Source-linked AI summary

General Framework to Evaluate Unlinkability in Biometric Template Protection Systems

Marta Gomez-Barrero, Javier Galbally, Christian Rathgeb, Christoph Busch

arXiv:2311.04633v1cs.CV

TL;DR

Biometric template protection requires irreversibility and unlinkability, but unlinkability lacks a systematic quantitative evaluation method. The paper proposes a general framework with local and global metrics, applies it across protection systems, and identifies a scope boundary requiring Lebesgue-integrable linkage functions.

  • Problem

    Biometric template protection standards require unlinkability as well as irreversibility, yet no general objective quantitative framework exists for assessing unlinkability.

  • Method

    The paper introduces local score-wise and global system-level unlinkability measures based on linkage-function score distributions and specifies a linkability evaluation protocol.

  • Results

    The framework provides both detailed score-wise linkability analysis and whole-system benchmarking, and can reveal vulnerabilities concealed by other metrics.

  • Takeaways & Limitations

    The proposed measures support quantitative, objective comparison of unlinkability across biometric template protection systems and linkage functions.

  • Takeaways & Limitations

    The framework requires Lebesgue-integrable linkage functions, although the paper states that most usual linkage functions satisfy this condition.

Abstract

from arXiv · show

The wide deployment of biometric recognition systems in the last two decades has raised privacy concerns regarding the storage and use of biometric data. As a consequence, the ISO/IEC 24745 international standard on biometric information protection has established two main requirements for protecting biometric templates: irreversibility and unlinkability. Numerous efforts have been directed to the development and analysis of irreversible templates. However, there is still no systematic quantitative manner to analyse the unlinkability of such templates. In this paper we address this shortcoming by proposing a new general framework for the evaluation of biometric templates' unlinkability. To illustrate the potential of the approach, it is applied to assess the unlinkability of four state-of-the-art techniques for biometric template protection: biometric salting, Bloom filters, Homomorphic Encryption and block re-mapping. For the last technique, the proposed framework is compared with other existing metrics to show its advantages.

I. INTRODUCTION

Biometric template protection must provide both irreversibility and unlinkability, yet unlinkability has lacked a general objective quantitative evaluation framework. The paper proposes metrics and a framework designed to compare unlinkability across diverse protection systems and linkage functions.

  • Scope: The framework supports systematic evaluation of biometric template protection systems, including biometric cryptosystems, cancelable biometrics, and cross-matching analyses.The paper situates the framework within prior work spanning multiple protection strategies and adversary-oriented analyses.
  • Motivation: ISO/IEC 24745 requires protected biometric templates to be irreversible and unlinkable across applications or databases.Both properties are presented as necessary for privacy protection.
  • Research gap: Existing research has thoroughly analysed irreversibility and accuracy degradation, but lacks a general metric, protocol, or framework for objectively evaluating unlinkability.Prior approaches include subjective analyses and methods restricted to particular systems or assumptions.
  • Framework: The proposed framework provides two quantitative measures: a local score-wise measure D↔(s) and a global system measure Dsys↔.Both measures are defined over the complete score domain and support objective benchmarking among systems.
  • Framework: The metrics evaluate score distributions generated by linkage functions independently of the specific linkage function, requiring only Lebesgue integrability.The framework makes no assumptions about data uniformity or bit independence and permits linkage functions in protected or unprotected domains.

III. CONCEPTS ON BIOMETRIC TEMPLATE PROTECTION AND UNLINKABILITY

The paper defines unlinkability through whether protected templates from different applications can be distinguished as representing the same biometric instance. Its framework models linkage using scores produced from protected templates and compares mated and non-mated score distributions.

  • ISO/IEC 24745 requires biometric references to be irreversible and not linkable across applications or databases.
  • Linkability depends on a linkage function that determines whether two templates are more likely to represent the same instance than different instances.
  • The Pseudonymous Identifier Encoder generates application-specific templates from a biometric sample and secret key, T_i = PIE(M, K_i).
  • The framework assumes a linkage function produces continuous, normalizable scores and that linkage scores between templates are available.
  • Mated scores compare templates from samples of one instance enrolled in different applications, while non-mated scores compare templates from different instances and applications.
  • The framework combines same-sample and different-sample comparisons within the mated distribution, while retaining a general extension to three distributions.

