Authentication Risk Assessment with Similarity-Gradient Adversarial Samples
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems are vulnerable to adversarial samples that can mislead authentication models, lacking effective methods to assess and mitigate the risks associated with such attacks.
Innovation Solution
An information processing apparatus and method that calculates similarity and gradient information to determine perturbation targets, applies perturbations to generate adversarial samples, and assesses authentication risks based on the authentication results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication processing is performed using traditional methods, then authentication speed is maintained, but the system becomes vulnerable to adversarial samples that can mislead the authentication model
Solution Approach 1:
The patent applies preliminary action by performing risk assessment before actual authentication decisions. Adversarial samples are generated and evaluated in advance to determine potential risks, allowing the system to prepare appropriate countermeasures before encountering real authentication attempts, thereby improving security without significantly increasing operational complexity
Solution Approach 2:
The patent introduces an intermediary risk assessment mechanism between the authentication model and the final authentication decision. This intermediary layer generates adversarial samples, evaluates them through similarity calculation and gradient analysis, and provides risk information to guide authentication decisions, effectively mediating between raw authentication processing and security requirements
2Measurement precision
If adversarial samples are generated to test authentication robustness, then security evaluation capability is improved, but computational cost and processing time increase
Solution Approach 1:
The patent applies local quality by focusing gradient calculations on specific regions and features rather than uniformly processing entire images or datasets. The gradient-based adversarial sample generation targets local feature spaces that are most critical for authentication decisions, thereby improving risk assessment accuracy while reducing overall computational energy requirements
Solution Approach 2:
The patent utilizes parameter changes by adjusting gradient magnitudes, perturbation strengths, and similarity thresholds to optimize the balance between assessment accuracy and computational cost. By dynamically tuning these parameters based on the specific authentication context, the system achieves high measurement precision without excessive energy consumption
3Object-affected harmful factors
If gradient-based perturbation is applied to generate adversarial samples, then ability to mislead authentication model is improved, but difficulty in controlling perturbation magnitude increases
Solution Approach 1:
The patent implements feedback by using gradient information from the authentication model to guide perturbation application, then evaluating the resulting adversarial samples through similarity calculations. This feedback loop allows the system to adjust perturbation magnitudes and directions iteratively, achieving effective adversarial samples while maintaining control over perturbation characteristics through continuous evaluation and adjustment
Data Source
AI summary
An information processing apparatus includes: a similarity degree calculation unit that calculates a degree of similarity between a feature quantity of first information and a feature quantity of second information; a gradient information calculation unit that calculates gradient information indicating a gradient of the degree of similarity; a perturbing position determination unit that determines an element serving as a perturbing target in the first information, on the basis of the gradient information; a perturbing unit that applies a perturbation to the element serving as the perturbing target in the first information; and a risk assessment unit that assesses a risk in authentication processing on the basis of a result of the authentication processing of collating/verifying the first information to which the perturbation is applied, and the second information. According to such an information processing apparatus, it is possible to properly assess the risk in the authentication processing.


