skip to main content
10.1145/3560830.3563722acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
research-article

Video is All You Need: Attacking PPG-based Biometric Authentication

Published: 07 November 2022 Publication History

Abstract

Unobservable physiological signals enhance biometric authentication systems. Photoplethysmography (PPG) signals are convenient owing to its ease of measurement and are usually well protected against remote adversaries in authentication. Any leaked PPG signals help adversaries compromise the biometric authentication systems, and the advent of remote PPG (rPPG) enables adversaries to acquire PPG signals through restoration. While potentially dangerous, rPPG-based attacks are overlooked because existing methods require the victim's PPG signals. This paper proposes a novel spoofing attack approach that uses the waveforms of rPPG signals extracted from video clips to fool the PPG-based biometric authentication. We develop a new PPG restoration model to accomplish adversarial attacks without leaked PPG signals. Empirical study results on state-of-art PPG-based biometric authentication show that the signals recovered through rPPG pose a severe threat to PPG-based biometric authentication.

Supplementary Material

MP4 File (AISec22-025.mp4)
Presentation video for paper Video is All You Need: Attacking PPG-based Biometric Authentication.

References

[1]
Dwaipayan Biswas, Luke Everson, Muqing Liu, Madhuri Panwar, Bram-Ernst Verhoef, Shrishail Patki, Chris H. Kim, Amit Acharyya, Chris Van Hoof, Mario Konijnenburg, and Nick Van Helleputte. 2019. CorNET: Deep learning framework for PPG-based heart rate estimation and biometric identification in ambulant environment. IEEE Transactions on Biomedical Circuits and Systems, Vol. 13, 2 (2019), 282--291.
[2]
Giuseppe Boccignone, Donatello Conte, Vittorio Cuculo, Alessandro D'Amelio, Giuliano Grossi, and Raffaella Lanzarotti. 2020. An open framework for remote-PPG methods and their assessment. IEEE Access, Vol. 8 (2020), 216083--216103.
[3]
Alejandro Calleja, Pedro Peris-Lopez, and Juan E. Tapiador. 2015. Electrical heart signals can be monitored from the moon: Security implications for IPI-based protocols. In Proceedings of the Information Security Theory and Practice, Raja Naeem Akram and Sushil Jajodia (Eds.), Vol. 9311. Springer International Publishing, Cham, 36--51.
[4]
Utkarsh Chauhan, Norbert Reithinger, and John R Mackey. 2018. Real-time stress assessment through PPG sensor for VR biofeedback. In Proceedings of the 20th International Conference on Multimodal Interaction: Adjunct. 1--5.
[5]
Weixuan Chen and Daniel McDuff. 2018. Deepphys: Video-based physiological measurement using convolutional attention networks. In Proceedings of the European Conference on Computer Vision (ECCV). 349--365.
[6]
Shuo Cheng, Yongxin Chou, Jicheng Liu, Ya Gu, and Xufeng Huang. 2019. A novel identity authentication method by modeling Photoplethysmograph waveform. In Proceedings of the International Conference on Control, Automation and Information Sciences (ICCAIS). IEEE, 1--5.
[7]
Ivana Chingovska, Andre Rabello Dos Anjos, and Sebastien Marcel. 2014. Biometrics evaluation under spoofing attacks. IEEE Transactions on Information Forensics and Security, Vol. 9, 12 (2014), 2264--2276.
[8]
Gerard De Haan and Vincent Jeanne. 2013. Robust pulse rate from chrominance-based rPPG. IEEE Transactions on Biomedical Engineering, Vol. 60, 10 (2013), 2878--2886.
[9]
Ruggero Donida Labati, Vincenzo Piuri, Francesco Rundo, Fabio Scotti, and Concetto Spampinato. 2021a. Biometric recognition of PPG cardiac signals using transformed spectrogram images. In Proceedings of the ICPR International Workshops and Challenges on Pattern Recognition. Springer International Publishing, Cham, 244--257.
[10]
Ruggero Donida Labati, Vincenzo Piuri, Francesco Rundo, Fabio Scotti, and Concetto Spampinato. 2021b. Biometric recognition of PPG cardiac signals using transformed spectrogram images. In Proceedings of the ICPR Workshop on Mobile and Wearable Biometrics (WMWB), Vol. 12668. Springer, 244--257.
[11]
Y.Y. Gu, Y. Zhang, and Y.T. Zhang. 2003. A novel biometric approach in human verification by photoplethysmographic signals. In Proceedings of the 4th International IEEE EMBS Special Topic Conference on Information Technology Applications in Biomedicine. 13--14.
[12]
