Casting the Net! Revisiting MasterFace Impersonation Attacks

📅 2026-08-07
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work demonstrates, for the first time, that targeted MasterFace attacks can be constructed against commercial face recognition APIs using only legitimate API access, under the realistic constraint of a limited number of black-box verification attempts and without any internal knowledge of the system. The attack is formulated as a maximum coverage problem in the biometric embedding space (NET), leveraging geometric analysis of the embedding manifold combined with adversarial sample optimization. Within at most 30 attempts, the method achieves impersonation success rates up to 9.5 times higher than the baseline false match rate (FMR) across multiple open-source and commercial APIs, substantially violating conventional security assumptions and exposing critical blind spots in downstream applications.
📝 Abstract
Impersonation is a fundamental security threat in face recognition systems (FRSs). While the security of FRSs has been challenged by various attack vectors, under realistic adversarial capabilities, e.g., a limited number of decision-only authentication trials and no internal system knowledge, most attack techniques become infeasible. As a result, impersonation by zero-effort impostors, characterized by false match rate (FMR), is commonly regarded as a standalone baseline. A few years ago, impersonation attacks based on MasterFaces emerged as a notable security threat that could break the barrier of the FMR-based baseline under such realistic constraints. However, they were believed not to yield impersonation above the standard FMR in modern FRSs, as discussed by multiple follow-up studies. In this paper, we demonstrate that even legitimate access to public commercial APIs allows an adversary to amplify impersonation rates through MasterFaces, resulting in a non-trivial impersonation attack beyond FMR on downstream applications built on top of these APIs. We observe that several real-world FRS deployments are implemented using commercial APIs, and that the backend service provider is publicly disclosed or trivially inferable. As a result, the adversary can purchase these pay-as-you-go API services without requiring any additional privilege over the target FRS. From this observation, we formalize the MasterFaces attack as a maximum coverage problem over the biometric representation space, which we call a NET, and show that the adversary can construct an API-tailored NET by leveraging the geometric structure of the representation space. We demonstrate that our attack amplifies the impersonation rates of several open-source and commercial API-based FRSs by up to 9.5$\times$ within at most 30 authentication trials, compared to those expected from the standard FMR.
Problem

Research questions and friction points this paper is trying to address.

Impersonation
MasterFace
Face Recognition Systems
False Match Rate
Adversarial Attack
Innovation

Methods, ideas, or system contributions that make the work stand out.

MasterFace
impersonation attack
face recognition security
maximum coverage problem
biometric representation space
🔎 Similar Papers
No similar papers found.