A face recognition attack testing method and system
Through the automated robotic arm and test terminal system, multi-posture adjustment and action recognition of the target terminal are achieved, which solves the problem of low efficiency of manual detection and improves the efficiency and accuracy of face recognition attack testing.
Patent Information
- Application Number
- CN202310755114.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-25
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-06-25
AI Technical Summary
In the existing face recognition attack testing process, manual detection methods are inefficient and costly, and human factors lead to inaccurate test results.
An automated approach is adopted through the robotic arm and test terminal, combined with the control terminal, to achieve multiple posture adjustments and action recognition of the target terminal, and automatically complete the face recognition attack test.
It effectively reduces labor costs, improves testing efficiency, and can accurately discover security vulnerabilities in interactive face recognition.
Smart Images

Figure CN116994342B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a face recognition attack testing method and system. BACKGROUND
[0002] The face recognition authentication mode generally includes silent single frame biopsy and interactive biopsy with action (blinking, opening mouth, shaking head, nodding, etc.). Generally speaking, the authentication mode with interactive action has higher security level than the silent biopsy. In the testing process of the face recognition application program with interactive action, the artificial detection mode is always used, that is, the tester makes corresponding action according to the action prompt of the face recognition application program to attack the face recognition application program. The artificial detection mode has low efficiency and brings huge cost investment to the test. SUMMARY
[0003] The present application relates to the technical field of computer, in particular to a face recognition attack testing method and system.
[0004] According to the first aspect, a face recognition attack testing method is provided, which includes the following steps:
[0005] determining at least one first pose of a test terminal;
[0006] determining a plurality of second poses of a target terminal; the target terminal is installed with a target application program;
[0007] adjusting the target terminal to the plurality of second poses;
[0008] obtaining the recognition result of the test action played by the target application program on the test terminal at each second pose;
[0009] if the recognition result is a successful recognition result, determining an attack pose based on the second pose corresponding to the recognition result and the first pose.
[0010] As an optional implementation of the method of the first aspect, the attack pose includes distance data and angle data; the attack pose is determined based on the second pose corresponding to the successful recognition result and the first pose, specifically including:
[0011] determining the relative distance between the test terminal and the target terminal based on the second pose corresponding to the successful recognition result and the first pose, to obtain the distance data;
[0012] Based on the second posture and the first posture corresponding to the successful recognition result, a three-dimensional motion posture of the test terminal relative to the target terminal is determined, and the angle data is obtained based on the three-dimensional motion posture.
[0013] As an optional implementation manner of the method according to the first aspect, the test terminal pre-stores test action data; and the test terminal plays the test action, specifically including:
[0014] In response to the received test task, collecting a face recognition interface image of the target application in real time;
[0015] Extracting action prompt information from the face recognition interface image;
[0016] A test action is determined based on the action prompt information and played.
[0017] As an optional implementation manner of the method of the first aspect, the test terminal pre-stores test action data; obtaining a recognition result of the test action played by the target application on the test terminal in each of the second postures specifically includes:
[0018] The test terminal plays the test actions in a preset playback order;
[0019] For each test action, the target terminal is controlled to traverse the multiple second postures, and a recognition result of the test action by the target application in each of the second postures is obtained.
[0020] According to a second aspect, another face recognition attack test method is provided, which is applied to a face recognition attack test system, wherein the face recognition attack test system includes: a robotic arm, a test terminal, a target terminal, and a control terminal;
[0021] The test terminal is configured to play a test action at at least one first posture in response to a test task issued by the control terminal;
[0022] The robotic arm is configured to adjust the target terminal to a plurality of second postures preset in the test task in response to the test task issued by the control end;
[0023] The target terminal is provided on the robotic arm and is installed with a target application, and is configured to identify the test action through the target application when moving to each of the second postures;
[0024] The control end is used to generate the test task and send it to the robotic arm and the test terminal; and determine the attack posture based on the second posture and the first posture corresponding to the successful recognition result of the test action by the target application.
[0025] As an optional implementation scheme of the method described in the second aspect, the attack posture includes distance data and angle data; the control end is specifically used to determine the relative distance between the test terminal and the target terminal based on the second posture and the first posture corresponding to the successful recognition result, and obtain the distance data; based on the second posture and the first posture corresponding to the successful recognition result, determine the three-dimensional motion posture of the test terminal relative to the target terminal, and obtain the angle data based on the three-dimensional motion posture.
