Javascript must be enabled to continue!
DR-SigAttack: Distribution-Relevant Signature Attack Withstands Defense Mechanisms for Offline Signature Verification
View through CrossRef
Abstract
In the field of machine learning security, adversarial perturbations are carefully designed and added to images to fool a machine learning classifier into making incorrect predictions. As a key biometric for identity verification, offline handwritten signature systems are vulnerable to attacks that result in misclassification and thus pose serious risks to personal privacy and system security. However, traditional attack algorithms can be defended against with defensive measures and fail to assess the robustness of signature verification networks. To address this issue, we propose a novel Distribution-Relevant Signature Attack (DR-SigAttack) method based on the Triplet Attention (TA) module to assess the security of signature verification systems. Specifically, the TA module is integrated into the surrogate model and fine-tuned to strengthen its capacity for capturing discriminative stroke characteristics that are essential for signature verification. Then, using the fine-tuned surrogate model, distribution-relevant adversarial examples are generated by computing input gradients and updating them in alignment with or against the gradient direction. To evaluate the effectiveness of the proposed method, extensive experiments are conducted on three benchmark offline handwritten signature datasets (GPDS-synthetic, CEDAR, and BHSig260), demonstrating that the adversarial examples generated by the proposed method maintain high attack success rates, imperceptibility, and strong transferability, even after undergoing various standard and advanced defense mechanisms.
Springer Science and Business Media LLC
Title: DR-SigAttack: Distribution-Relevant Signature Attack Withstands Defense Mechanisms for Offline Signature Verification
Description:
Abstract
In the field of machine learning security, adversarial perturbations are carefully designed and added to images to fool a machine learning classifier into making incorrect predictions.
As a key biometric for identity verification, offline handwritten signature systems are vulnerable to attacks that result in misclassification and thus pose serious risks to personal privacy and system security.
However, traditional attack algorithms can be defended against with defensive measures and fail to assess the robustness of signature verification networks.
To address this issue, we propose a novel Distribution-Relevant Signature Attack (DR-SigAttack) method based on the Triplet Attention (TA) module to assess the security of signature verification systems.
Specifically, the TA module is integrated into the surrogate model and fine-tuned to strengthen its capacity for capturing discriminative stroke characteristics that are essential for signature verification.
Then, using the fine-tuned surrogate model, distribution-relevant adversarial examples are generated by computing input gradients and updating them in alignment with or against the gradient direction.
To evaluate the effectiveness of the proposed method, extensive experiments are conducted on three benchmark offline handwritten signature datasets (GPDS-synthetic, CEDAR, and BHSig260), demonstrating that the adversarial examples generated by the proposed method maintain high attack success rates, imperceptibility, and strong transferability, even after undergoing various standard and advanced defense mechanisms.
Related Results
Increased life expectancy of heart failure patients in a rural center by a multidisciplinary program
Increased life expectancy of heart failure patients in a rural center by a multidisciplinary program
Abstract
Funding Acknowledgements
Type of funding sources: None.
INTRODUCTION Patients with heart failure (HF)...
Verification of High Speed on Chip with VIP using System Verilog
Verification of High Speed on Chip with VIP using System Verilog
Abstract - The exploration work is addressing verification of High speed on chips protocol; we've used the system Verilog grounded test bench structure. I developed a system Verilo...
Writer-Independent Offline Signature Verification Using Deep Learning
Writer-Independent Offline Signature Verification Using Deep Learning
Abstract: The signature of humans is an important feature in the field of biometrics. It is used as an authentication tool especially in the banking sector because all humans have ...
Evaluation of differences in the performance strategies of top and bottom basketball teams utilizing rank-sum ratio comprehensive
Evaluation of differences in the performance strategies of top and bottom basketball teams utilizing rank-sum ratio comprehensive
IntroductionThis study aimed to explore common characteristics among top basketball teams, differentiate attacking and defensive performance between top and bottom teams, and corre...
Primary PCI: a reasonable treatment for STEMI care during the COVID-19 pandemic
Primary PCI: a reasonable treatment for STEMI care during the COVID-19 pandemic
Abstract
Funding Acknowledgements
Type of funding sources: None.
Introduction
...
Comparative Analysis Of A Multi-Layered Weapon System For City Air Defense In The Modern Warfare
Comparative Analysis Of A Multi-Layered Weapon System For City Air Defense In The Modern Warfare
In the era of modern warfare, urban defense is a very important aspect to maintain the security and stability of a country. Because modern war is a non-military war in which develo...
Enhancing analog circuit security through obfuscation
Enhancing analog circuit security through obfuscation
The focus of this dissertation is the safeguarding of analog circuits against IP piracy attacks, which includes the development of a novel method to secure analog IP, the assessmen...
Trained-feature specific offline learning in an orientation detection task
Trained-feature specific offline learning in an orientation detection task
AbstractIt has been suggested that sleep provides additional enhancement of visual perceptual learning (VPL) acquired before sleep, termed offline performance gains. A majority of ...