Ishaan Gulrajani, Faruk Ahmed, Martin Arjovsky, Vincent Dumoulin, and Aaron Courville. 2017. Improved training of wasserstein GANs. In Proceedings of the 31st International Conference on Neural Information Processing Systems. 5769--5779.
[13]
James Hensman, Nicolò Fusi, and Neil D Lawrence. 2013. Gaussian processes for Big data. In Proceedings of the 29th Conference on Uncertainty in Artificial Intelligence. 282--290.
[14]
Guillaume Heusch, André Anjos, and Sébastien Marcel. 2017. A reproducible study on remote heart rate measurement. arXiv preprint arXiv:1709.00962 (2017).
[15]
Shun Hinatsu, Daisuke Suzuki, Hiroki Ishizuka, Sei Ikeda, and Osamu Oshiro. 2021. Attack on PPG Biometrics: Presentation Attack by Stealth Recording and Waveform Estimation. In Proceedings of the 43rd Annual International Conference of the IEEE Engineering in Medicine & Biology Society (EMBC). IEEE, 64--67.
[16]
Po-Wei Huang, Bing-Jhang Wu, and Bing-Fei Wu. 2021. A heart rate monitoring framework for real-world drivers using remote photoplethysmography. IEEE Journal of Biomedical and Health Informatics, Vol. 25, 5 (2021), 1397--1408.
[17]
Yuwen Huang, Gongping Yang, Kuikui Wang, Haiying Liu, and Yilong Yin. 2022. Robust Multi-feature Collective Non-Negative Matrix Factorization for ECG Biometrics. Pattern Recognition, Vol. 123 (2022), 108376.
[18]
Dae Yon Hwang, Bilal Taha, and Dimitrios Hatzinakos. 2021a. Variation-Stable fusion for PPG-Based biometric system. In Proceedings of the International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 8042--8046.
[19]
Dae Yon Hwang, Bilal Taha, Da Saem Lee, and Dimitrios Hatzinakos. 2021b. Evaluation of the time stability and uniqueness in PPG-based biometric system. IEEE Transactions on Information Forensics and Security, Vol. 16 (2021), 116--130.
[20]
Anil K Jain, Arun Ross, and Salil Prabhakar. 2004. An introduction to biometric recognition. IEEE Transactions on circuits and systems for video technology, Vol. 14, 1 (2004), 4--20.
[21]
Jawahar Jain, Vatche A Attarian, Sajid Sadi, and Pranav Mistry. 2021. Real time authentication based on blood flow parameters. US Patent 11,064,893.
[22]
Nima Karimian. 2019. How to attack PPG biometric using adversarial machine learning. In Proceedings of the Autonomous Systems: Sensors, Processing, and Security for Vehicles and Infrastructure, Vol. 11009. International Society for Optics and Photonics, 1100909.
[23]
Nima Karimian, Zimu Guo, Mark Tehranipoor, and Domenic Forte. 2017. Human recognition from photoplethysmography (ppg) based on non-fiducial features. In Proceedings of the International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 4636--4640.
[24]
A. Reit Kavsaolu, Kemal Polat, and M. Recep Bozkurt. 2014. A novel feature ranking algorithm for biometric recognition with PPG signals. Computers in Biology and Medicine, Vol. 49 (2014), 1--14.
[25]
S Kolkur, D Kalbande, P Shimpi, C Bapat, and J Jatakia. 2016. Human skin detection using RGB, HSV and YCbCr color models. In Proceedings of the International Conference on Communication and Signal Processing. Atlantis Press, 324--332.
[26]
Magdalena Lewandowska, Jacek Rumi'nski, Tomasz Kocejko, and Jedrzej Nowak. 2011. Measuring pulse rate with a webcam -- a non-contact method for evaluating cardiac activity. In Proceedings of the Federated Conference on Computer Science and Information Systems. IEEE, 405--410.
[27]
Xin Liu, Josh Fromm, Shwetak Patel, and Daniel McDuff. 2020. Multi-Task Temporal Shift Attention Networks for On-Device Contactless Vitals Measurement. In Proceedings of the Advances in Neural Information Processing Systems, Vol. 33. Curran Associates, Inc., 19400--19411.
[28]
Giulio Lovisotto, Henry Turner, Simon Eberz, and Ivan Martinovic. 2020. Seeing red: PPG biometrics using smartphone cameras. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). IEEE, virtual, 3565--3574.
[29]
Hao Lu, Hu Han, and S Kevin Zhou. 2021. Dual-GAN: Joint BVP and noise modeling for remote physiological measurement. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 12404--12413.
[30]
Alexander G. de G. Matthews, Mark van der Wilk, Tom Nickson, Keisuke. Fujii, Alexis Boukouvalas, Pablo León-Villagrá, Zoubin Ghahramani, and James Hensman. 2017. GPflow: A Gaussian process library using TensorFlow. Journal of Machine Learning Research, Vol. 18, 40 (apr 2017), 1--6.
[31]
