible attacks. “Artificial intelligence and facial recognition are incredibly powerful tools to help in the process of identifying and authorizing people,” he explained. Steve Povolny, Studio Director. “But when they are simply used to blindly replace an existing system that is completely dependent on a human without having some kind of secondary control, then a greater weakness is introduced than it was before.”