공격 · 점수만으로 얼굴을 복원하다Attack · Reconstructing a face from scores alone
인식 시스템은 "이 두 이미지가 얼마나 닮았나"를 점수로 돌려줍니다. 기존 공격은 대부분 모델의 gradient를 따라 픽셀을 조금씩 바꾸거나, 점수를 보고 다음 질문을 고르는 adaptive 방식으로 수만 번을 묻습니다. 우리 공격은 경사하강법을 전혀 쓰지 않습니다. 질문을 전부 미리 정해 두는 non-adaptive 방식으로, 사진 몇 장과 한 번의 일괄 질의만으로 점수의 구조에서 곧바로 대상의 얼굴을 복원하거나, 노이즈 없는 자연스러운 사칭 이미지를 만들어 냅니다. Amazon Rekognition, Tencent 같은 상용 API에서도 성공했습니다. A recognizer returns a score for "how similar are these two images?". Most prior attacks either follow the model's gradient, nudging pixels step by step, or are adaptive: tens of thousands of queries, each chosen after seeing the last score. Our attacks use no gradient descent at all. They are non-adaptive, fixing every query up front, and with a handful of images and a single batch query they reconstruct a target's face straight from the structure of the scores, or generate a perturbation-free impersonation image. They succeed against commercial APIs such as Amazon Rekognition and Tencent.
핵심은 표현 공간의 구조입니다. 구면 위에는 identity와 관련된 속성이 변하는 저차원 방향들이 있고, 이 구조를 알면 gradient 없이도 놀랄 만큼 적은 정보로 충분합니다. 같은 틀은 얼굴을 넘어 화자 인식, 손바닥 인식, 금융 본인확인 시스템으로 확장되고, 생체 템플릿 보호 기법 자체를 되돌리는 안전성 분석(BMVC 2023)으로도 이어집니다. The key is the structure of the representation space: low-dimensional directions along which identity varies. Once that structure is known, surprisingly little information suffices, and no gradients are needed. The same framework carries over to speaker recognition, palmprints, and the identity-verification stacks used in finance, and to reversing biometric template protection schemes themselves (BMVC 2023).