Rita Meziatisabour, Yannick Benezeth, Pierre De Oliveira, Julien Chappe, and Fan Yang. 2021. UBFC-Phys: A multimodal database for psychophysiological studies of social stress. IEEE Transactions on Affective Computing (2021). https://doi.org/10.1109/TAFFC.2021.3056960
[32]
Andreia V Mocc o, Sander Stuijk, and Gerard de Haan. 2018. New insights into the origin of remote PPG signals in visible light and infrared. Scientific Reports, Vol. 8, 1 (2018), 1--15.
[33]
Stephen Oung, Avrum Douglas Hollinger, Gregor Simeonov, and Abhishek Ranjan. 2020. Live user authentication device, system and method. US Patent App. 16/956,470.
[34]
Fabian Pedregosa, Gaël Varoquaux, Alexandre Gramfort, Vincent Michel, Bertrand Thirion, Olivier Grisel, Mathieu Blondel, Peter Prettenhofer, Ron Weiss, Vincent Dubourg, et al. 2011. Scikit-learn: Machine learning in Python. The Journal of Machine Learning Research, Vol. 12 (2011), 2825--2830.
[35]
Ming-Zher Poh, Daniel J McDuff, and Rosalind W Picard. 2010. Non-contact, automated cardiac pulse measurements using video imaging and blind source separation. Optics Express, Vol. 18, 10 (2010), 10762--10774.
[36]
Aditya Singh Rathore, Zhengxiong Li, Weijin Zhu, Zhanpeng Jin, and Wenyao Xu. 2020. A survey on heart biometrics. Comput. Surveys, Vol. 53, 6 (Dec. 2020), 1--38.
[37]
Ronald W Schafer. 2011. What is a Savitzky-Golay filter? IEEE Signal processing magazine, Vol. 28, 4 (2011), 111--117.
[38]
Fabian Schrumpf, Patrick Frenzel, Christoph Aust, Georg Osterhoff, and Mirco Fuchs. 2021. Assessment of deep learning based blood pressure prediction from PPG and rPPG signals. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 3820--3830.
[39]
Robert Mark Seepers, Wenjin Wang, Gerard de Haan, Ioannis Sourdis, and Christos Strydis. 2018. Attacks on heartbeat-based security using remote photoplethysmography. IEEE Journal of Biomedical and Health Informatics, Vol. 22, 3 (2018), 714--721.
[40]
Rencheng Song, Huan Chen, Juan Cheng, Chang Li, Yu Liu, and Xun Chen. 2021. PulseGAN: Learning to generate realistic pulse waveforms in remote photoplethysmography. IEEE Journal of Biomedical and Health Informatics, Vol. 25, 5 (2021), 1373--1384.
[41]
Wim Verkruysse, Lars O Svaasand, and J Stuart Nelson. 2008. Remote plethysmographic imaging using ambient light. Optics Express, Vol. 16, 26 (2008), 21434--21445.
[42]
Min Wang, Jiankun Hu, and Hussein A Abbass. 2020. BrainPrint: EEG biometric identification based on analyzing brain connectivity graphs. Pattern Recognition, Vol. 105 (2020), 107381.
[43]
Wenjin Wang, Sander Stuijk, and Gerard De Haan. 2015. A novel algorithm for remote photoplethysmography: Spatial subspace rotation. IEEE Transactions on Biomedical Engineering, Vol. 63, 9 (2015), 1974--1984.
[44]
Xuerui Wang, Zheng Yan, Rui Zhang, and Peng Zhang. 2021. Attacks and defenses in user authentication systems: A survey. Journal of Network and Computer Applications, Vol. 188 (2021), 103080.
[45]
Umang Yadav, Sherif N. Abbas, and Dimitrios Hatzinakos. 2018. Evaluation of PPG biometrics for authentication in different states. In Proceedings of the International Conference on Biometrics. 277--282.
[46]
Zitong Yu, Wei Peng, Xiaobai Li, Xiaopeng Hong, and Guoying Zhao. 2019. Remote heart rate measurement from highly compressed facial videos: an end-to-end deep learning solution with video enhancement. In Proceedings of the IEEE/CVF International Conference on Computer Vision. 151--160.
[47]
Junqing Zhang, Yushi Zheng, Weitao Xu, and Yingying Chen. 2021. H2K: A Heartbeat-based Key Generation Framework for ECG and PPG Signals. IEEE Transactions on Mobile Computing (2021.
[48]
Kaipeng Zhang, Zhanpeng Zhang, Zhifeng Li, and Yu Qiao. 2016. Joint face detection and alignment using multitask cascaded convolutional networks. IEEE Signal Processing Letters, Vol. 23, 10 (2016), 1499--1503.
[49]
Tianming Zhao, Yan Wang, Jian Liu, Yingying Chen, Jerry Cheng, and Jiadi Yu. 2020a. Trueheart: Continuous authentication on wrist-worn wearables using PPG-based biometrics. In Proceedings of the Annual IEEE International Conference on Computer Communications (INFOCOM). 30--39.
[50]
Tianming Zhao, Yan Wang, Jian Liu, Yingying Chen, Jerry Cheng, and Jiadi Yu. 2020b. Trueheart: Continuous authentication on wrist-worn wearables using ppg-based biometrics. In Proceedings of the Annual IEEE International Conference on Computer Communications (INFOCOM). IEEE, 30--39. io

