On the vulnerability of ECG verification to online presentation attacks

Nima Karimian, Damon L. Woodard, Domenic Forte

Research output: Chapter in Book/Report/Conference proceedingConference contribution

23 Citations (Scopus)

Abstract

Electrocardiogram (ECG) has long been regarded as a biometric modality which is impractical to copy, clone, or spoof. However, it was recently shown that an ECG signal can be replayed from arbitrary waveform generators, computer sound cards, or off-the-shelf audio players. In this paper, we develop a novel presentation attack where a short template of the victim's ECG is captured by an attacker and used to map the attacker's ECG into the victim's, which can then be provided to the sensor using one of the above sources. Our approach involves exploiting ECG models, characterizing the differences between ECG signals, and developing mapping functions that transform any ECG into one that closely matches an authentic user's ECG. Our proposed approach, which can operate online or on-the-fly, is compared with a more ideal offline scenario where the attacker has more time and resources. In our experiments, the offline approach achieves average success rates of 97.43% and 94.17% for non-fiducial and fiducial based ECG authentication. In the online scenario, the performance is de-graded by 5.65% for non-fiducial based authentication, but is nearly unaffected for fiducial authentication.

Original languageEnglish
Title of host publicationIEEE International Joint Conference on Biometrics, IJCB 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages143-151
Number of pages9
ISBN (Electronic)9781538611241
DOIs
Publication statusPublished - Jul 1 2017
Event2017 IEEE International Joint Conference on Biometrics, IJCB 2017 - Denver, United States
Duration: Oct 1 2017Oct 4 2017

Publication series

NameIEEE International Joint Conference on Biometrics, IJCB 2017
Volume2018-January

Conference

Conference2017 IEEE International Joint Conference on Biometrics, IJCB 2017
Country/TerritoryUnited States
CityDenver
Period1/10/174/10/17

Bibliographical note

Publisher Copyright:
© 2017 IEEE.

ASJC Scopus Subject Areas

  • Computer Networks and Communications
  • Instrumentation
  • Signal Processing
  • Biomedical Engineering

Fingerprint

Dive into the research topics of 'On the vulnerability of ECG verification to online presentation attacks'. Together they form a unique fingerprint.

Cite this