[0026] As an optional implementation of the method described in the second aspect, test action data is pre-stored in the test terminal; the test terminal is specifically used to respond to the test task issued by the control terminal, collect the face recognition interface image of the target application in real time; extract action prompt information from the face recognition interface image; determine the test action based on the action prompt information and play it.
[0027] As an optional implementation of the method of the second aspect, the test terminal pre-stores test action data;
[0028] The test terminal is specifically used to play the test actions in a preset play order;
[0029] The control end is specifically used to adjust the posture of the target terminal through the robotic arm for each test action, so that the target terminal traverses the multiple second postures, and obtains the recognition result of the target application for the test action in each of the second postures.
[0030] According to a third aspect, a face recognition attack test system is provided, comprising: a robotic arm, a test terminal, a target terminal, and a control terminal;
[0031] The test terminal is configured to play a test action at at least one first posture in response to a test task issued by the control terminal;
[0032] The robotic arm is configured to adjust the target terminal to a plurality of second postures preset in the test task in response to the test task issued by the control end;
[0033] The target terminal is provided on the robotic arm and is installed with a target application, and is configured to identify the test action through the target application when moving to each of the second postures;
[0034] The control end is used to generate the test task and send it to the robotic arm and the test terminal; and determine the attack posture based on the second posture and the first posture corresponding to the successful recognition result of the test action by the target application.
[0035] As an optional implementation of the system of the third aspect, the robotic arm includes a controller, a driver, and an actuator;
[0036] The control end is specifically configured to determine a control instruction based on the plurality of second postures and a preset motion path of the target terminal;
[0037] The controller is configured to execute the control instruction and control the driver to adjust the posture of the target terminal to the plurality of second postures.
[0038] According to a fourth aspect, an evaluation method is provided, the method comprising:
[0039] determining at least one target terminal, wherein the at least one target terminal has at least one target application installed thereon;
[0040] Using the face recognition attack testing method according to any one of claims 1 to 4, the target application is tested to determine the attack posture of the target application;
[0041] Based on the attack posture, a preset attack action is played through the test terminal, and a recognition result of the attack action by the target application is obtained;
[0042] An evaluation result of the target application is determined based on the total number of attacks of the attack action and the number of successful identifications in the identification result.
[0043] The face recognition attack testing method and system provided by one or more embodiments of this specification can automatically complete face recognition attack testing, effectively reduce labor costs, and efficiently discover security vulnerabilities in interactive face scanning. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate one or more embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0045] Figure 1 A flowchart of a face recognition attack testing method provided by one or more embodiments of this specification;
[0046] Figure 2 A schematic diagram of the structure of a face recognition attack testing system provided in one or more embodiments of this specification;
[0047] Figure 3 A schematic diagram of the structure of a robotic arm provided for one or more embodiments of this specification;
[0048] Figure 4 A flowchart of another face recognition attack testing method provided for one or more embodiments of this specification;
[0049] Figure 5 A flowchart of an evaluation method provided for one or more embodiments of this specification. DETAILED DESCRIPTION
[0050] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments in this specification without creative work should fall within the scope of protection of this specification.
[0051] It should be noted that in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the method may include more or fewer steps than those described in this specification. In addition, a single step described in this specification may be broken down into multiple steps for description in other embodiments, and multiple steps described in this specification may be combined into a single step for description in other embodiments.
[0052] Currently, interactive face recognition is commonly used for face recognition. Specifically, during the face recognition process, the terminal interface prompts users to open their mouth, blink, shake their head, and nod. Users are prompted to perform corresponding actions. The terminal interface's face recognition window recognizes these actions and confirms whether the face recognition is successful, thereby determining whether to log in to the corresponding app.
[0053] To prevent hackers from attacking apps' facial recognition authentication processes, potentially leaking user privacy and even causing financial losses, apps typically include features to protect against fake user authentication. To assess apps' capabilities and vulnerabilities in this area, they are typically tested for facial recognition attacks.
[0054] For apps that use interactive movements for facial recognition authentication, manual testing is often employed due to the complexity of attack testing. This involves the tester performing actions such as shaking their head, nodding, opening their mouth, and blinking according to prompts provided by the app's interface. The app's built-in recognition algorithm then captures and identifies the tester's movements within the face recognition frame. During testing, the tester's attack data and the app's corresponding recognition results are recorded to evaluate the app's ability to defend against prosthetic attacks and identify vulnerabilities.