Cited By

View all
  • (2024)Biometrics-Based Authenticated Key Exchange With Multi-Factor Fuzzy ExtractorIEEE Transactions on Information Forensics and Security10.1109/TIFS.2024.346862419(9344-9358)Online publication date: 2024
  • (2024)A Framework for User Biometric Privacy Protection in UAV Delivery Systems with Edge Computing2024 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops)10.1109/PerComWorkshops59983.2024.10502849(631-636)Online publication date: 11-Mar-2024
  • (2024)PressHeart: A Two-Factor Authentication Mechanism via PPG Signals for Wearable DevicesICC 2024 - IEEE International Conference on Communications10.1109/ICC51166.2024.10622232(4662-4667)Online publication date: 9-Jun-2024
  • Show More Cited By

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
AISec'22: Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security
November 2022
168 pages
ISBN:9781450398800
DOI:10.1145/3560830
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 07 November 2022

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. biometric authentication
  2. photoplethysmography
  3. physiological signal
  4. spoofing attack

Qualifiers

  • Research-article

Conference

CCS '22
Sponsor:

Acceptance Rates

Overall Acceptance Rate 94 of 231 submissions, 41%

Upcoming Conference

CCS '25

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)133
  • Downloads (Last 6 weeks)15
Reflects downloads up to 03 Mar 2025

Other Metrics

Citations

Cited By

View all
  • (2024)Biometrics-Based Authenticated Key Exchange With Multi-Factor Fuzzy ExtractorIEEE Transactions on Information Forensics and Security10.1109/TIFS.2024.346862419(9344-9358)Online publication date: 2024
  • (2024)A Framework for User Biometric Privacy Protection in UAV Delivery Systems with Edge Computing2024 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops)10.1109/PerComWorkshops59983.2024.10502849(631-636)Online publication date: 11-Mar-2024
  • (2024)PressHeart: A Two-Factor Authentication Mechanism via PPG Signals for Wearable DevicesICC 2024 - IEEE International Conference on Communications10.1109/ICC51166.2024.10622232(4662-4667)Online publication date: 9-Jun-2024
  • (2024)Biometric Authentication Using Chest Wall Displacement Recorded by VHF-Band Loop AntennaIEEE Access10.1109/ACCESS.2024.352101312(196475-196487)Online publication date: 2024
  • (2024)Camera-based physiological measurementNeurocomputing10.1016/j.neucom.2024.127282575:COnline publication date: 16-May-2024
  • (2024)Deceptive Waves: Embedding Malicious Backdoors in PPG AuthenticationWeb Information Systems Engineering – WISE 202410.1007/978-981-96-0567-5_19(258-272)Online publication date: 3-Dec-2024
  • (2023)SigA: rPPG-based Authentication for Virtual Reality Head-mounted DisplayProceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses10.1145/3607199.3607209(686-699)Online publication date: 16-Oct-2023
  • (2023) Pistis : Replay Attack and Liveness Detection for Gait-Based User Authentication System on Wearable Devices Using Vibration IEEE Internet of Things Journal10.1109/JIOT.2022.323138110:9(8155-8171)Online publication date: 1-May-2023
  • (2023)PulseOblivion: An Effective Session-Based Continuous Authentication Scheme Using PPG SignalsIEEE Access10.1109/ACCESS.2023.332999311(124213-124227)Online publication date: 2023
  • (2022)Remote Heart Rate Estimation by Pulse Signal Reconstruction Based on Structural Sparse RepresentationElectronics10.3390/electronics1122373811:22(3738)Online publication date: 15-Nov-2022
  • Show More Cited By

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media