TY - GEN
T1 - Reconstructing Protected Biometric Templates from Binary Authentication Results
AU - Rahimi, Eliron
AU - Osadchy, Margarita
AU - Dunkelman, Orr
N1 - Publisher Copyright: © 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Biometric data is considered to be very private and highly sensitive. As such, many methods for biometric template protection were considered over the years - from biohashing and specially crafted feature extraction procedures, to the use of cryptographic solutions such as Fuzzy Commitments or the use of Fully Homomorphic Encryption (FHE).A key question that arises is how much protection these solutions can offer when the adversary can inject samples, and observe the outputs of the system. While for systems that return the similarity score, one can use attacks such as hill-climbing, for systems where the adversary can only learn whether the authentication attempt was successful, this question remained open.In this paper, we show that it is indeed possible to reconstruct the biometric template by just observing the success/failure of the authentication attempt (given the ability to inject a sufficient amount of faces). Our attack achieves negligible template reconstruction loss and enables full recovery of facial images through a generative inversion method, forming a pipeline from binary scores to high-resolution facial images that successfully pass the system more than 98% of the time. Our results are, of course, independent of the protection mechanism used by the system.
AB - Biometric data is considered to be very private and highly sensitive. As such, many methods for biometric template protection were considered over the years - from biohashing and specially crafted feature extraction procedures, to the use of cryptographic solutions such as Fuzzy Commitments or the use of Fully Homomorphic Encryption (FHE).A key question that arises is how much protection these solutions can offer when the adversary can inject samples, and observe the outputs of the system. While for systems that return the similarity score, one can use attacks such as hill-climbing, for systems where the adversary can only learn whether the authentication attempt was successful, this question remained open.In this paper, we show that it is indeed possible to reconstruct the biometric template by just observing the success/failure of the authentication attempt (given the ability to inject a sufficient amount of faces). Our attack achieves negligible template reconstruction loss and enables full recovery of facial images through a generative inversion method, forming a pipeline from binary scores to high-resolution facial images that successfully pass the system more than 98% of the time. Our results are, of course, independent of the protection mechanism used by the system.
UR - https://www.scopus.com/pages/publications/105035834310
U2 - 10.1109/IJCB65343.2025.11410617
DO - 10.1109/IJCB65343.2025.11410617
M3 - Conference contribution
T3 - 2025 IEEE International Joint Conference on Biometrics, IJCB 2025
BT - 2025 IEEE International Joint Conference on Biometrics, IJCB 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2025 IEEE International Joint Conference on Biometrics, IJCB 2025
Y2 - 8 September 2025 through 11 September 2025
ER -