[0055] However, in actual operation, the position of the face in the face scan frame and the relative distance between the tester and the terminal are uncontrollable, making it difficult to reproduce the vulnerability after it is discovered, and the manual vulnerability discovery process is inefficient. Furthermore, during manual testing, data recording is also asynchronous, which is subject to human subjective factors and can easily cause errors in the recorded test results, leading to analytical bias.
[0056] In view of this, this specification aims to propose a face recognition attack testing method and system, which can complete face attack testing in an automated manner.
[0057] The following will further explain in detail the manual review capability evaluation method and system described in the embodiments of this specification in conjunction with the accompanying drawings and specific embodiments. However, this detailed description does not constitute a limitation to the embodiments of this specification.
[0058] Please refer to Figure 1 , Figure 1 A method for evaluating manual review capability provided by this embodiment is shown, and the method specifically includes steps S100 to S108.
[0059] S100: Determine at least one first position of the test terminal.
[0060] The test terminal is used to play test actions, such as nodding, raising the head, shaking the head, opening the mouth, blinking, etc.
[0061] In an exemplary embodiment of the present specification, the test terminal may be a display device capable of playing test actions, such as a display, a high-definition screen, or a terminal device with a display, such as a computer, a TV, an iPad, etc.
[0062] In an exemplary embodiment of the present specification, the position of the test terminal during the test process may remain unchanged or may be changed.
[0063] In an exemplary embodiment of the present specification, the first posture of the test terminal is composed of the position and angle of the test terminal in the coordinate system of the test site. A reference object with a known position can be set in the test site, and then the position data of the test terminal can be determined by the three-point positioning method. After the position data is determined, the angle data of the test terminal relative to the preset reference direction can be measured, such as the deflection angle and the pitch angle.
[0064] S102: Determine multiple second postures of the target terminal.
[0065] The target application to be tested is deployed in the target terminal. When the target application is started, the test actions played by the test terminal are collected through the detection box in the interactive interface, and then the collected test actions are recognized through the built-in recognition program, and the recognition results are presented through the interactive interface.
[0066] In an exemplary embodiment of the present specification, the target terminal may be a terminal device capable of installing the target application, such as a computer, a mobile phone, an access control system with an interactive face recognition function, a gate system, etc.
[0067] In an exemplary embodiment of this specification, the second posture can be pre-set or randomly selected during the test. The second posture of the target terminal is composed of the position and angle of the target terminal in the test site coordinate system. The target terminal's own posture sensor can obtain motion data of the target terminal during the test, and then determine multiple second postures of the target terminal based on a preset reference position.
[0068] In an exemplary embodiment of the present specification, the second posture of the target terminal is a relative posture of the target terminal with respect to the test terminal as a reference, including distance data between the target terminal and the test terminal, and relative angle data between the target terminal and the test terminal, such as a yaw angle and a pitch angle.
[0069] S104: Adjust the target terminal to the plurality of second postures.
[0070] In an exemplary embodiment of the present invention, a gripping device may be used to adjust the position of a target terminal. For example, a robotic arm may be used to grip the target terminal. By setting a motion path and action instructions of the robotic arm, the robotic arm adjusts the gripped target terminal to multiple second positions.
[0071] S106: Obtain recognition results of the test actions played by the target application to the test terminal at each second posture.
[0072] In an exemplary embodiment of this specification, the recognition algorithm of the target application can be adjusted so that the target application can recognize a single action and provide a recognition result. The test terminal can then play the test actions in a preset playback order. For each test action, the target terminal is controlled to traverse all second postures and obtain the target application's recognition result for the test action in each second posture.
[0073] In an exemplary embodiment of the present specification, the test terminal can respond to a received test task, collect the face recognition interface image of the target application in real time, identify the action prompt information in the face recognition interface image, determine the test action based on the identified action prompt information, and play it.
[0074] In an exemplary embodiment of this specification, the test actions may be pre-stored in the test terminal or read from a storage device by the test terminal. The test terminal and the storage device are connected via a network link, which provides a communication medium between the test terminal and the storage device, including various wired or wireless networks such as a data bus, Bluetooth, and Wi-Fi.
[0075] In an exemplary embodiment of the present specification, the test actions can be stored in various video formats, such as MPEG, MPG, DAT, AVI, MOV, ASF, WMV, MKV, FLVRMVB, MP4, etc. The test terminal is equipped with a player capable of decoding and playing videos in the corresponding formats.