IV. MEASURING LINKABILITY

The paper evaluates linkability by comparing the likelihoods of mated and non-mated templates across linkage-score values. It introduces local and global measures to characterize linkability at individual scores and across an entire system.

  • Templates are linkable at score s when mated instances are more likely than non-mated instances; otherwise, the linkage function fails to link them.
  • The framework defines a local measure D↔(s) for score-wise linkability and a global measure Dsys↔ for system-wide linkability independent of score domain.
  • In a fully unlinkable scenario, mated and non-mated distributions are identical, so linkage scores provide equal probabilities for same and different instances.
  • In a fully linkable scenario, the mated and non-mated distributions are fully separable, enabling near-certain decisions across the score domain.
  • In a semi-linkable scenario, templates are linkable only for a subset of scores, while other scores are more likely to represent different instances.

A. Local Measure D↔(s): System Score-Wise Linkability

The local measure D↔(s) quantifies linkability for each linkage score using likelihood ratios and prior probabilities. It is defined over the full score domain, continuously bounded between 0 and 1, and increases with linkability.

  • Definition and derivation: D↔(s) measures score-specific linkability from the difference between the conditional probabilities of mated and non-mated hypotheses.The measure is derived using Bayes’ theorem, likelihood ratios, and the prior-probability ratio ω.
  • Piecewise local metric: D↔(s) = 0 for scores where LR(s)·ω ≤ 1, indicating that the templates are not linkable at those scores.For LR(s)·ω > 1, the metric follows the likelihood-ratio expression and increases toward 1 as linkability increases.
  • Metric properties: The local metric is defined over the whole score domain and is continuous, bounded in [0, 1], and monotonically increasing.These properties support consistent interpretation of score-wise linkability.
  • Prior-probability assumption: The prior ratio ω is at most 1 for N ≥ 2 subjects and equals 1 in the worst-case unlinkability evaluation with two subjects.For unlinkability analysis, comparisons pair one template from application A with all templates in application B.
  • Global complement: The global metric Dsys↔ complements D↔(s) by estimating system-wide linkability independently of the score.Its value reflects the linkable score domain, linkability within that domain, and the probability of producing those scores.

C. Local and Global Metrics: Discussion

The local and global measures capture different aspects of unlinkability: a score can be unlinkable while revealing that the system is linkable elsewhere. Thus, local unlinkability does not imply global unlinkability.

  • Local interpretation: A score s0 with p(s0|Hnm) > p(s0|Hm) is locally unlinkable, so D↔(s0) = 0.At that score, the templates are more likely to originate from different instances.
  • Distribution complementarity: Observing an unlinkable score implies that some other score s1 must be linkable because the mated and non-mated distributions integrate to one.The value of s1 is not known, but its existence follows from the statistical distributions.
  • Local–global distinction: Therefore, an unlinkable score can coexist with a nonzero global linkability measure Dsys↔.The local metric remains zero for s0 because that specific score does not support linking the templates to the same instance.

V. PROPOSED LINKABILITY EVALUATION PROTOCOL

The proposed protocol evaluates template linkability across applications by generating differently keyed databases, computing mated and non-mated score distributions, and reporting local and global metrics. It supports arbitrary integrable linkage functions and security models, while accuracy evaluation itself is outside scope.

  • Evaluation setup: The protocol defines linkability across applications, where templates in different databases are protected with different keys.Evaluating an algorithm therefore requires multiple databases containing templates derived from the same biometric samples.
  • Protocol steps: The protocol recommends generating K > 5 protected-template databases, each with a different key, then computing mated and non-mated score distributions.Larger databases improve the statistical significance of the evaluation.
  • Reporting and analysis: The evaluation reports D↔(s) plots, score distributions, and global values Dsys↔, then examines maxima, the LR(s)·ω = 1 boundary, and the global metric.The same score-computation protocol should be repeated for every linkage function considered.
  • Multiple linkage functions: When multiple linkage functions are used, the system is at least as vulnerable as under the most challenging function considered.Each function produces its own score and global linkability value.
  • Scope and limitations: The framework applies to any Lebesgue integrable linkage function and security model, while accuracy-evaluation procedures remain outside the article’s scope.Non-continuous functions may eventually be handled by mapping them to distance-based functions.

