THE USE OF ARTIFICIAL INTELLIGENCE ALGORITHMS IN BIOMETRIC AUTHENTICATION SYSTEMS: CAPABILITIES AND VULNERABILITIES
Abstract
The article presents a systematic analysis of the capabilities and vulnerabilities arising from the application of artificial intelligence algorithms in modern biometric authentication systems. The relevance of the study is driven by a qualitative shift in digital identity architecture by the mid-2020s: the adoption of WebAuthn Level 3 and passkeys standards, tightening regulatory and methodological requirements of the EU AI Act and NIST SP 800-63B-4, and the rapid development of morphing and deepfake attacks. The article examines key biometric modalities — face recognition, fingerprint recognition (including contactless technologies), iris and retina — in the context of neural network architectures (CNN, ResNet/DRN). Quality metrics of biometric systems (FPIR, FNIR, APCER, BPCER, IAPMR) and international benchmarks FRVT and IREX are analyzed. Special attention is paid to threats: presentation attacks (PA), morphing, deepfakes, and contactless spoofing, as well as countermeasures (PAD, MAD). The passkeys/WebAuthn L3 architecture is examined as a model for separating biometric verification and cryptographic authentication. A risk assessment and mitigation methodology compatible with EU AI Act, ISO/IEC 30107-3 and NIST SP 800-63B-4 requirements is proposed. Architectural and organizational measures linking technical metrics with risk management requirements are specified. The conclusion is drawn that the further development of biometric systems is determined not by the growth of computing power, but by the ability to combine intelligent feature processing, ethical constraints and engineering reproducibility within accountable and verifiable architectures.
Online viewer
References
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, 2024, L 1689. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689 (accessed 31.03.2025).
- Temoshok D., Fenton J., Lefkovitz N., Regenscheid A., Richer J. Digital Identity Guidelines: Authentication and Authenticator Management. NIST Special Publication 800-63B. Gaithersburg, MD: National Institute of Standards and Technology, 2025. DOI: 10.6028/NIST.SP.800-63B-4.
- Scherhag U., Rathgeb C., Merkle J., Breithaupt R., Busch C. Face Recognition Systems Under Morphing Attacks: A Survey. IEEE Access, 2019, vol. 7, pp. 23012–23026. DOI: 10.1109/ACCESS.2019.2899367.
- Tolosana R., Vera-Rodriguez R., Fierrez J., Morales A., Ortega-Garcia J. Deepfakes and Beyond: A Survey of Face Manipulation and Fake Detection. Information Fusion, 2020, vol. 64, pp. 131–148. DOI: 10.1016/j.inffus.2020.06.014.
- Balfanz D., Czeskis A., Hodges J., Jones J. C., Jones M. B., Kumar A., Lindemann R., Powers A., Verrept J. Web Authentication: An API for accessing Public Key Credentials Level 3. W3C Recommendation, 2023. Available at: https://www.w3.org/TR/webauthn-3/ (accessed 31.03.2025).
- Maltoni D., Maio D., Jain A. K., Feng J. Handbook of Fingerprint Recognition. 3rd ed. Cham: Springer, 2022. 512 p. DOI: 10.1007/978-3-030-83624-5.
- Guo Y., Zhang L., Hu Y., He X., Gao J. MS-Celeb-1M: A Dataset and Benchmark for Large-Scale Face Recognition. Lecture Notes in Computer Science, 2016, vol. 9907, pp. 87–102. DOI: 10.1007/978-3-319-46487-9_6.
- Ramachandra R., Busch C. Presentation Attack Detection Methods for Face Recognition Systems: A Comprehensive Survey. ACM Computing Surveys, 2017, vol. 50, no. 1, art. 8. DOI: 10.1145/3038924.
- Biggio B., Roli F. Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning. Pattern Recognition, 2018, vol. 84, pp. 317–331. DOI: 10.1016/j.patcog.2018.07.023.
- Regan P. M., Jesse J. Ethical Challenges of Edtech, Big Data and Personalized Learning: Twenty-First Century Student Sorting and Tracking. Ethics and Information Technology, 2019, vol. 21, no. 3, pp. 167–179. DOI: 10.1007/s10676-018-9492-2.
- ISO/IEC 30107-3:2023. Information technology – Biometric presentation attack detection – Part 3: Testing and reporting. Geneva: International Organization for Standardization, 2023.
- NIST Special Publication 500-290. Biometric Specifications for Personal Identity Verification. Gaithersburg, MD: National Institute of Standards and Technology, 2020.
- Grother P., Ngan M., Hanaoka K. Face Recognition Vendor Test (FRVT). Part 3: Demographic Effects. NIST Interagency Report 8280. Gaithersburg, MD: National Institute of Standards and Technology, 2019. DOI: 10.6028/NIST.IR.8280.
- Grother P., Ngan M. Iris Exchange (IREX) 10: Performance of Iris Recognition Algorithms. NIST Interagency Report 8247. Gaithersburg, MD: National Institute of Standards and Technology, 2018. DOI: 10.6028/NIST.IR.8247.
- FIDO Alliance. FIDO2: WebAuthn & CTAP. Technical Overview, 2023. Available at: https://fidoalliance.org/fido2/ (accessed 31.03.2025).
- Jain A. K., Nandakumar K., Ross A. 50 Years of Biometric Research: Accomplishments, Challenges, and Opportunities. Pattern Recognition Letters, 2016, vol. 79, pp. 80–105. DOI: 10.1016/j.patrec.2015.12.013.
- Marcel S., Nixon M. S., Fierrez J., Evans N. (Eds.) Handbook of Biometric Anti-Spoofing: Presentation Attack Detection and Liveness Detection. 3rd ed. Cham: Springer, 2023. 650 p. DOI: 10.1007/978-3-031-48349-6.
- Daugman J. How Iris Recognition Works. IEEE Transactions on Circuits and Systems for Video Technology, 2004, vol. 14, no. 1, pp. 21–30. DOI: 10.1109/TCSVT.2003.818350.
- Ferrara M., Franco A., Maltoni D. The Magic Passport. Proceedings of the IEEE International Joint Conference on Biometrics (IJCB), 2014, pp. 1–7. DOI: 10.1109/BTAS.2014.6996240.
- Uymin A. G. Primenenie tekhnologiy tsifrovogo dvoynika v podgotovke spetsialistov po setevomu i sistemnomu administrirovaniyu [Application of digital twin technologies in training specialists in network and system administration]. Sovremennye naukoemkie tekhnologii [Modern High Technologies], 2023, no. 5, pp. 112–118. (In Russian).
License
Copyright (c) 2025 A. G. Uymin (Author)