[0076] In an exemplary embodiment of this specification, the target terminal can automatically record the timestamp of reaching each second pose and the timestamp of the recognition result. The timestamp of the test action playback can then be determined from the playback record of the test terminal. Through timestamp matching, a matching result of the pose data, test results, and test action can be obtained. Based on this matching result, the security vulnerabilities of the target application in face recognition attacks can be analyzed.
[0077] S108: If the recognition result is a successful recognition result, determine an attack posture based on the second posture and the first posture corresponding to the recognition result.
[0078] In an exemplary embodiment of the present specification, all recognition results may be recorded by the target terminal, and then the test action and posture data corresponding to the successful recognition results may be selected to determine the attack posture.
[0079] In an exemplary embodiment of the present specification, a data recording program of the target terminal may be set to only record successful recognition results, and then the attack posture is determined based on the test action and posture data corresponding to the successful recognition results.
[0080] The attack posture described in this embodiment is the relative posture of the target terminal and the test terminal, including distance data and angle data. In an exemplary embodiment of this specification, determining the attack posture based on the second posture and the first posture corresponding to the successful recognition result specifically includes: determining the relative distance between the test terminal and the target terminal based on the second posture and the first posture corresponding to the successful recognition result, and obtaining distance data; determining the three-dimensional motion posture of the test terminal relative to the target terminal based on the second posture and the first posture corresponding to the successful recognition result, and obtaining angle data based on the three-dimensional motion posture.
[0081] It can be seen from this that Figure 1 In the facial recognition attack testing method shown, the attack is performed by playing a video of a test action on the test terminal, while the target application on the target terminal recognizes the test action. During the test, the first pose of the test terminal and the second pose of the target terminal are both fixed, so the attack pose can be determined and the attack process can be repeated under this attack pose. The entire process is automated, effectively reducing labor costs and improving testing efficiency compared to manual facial recognition attack testing.
[0082] Corresponding to the above-mentioned face recognition attack test method, this embodiment also provides a face recognition attack test system. Figure 2 , Figure 2 1 is a structural diagram of a face recognition attack test system shown in an exemplary embodiment. The system includes: a control terminal 201, a robotic arm 202, a test terminal 203, and a target terminal 204.
[0083] The test terminal 203 is configured to play a test action at at least one first posture in response to the test task issued by the control terminal 201.
[0084] The robotic arm 202 is configured to adjust the target terminal 204 to a plurality of second postures preset for the test task in response to the test task issued by the control terminal 201 .
[0085] The target terminal 204 is disposed on the robotic arm 202 and is installed with a target application, and is configured to recognize the test action through the target application when the robot moves to each second posture.
[0086] The control terminal 201 is used to generate a test task and send it to the robot arm 202 and the test terminal 203; and determine the attack posture based on the second posture and the first posture corresponding to the successful recognition result of the test action by the target application.
[0087] In an exemplary embodiment of this specification, control terminal 201 controls robotic arm 202 and target terminal 204 by issuing a test task to accomplish the aforementioned functions. For example, the test task can specify a motion path for robotic arm 202, causing it to move target terminal 204 to a preset second position at a specified time. Target terminal 204, through a pre-configured operating program, can then configure a target application to recognize test actions played by the test terminal at various time points corresponding to the second position.
[0088] In this scenario, the control terminal 201 is connected to the robot arm 202 and the target terminal 204 through a wired or wireless network.
[0089] In an exemplary embodiment of this specification, the control end 201 can also be connected to the robotic arm 202, the test terminal 203 and the target terminal 204 respectively through a wired or wireless network, and control the robotic arm 202, the test terminal 203 and the target terminal 204 to complete the above functions by issuing test tasks.
[0090] In an exemplary embodiment of the present specification, the control terminal 201 may be a physical server of an independent host, or a virtual server carried by a host cluster.
[0091] In an exemplary embodiment of the present specification, the test terminal 203 may pre-store test actions, the test action data may be directly stored in a video format, and the test terminal 203 is configured with a player capable of decoding and playing the test action data.
[0092] In an exemplary embodiment of this specification, the test terminal 203 can also read the test action data from the external memory in response to the test task. The test action data can be directly stored in a video format, and the test terminal 203 is configured with a player capable of decoding and playing the test action data.
