Single-Sensor Sparse Adversarial Perturbation Attacks Against Behavioral Biometrics
Ravin Gunawardena, Sandani Jayawardena, Suranga Seneviratne, Rahat Masood, Salil S. Kanhere · IEEE Internet of Things Journal · 2024
In Internet of Things (IoT) deployments, sensing applications have emerged as critical tools. They combine data streams from heterogeneous, untrusted sensors to provide valuable insights or make automated decisions. This paper shows that such systems can be easily manipulated by only compromising a single sensor and perturbing the data from specific time slots rather than entire data streams in grey-box and black-box settings -attack scenarios not considered in traditional machine learning literature. Drawing from two datasets related to behavioural biometrics of smart headsets, we demonstrate that by altering just 6.2% of the data, an attacker can significantly reduce the system’s accuracy—achieving drops of 85% in grey-box scenarios and 74.5% in black-box settings. Next, we show that while adversarial training can mitigate such attacks, an attacker can overcome such defences by increasing the perturbation only in specific time steps. To this end, we propose a two-step defence where we detect more significant perturbations in IoT sensor readings using anomaly detection and mitigate more minor perturbations through adversarial training. Overall, our proposed method can limit the accuracy drop to a maximum of 9.59% across all magnitudes of perturbations, thus protecting against adversarial attacks on multi-sensor systems.