Related Experiment Video
Updated: Jul 17, 2025

05:33
Three-Dimensional Shape Modeling and Analysis of Brain Structures
Published on: November 14, 2019
7.1K
Comprehensive Vulnerability Evaluation of Face Recognition Systems to Template Inversion Attacks via 3D Face
IEEE Transactions on Pattern Analysis and Machine Intelligence
|September 5, 2023
Summary
This study reveals face recognition systems are vulnerable to 3D reconstruction attacks. A new method (GaFaR) reconstructs 3D faces from templates, demonstrating significant security risks.
Area of Science:
- Computer Vision
- Biometrics
- Cybersecurity
Background:
- State-of-the-art face recognition systems are susceptible to sophisticated attacks.
- Template inversion attacks pose a significant threat to biometric data security.
- 3D face reconstruction offers a novel approach to exploit facial templates.
Purpose of the Study:
- To comprehensively evaluate the vulnerability of face recognition systems to template inversion attacks using 3D face reconstruction.
- To propose and validate a new method (GaFaR) for 3D face reconstruction from facial templates.
- To assess the effectiveness of proposed attack methods in both whitebox and blackbox scenarios.
Main Methods:
- Developed GaFaR: a novel method for 3D face reconstruction from facial templates using a pretrained geometry-aware face generation network.
- Employed a semi-supervised approach with real and synthetic face images to train a mapping from facial templates to the latent space of a face generator network.
- Utilized generative adversarial network (GAN)-based framework for real images and direct mapping for synthetic images.
- Optimized camera parameters of the GNeRF model to enhance attack success rates.
- Conducted whitebox and blackbox attacks against face recognition systems.
Main Results:
- Demonstrated the effectiveness of the proposed GaFaR method in reconstructing 3D faces from templates.
- Achieved high attack success rates in both whitebox and blackbox scenarios.
- Evaluated the transferability of the attack across different face recognition systems on MOBIO and LFW datasets.
- Successfully performed practical presentation attacks using digital screen replay and printed photographs.
Conclusions:
- Face recognition systems are vulnerable to template inversion attacks facilitated by 3D face reconstruction.
- The proposed GaFaR method offers a potent tool for assessing and enhancing the security of face recognition systems.
- Findings highlight the need for developing more robust defenses against advanced biometric attacks.