VI. ANALYSING THE UNLINKABILITY OF BTP SYSTEMS

The framework is applied to evaluate the unlinkability of four previously proposed biometric template protection schemes, with additional analyses of the prior parameter and comparisons against existing metrics.

  • Application: The framework evaluates four previously proposed biometric template protection schemes following the protocol introduced earlier.The schemes are assessed using the metrics described in the framework.
  • Additional analyses: The experiments also study the impact of different ω values and compare the proposed framework with other unlinkability metrics.These analyses extend the evaluation beyond the primary scheme comparisons.

A. Experimental Setup

The experiments evaluate four biometric template protection systems across different biometric modalities, protection algorithms, linkage settings, and prior-probability assumptions. Templates are compared across ten differently keyed databases using mated and non-mated score distributions.

  • Systems and protection methods: Four systems cover iris, signature, face, and fingervein verification with random XOR, Homomorphic Encryption, Bloom filters, and block re-mapping protection.The systems use different feature representations and comparators, including Hamming distance, Euclidean distance, histogram intersections, and cross-correlation.
  • Cross-application evaluation: K = 10 different protection keys simulate subjects enrolled in ten applications whose stored templates an attacker attempts to link.Mated and non-mated distributions are computed from comparisons between templates stored in different databases and protected with different keys.
  • Datasets: The iris, signature, and face analyses use BioSecure data from 210 subjects, with four eye and face samples and sixteen signature samples per subject.Only the left-eye samples are considered for the iris subcorpus.
  • Prior-probability assumption: Because no prior evidence determines the mated and non-mated prior probabilities, the experiments assume p(Hm) = p(Hnm), yielding ω = 1.Likelihood ratios are computed point-wise.
  • Evaluation stages: The evaluation comprises PIC-score analysis, vulnerability-oriented linkage functions for face, ω analysis for facial and iris templates, and fingervein comparison experiments.These stages follow the paper’s linkability evaluation protocol.

B. First Linkage Function: Systems’ PIC Scores

Using each system’s original PIC dissimilarity score as a zero-effort linkage function, the framework finds complete unlinkability for iris and signature templates and near-complete unlinkability for face templates.

  • Linkage function: The original PIC score requires only knowledge of each scheme’s protected-template dissimilarity score and serves as the zero-effort linkage score.No further attacker knowledge is assumed.
  • Iris and signature: For iris XOR and signature Homomorphic Encryption templates, mated and non-mated score distributions completely overlap, giving D↔(s) = 0 throughout the score domain.Their global linkability measure is Dsys↔ = 0, corresponding to fully unlinkable templates.
  • Face: Face Bloom-filter templates have global linkability Dsys↔ = 0.07 under PIC scores and are therefore only slightly linkable.Scores s < 0.94 favor mated instances, but their probability is very low: p(s|Hm) < 0.005.
  • Overall finding: The objective metrics indicate that these protection approaches provide either full or a very high degree of unlinkability.This conclusion is based on the evaluated systems’ global linkability values.

C. Further Linkage Functions Different from the PIC

The framework tests whether linkage functions exploiting reconstruction, Hamming weights, or XOR linearity reveal more linkability than the original PIC score. Reconstruction is the strongest tested vulnerability for the facial Bloom-filter system.

