Tsinghua University has developed glasses Which Can crack face recognition technology in 15 minutes, and open bank accounts online
Some of the simple printed out sample
Face recognition technology is now very common, whether it is on mobile phones or any other things, more or less we will see the use of face recognition, but while we enjoy the convenience, will we accidentally ignore the safety problem? Although mobile phone manufacturers express facial recognition technology, they always say that the probability of cracking facial recognition is as low as one in a million, but occasionally there are news that twins can open their phones to each other. This loophole also shows that people Face recognition is not absolutely safe.
Recently, the RealAI team from Tsinghua University demonstrated a face recognition that cracked mobile phones in an ultra-simple way. Among them, 19 mobile phones were not spared, all successfully cracked face recognition within 15 minutes.
This steps just require a printer and a glasses
Throughout the testing process, RealAI selected a total of 20 different mobile phones, except for one iPhone 11, the rest are all Android models. At the beginning of the test, these 20 mobile phones were all uniformly entered with the same person’s face (hereinafter referred to as the attached person) to verify information, and the person who tested the face recognition technology (hereinafter referred to as the attacker) put on one A4 printer, a piece of A4 paper and a pair of glasses framed glasses with patterns against the sample.
In the end, after wearing glasses with counter-samples, all Android models except iPhone 11 were successfully unlocked. Moreover, after unlocking, the attacker also arbitrarily browses various privacy such as the content of the mobile phone, and even completes the account opening through the online identity authentication of the personal APP such as the bank in the mobile phone. In the whole process of cracking face recognition, it only took about 15 minutes.
How did the glasses with adversarial samples complete? As mentioned in the third paragraph, only a printer, a sheet of A4 paper and a pair of glasses frames are required. Then, after getting the face photo of the victim, the algorithm generates interference patterns in the eye area, and then prints out and crops the shape of “glasses” and pastes it on the frame for the attacker to wear.
It can simply used to crack open any phone security
The algorithm staff said that this is a perturbation pattern generated by algorithm calculation by combining the image of the attacker and the image of the attacked person. It is called “adversarial sample” in the AI academic community, so it has the title of the above-mentioned adversarial sample glasses. This is to set the attacker’s image as the input value and the attacker’s image as the output value. The algorithm will automatically calculate the best confrontation sample pattern to ensure that the similarity of the two images reaches the highest value.
In this way, we can see that unlocking the phone is only the first step. After that, I also saw the bank account opening completed online with the identity of the attacked person. Does that mean that the money will be transferred next?
Of course, face recognition can also add a template to check adversarial samples in the authentication process to prevent interested persons from using adversarial samples to crack face recognition technology and embezzle other people’s information.
This are the steps, as easy as that