[0093] Please refer to Figure 3 In an exemplary embodiment of the present disclosure, the robotic arm 202 includes a controller 301, a driver 302, and an actuator 303. The controller 201 is specifically configured to determine a control instruction based on multiple second postures and a preset motion path of the target terminal. The controller 301 is configured to execute the control instruction issued by the controller 201, controlling the driver 302 to drive the actuator 303 to adjust the posture of the target terminal 204 to the multiple preset second postures.
[0094] Please refer to Figure 4 ,The face attack test method of the above face recognition attack test system is as follows:
[0095] S400: The control terminal 201 generates a test task and sends it to the robot arm 202 and the test terminal 203;
[0096] S402: The test terminal 203 plays a test action at at least one first posture in response to the test task;
[0097] S404 , the robotic arm 202 adjusts the target terminal 204 to a plurality of second postures preset for the test task in response to the test task;
[0098] S406 , when the target terminal 204 moves to each second posture, the target application recognizes the test action and uploads the recognition result to the control terminal 201 ;
[0099] S408. The control terminal 201 determines the attack posture based on the second posture and the first posture corresponding to the successful recognition result of the test action.
[0100] In an exemplary embodiment of this specification, the attack posture includes distance data and angle data. Control terminal 201 is specifically configured to determine the relative distance between test terminal 203 and target terminal 204 based on the second posture and the first posture corresponding to the successful recognition result, thereby obtaining distance data. Control terminal 201 then determines the three-dimensional motion posture of test terminal 203 relative to target terminal 204 based on the second posture and the first posture corresponding to the successful recognition result, thereby obtaining angle data based on the three-dimensional motion posture.
[0101] In an exemplary embodiment of this specification, test action data is pre-stored in test terminal 203. Specifically, test terminal 203 is configured to respond to test tasks issued by control terminal 201 by capturing a face recognition interface image of the target application in real time; extracting action prompt information from the face recognition interface image; and determining and playing a test action based on the action prompt information.
[0102] In an exemplary embodiment of this specification, test action data is pre-stored in test terminal 203. Test terminal 203 is specifically configured to play the test actions in a preset playback order. Control terminal 201 is specifically configured to adjust the position of target terminal 204 via robotic arm 202 for each test action, causing target terminal 204 to traverse all preset second positions, and obtain recognition results of the target application for each test action in each second position.
[0103] Please refer to Figure 5 An embodiment of the present invention provides an evaluation method, which includes the following steps:
[0104] S500: Determine at least one target terminal, where at least one target application is installed.
[0105] S502: Using the above-mentioned face recognition attack testing method, test the target application to determine the attack posture of the target application;
[0106] S504: Based on the attack posture, a preset attack action is played through the test terminal, and a recognition result of the attack action by the target application is obtained;
[0107] S506: Determine an evaluation result of the target application based on the total number of attacks of the attack action and the number of successful identifications in the identification result.
[0108] In an exemplary embodiment of this specification, for the same target application, the ratio of the number of test actions successfully recognized during each attack test to the total number of attacks can be used as the attack success rate. The lower the attack success rate, the better the target application's ability to resist fake attacks.
[0109] It should be understood that the structures illustrated in the embodiments of this specification do not constitute specific limitations on the systems of the embodiments of this specification. In other embodiments of the specification, the above-mentioned system may include more or fewer components than shown in the figure, or some components may be combined, some components may be separated, or the components may be arranged differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0110] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0111] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0112] It should be noted that the above examples are merely specific embodiments of the present invention. Obviously, the present invention is not limited to the above examples, and many similar variations are possible. All variations directly derived from or associating with the present invention by those skilled in the art are intended to fall within the scope of protection of the present invention.
Claims
1. A face recognition attack testing method, comprising: Determining at least one first pose of the test terminal; determining a plurality of second poses of the target terminal; The target terminal is installed with a target application; The test terminal has test action data pre-stored therein, and in response to a received test task, the test terminal collects a face recognition interface image of the target application in real time; Extracting action prompt information from the face recognition interface image; determining a test action based on the action prompt information and playing the test action; Adjusting the target terminal to the plurality of second postures; Obtaining recognition results of the test actions played by the target application on the test terminal in each of the second postures; If the recognition result is a successful recognition result, determining an attack posture based on the second posture and the first posture corresponding to the recognition result, and repeating the attack process in the attack posture; Automatically recording the timestamp of reaching each second posture and the timestamp of the recognition result by the target terminal, determining the timestamp of playing the test action from the playback record of the test terminal, and obtaining the matching result of the posture data, the recognition result, and the test action by matching the timestamps; Based on the matching results, the security vulnerabilities of the target application in the face recognition attack are analyzed.