  • Reconstruction function: A reconstruction linkage function rebuilds unprotected templates using the protected templates and secret key, then compares them with Hamming distance.For s < 1.15 × 10^-2, p(s|Hnm) = 0 and p(s|Hm) > 0, yielding D↔(s) = 1.
  • Reconstruction function: Reconstruction raises global linkability to Dsys↔ = 0.25, compared with Dsys↔ = 0.07 for the original PIC score.The paper reports that linking is more likely with reconstruction than with PIC output.
  • Hamming weights function: The Hamming-weight function compares the absolute difference between the protected templates’ Hamming weights and requires only knowledge of the templates.It targets the reported similarity of Hamming weights for same-instance templates protected with different keys.
  • Combined assessment: Across the tested alternatives, the facial system’s overall linkability is Dsys↔ = max {0.07, 0.25, 0.08, 0.06} = 0.25.The maximum combines PIC, reconstruction, Hamming-weight, and XOR linkage values.
  • XOR function: An XOR-based linkage function permutes one template and computes Hamming distance, exploiting the linearity of XOR protection without requiring secret-key knowledge.This attack applies to the original Bloom-filter protection concept.

D. Analysis of Parameter ω

The framework evaluates how the prior-probability ratio ω changes score-wise and global linkability for facial and iris systems. Higher ω increases linkability, with the global measure reaching its maximum at ω = 1.

  • Parameter settings: The analysis tests ω = {0.0001, 0.001, 0.01, 1} for PIC linkage scores from facial and iris protection systems.ω represents the ratio of the prior probabilities of mated and non-mated comparisons.
  • Score-wise effect: As ω increases, D↔(s) increases for every score s with p(s|Hm) > 0.The paper attributes this to the increase of (LR(s) · ω) / (1 + LR(s) · ω) with ω.
  • Interpretation: A higher ω corresponds to a higher prior probability of mated comparisons and increases the probabilities of linking subjects.The paper associates higher ω with a smaller number of enrolled subjects.
  • Global effect: For ω = 1, the global linkability measure Dsys↔ reaches its maximum value.The increase in score-wise linkability drives the corresponding global measure upward.

E. Advantages over Previously Proposed Metrics

The framework provides quantitative, score-wise and system-level linkability analysis and can expose vulnerabilities that existing metrics miss. Its applicability spans protection schemes and linkage functions, subject to a common evaluation protocol and Lebesgue-integrable linkage functions.

  • Fingervein comparison: The framework detected that the fingervein system was almost fully linkable, whereas two existing metrics indicated unlinkability.Dsys↔ was 0.92, and D↔(s) equaled 1 across almost the entire score domain.
  • Framework advantages: The two proposed measures provide complementary views: D↔(s) analyzes score-wise linkability, while Dsys↔ evaluates the system globally.This supports detailed evaluations and benchmarking across systems.
  • Generality: The framework requires only linkage-function scores, without assumptions about input data, template structure, internal modules, or communication channels.This enables analysis of systems using different protection strategies and multiple linkage functions.
  • Scope condition: A minor limitation is that linkage functions must be Lebesgue integrable, although most usual functions satisfy this condition.The paper notes that some non-continuous functions can be mapped to distance-based functions for analysis.
  • Benchmarking: The metrics can reveal linkability vulnerabilities concealed by existing approaches and quantify degrees of linkability rather than returning only binary decisions.Fair comparison requires the same evaluation protocol, such as using the same data.
  • Broader applicability: The framework applies beyond biometric recognition to privacy-sensitive linking activities such as profiling information stored in the cloud.The paper connects this broader use to risks including social exclusion, prejudice, and discrimination.

APPENDIX A MATHEMATICAL PROOFS

The appendix proves that the proposed linkability measures are mathematically well behaved. It establishes their domain, continuity, bounded range, monotonicity, and integrability properties.

  • Domain: D↔(s) is defined over the complete score domain for any mated and non-mated score distributions.The proof uses the fact that the likelihood ratio is defined over the whole score domain.
  • Continuity: D↔(s) is continuous, including at the boundary where LR(s)·ω = 1.The appendix evaluates the one-sided limits at this transition point.
  • Monotonicity: D↔(s) is monotonically increasing because its derivative is non-negative throughout its domain.This makes the measure suitable for evaluating monotonic template linkability.
  • Proper definition: The product defining Dsys↔ is integrable because D↔(s) and p(s|Hm) are continuous functions.The appendix invokes the Riemann–Lebesgue theorem to establish integrability.
  • System-level range: Dsys↔ belongs to [0, 1] because the mated-score density integrates to one over the score domain.The proof begins from the probability-density property of p(s|Hm).
Loading 2311.04633v1…