2. The method according to claim 1, wherein the attack posture comprises distance data and angle data; Determining an attack posture based on the second posture and the first posture corresponding to the successful recognition result specifically includes: Determining a relative distance between the test terminal and the target terminal based on the second posture and the first posture corresponding to the successful recognition result to obtain the distance data; Based on the second posture and the first posture corresponding to the successful recognition result, a three-dimensional motion posture of the test terminal relative to the target terminal is determined, and the angle data is obtained based on the three-dimensional motion posture.
3. A face recognition attack testing method, applied to a face recognition attack testing system, the face recognition attack testing system comprising: Robotic arm, test terminal, target terminal and control terminal; The test terminal has test action data pre-stored therein, and is configured to collect face recognition interface images of a target application in real time in response to a test task issued by the control terminal; Extracting action prompt information from the face recognition interface image; determining a test action based on the action prompt information and playing the test action at at least one first posture; The robotic arm is configured to adjust the target terminal to a plurality of second postures preset in the test task in response to the test task issued by the control end; The target terminal is provided on the robotic arm and is installed with the target application, and is configured to identify the test action through the target application when moving to each of the second postures; The control terminal is used to generate the test task and send it to the robotic arm and the test terminal; and determining an attack posture based on the second posture and the first posture corresponding to the successful recognition result of the test action by the target application, and repeating the attack process under the attack posture; Automatically recording the timestamp of reaching each second posture and the timestamp of the recognition result by the target terminal, determining the timestamp of playing the test action from the playback record of the test terminal, and obtaining the matching result of the posture data, the recognition result, and the test action by matching the timestamps; Based on the matching results, the security vulnerabilities of the target application in the face recognition attack are analyzed.
4. In the method as claimed in claim 3, the attack posture includes distance data and angle data; the control end is specifically used to determine the relative distance between the test terminal and the target terminal based on the second posture and the first posture corresponding to the successful recognition result, and obtain the distance data; based on the second posture and the first posture corresponding to the successful recognition result, determine the three-dimensional motion posture of the test terminal relative to the target terminal, and obtain the angle data based on the three-dimensional motion posture.
5. A face recognition attack testing system, comprising: Robotic arm, test terminal, target terminal and control terminal; The test terminal has test action data pre-stored therein, and is configured to collect face recognition interface images of a target application in real time in response to a test task issued by the control terminal; Extracting action prompt information from the face recognition interface image; determining a test action based on the action prompt information and playing the test action at at least one first posture; The robotic arm is configured to adjust the target terminal to a plurality of second postures preset in the test task in response to the test task issued by the control end; The target terminal is provided on the robotic arm and is installed with the target application, and is configured to identify the test action through the target application when moving to each of the second postures; The control terminal is used to generate the test task and send it to the robotic arm and the test terminal; and determining an attack posture based on the second posture and the first posture corresponding to the successful recognition result of the test action by the target application, and repeating the attack process under the attack posture; The control end is also used to automatically record the timestamp of reaching each second posture and the timestamp of the recognition result through the target terminal, determine the timestamp of playing the test action from the playback record of the test terminal, and obtain the matching results of the posture data, the recognition result, and the test action through timestamp matching; based on the matching results, analyze the security vulnerabilities of the target application in the face recognition attack.
6. The system of claim 5, wherein the robotic arm comprises a controller, a driver, and an actuator; The control end is specifically configured to determine a control instruction based on the plurality of second postures and a preset motion path of the target terminal; The controller is configured to execute the control instruction and control the driver to adjust the posture of the target terminal to the plurality of second postures.
7. An evaluation method comprising: determining at least one target terminal, wherein the at least one target terminal has at least one target application installed thereon; Using the face recognition attack testing method according to any one of claims 1 to 2, the target application is tested to determine the attack posture of the target application; Based on the attack posture, a preset attack action is played through the test terminal, and a recognition result of the attack action by the target application is obtained; An evaluation result of the target application is determined based on the total number of attacks of the attack action and the number of successful identifications in the identification result.
Citation Information
Patent Citations
Attack testing method, device and equipment for biological feature recognition
CN112559332A
Video processing method, application program testing method and electronic equipment
CN114220051A