<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>biometric security &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/biometric-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Wed, 30 Sep 2026 20:21:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>biometric security &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>AI Learns the Hidden Geometry of How We Walk to Identify People by Gait</title>
		<link>https://scienmag.com/ai-learns-the-hidden-geometry-of-how-we-walk-to-identify-people-by-gait/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 20:21:36 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[adaptive adjacency matrix]]></category>
		<category><![CDATA[advanced gait recognition frameworks]]></category>
		<category><![CDATA[AI in biometric security]]></category>
		<category><![CDATA[biomechanics of walking]]></category>
		<category><![CDATA[biometric security]]></category>
		<category><![CDATA[biometric signature detection]]></category>
		<category><![CDATA[CASIA-B]]></category>
		<category><![CDATA[dynamic human body modeling]]></category>
		<category><![CDATA[forensic identification]]></category>
		<category><![CDATA[gait recognition]]></category>
		<category><![CDATA[Gait-based biometric identification]]></category>
		<category><![CDATA[graph convolutional networks]]></category>
		<category><![CDATA[graph partitioning]]></category>
		<category><![CDATA[human movement pattern recognition]]></category>
		<category><![CDATA[human walking pattern analysis]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[machine learning for gait recognition]]></category>
		<category><![CDATA[MoCap-Gait dataset]]></category>
		<category><![CDATA[motion capture]]></category>
		<category><![CDATA[non-intrusive person identification]]></category>
		<category><![CDATA[open access gait research]]></category>
		<category><![CDATA[OUMVLP-Pose]]></category>
		<category><![CDATA[skeleton-based biometrics]]></category>
		<category><![CDATA[skeleton-based gait analysis]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=218918</guid>

					<description><![CDATA[Researchers have developed AGSL-Gait, a framework that learns adaptive graph structures from skeletal walking data to capture fine-grained joint dependencies, improving gait recognition across three datasets including a new forensic motion capture collection.]]></description>
										<content:encoded><![CDATA[<p>Every person walks in a way that is subtly, persistently their own. The rhythm of a stride, the swing of an arm, the angle at which a knee bends and releases — these patterns are so distinctive that security researchers have long sought to turn them into a biometric signature, one that can be measured from a distance without the subject ever knowing. A new study published in Complex &amp; Intelligent Systems by Zheze Liu, Lichang Guan and colleagues, spanning the Institute of Automation of the Chinese Academy of Sciences, the Hunan Police Academy and the Institute of Forensic Science of China, pushes this idea forward with a machine learning framework called AGSL-Gait, which learns the structure of the human body directly from walking data rather than imposing it in advance. The work, published open access on 28 September 2026, addresses one of the most stubborn limitations in skeleton-based gait recognition: the tendency of existing systems to treat the body as a fixed, rigid diagram instead of a dynamic, coordinated machine.</p>
<p>To understand why this matters, it helps to look at how modern gait recognition actually works. Many of the best-performing systems do not analyze raw video at all. Instead, they extract a skeletal representation of the walking person — a set of joint positions, typically for the ankles, knees, hips, shoulders, elbows, wrists and head — tracked frame by frame across a walking sequence. This skeleton-based approach has a major practical advantage: because the model sees only the geometry of the body&#8217;s movement, it is naturally robust to external variations that confound appearance-based methods. A suspect wearing a heavy coat, carrying a bag, or walking under unusual lighting still produces a recognizable skeletal signature, even when their visual appearance has changed dramatically.</p>
<p>The standard tool for processing these skeletal sequences is the graph convolutional network, or GCN. In this framework, the joints of the body are treated as nodes in a graph, and the anatomical connections between them — shin to knee, forearm to elbow, and so on — are the edges. Information is then propagated across this graph layer by layer, allowing each joint&#8217;s representation to be shaped by the movement of its connected neighbors. The problem, as the authors of the new study point out, is that the graphs used by most existing methods are static. They are hand-designed from human anatomy and then frozen in place, the same fixed wiring pattern applied to every person, every walking style and every frame of every sequence.</p>
<p>That fixed wiring is a real constraint, because human walking involves coordination that goes well beyond direct anatomical links. When a person walks, the left arm swings in counterpoint to the right leg; the rotation of the pelvis is coupled to the motion of the shoulders; the timing of a heel strike ripples upward through the entire kinetic chain. These long-range, fine-grained dependencies between joints that are not physically connected — and that vary from person to person — carry some of the most discriminative information about an individual&#8217;s gait. A static graph built only from the skeletal diagram simply cannot represent them. The result is that conventional GCN-based systems capture the coarse choreography of walking but miss the subtle personal quirks that distinguish one walker from another.</p>
<p>AGSL-Gait tackles this limitation head-on by letting the network learn its own graph structure from data. The centerpiece of the framework is an adaptive adjacency matrix — the mathematical object that defines which joints influence which — that is not fixed by anatomy but learned during training. Rather than replacing the anatomical prior entirely, the method treats it as a starting point and learns a data-driven residual refinement on top of it, adjusting the connection strengths to capture the implicit, fine-grained inter-joint dependencies that the fixed skeleton misses. In effect, the network discovers for itself which pairs of joints carry the most identifying information about how a particular body moves, and strengthens those channels accordingly.</p>
<p>The second innovation concerns how the graph is partitioned. In graph convolution over a skeleton, a key design decision is which joints are grouped together and treated as sharing a transformation — for example, whether all joints are processed uniformly, whether they are split by body region such as torso, arms and legs, or whether finer subdivisions are used. Most prior work settles on a single partitioning strategy and sticks with it. The authors of the new study instead explore multiple partition strategies in combination, arguing that different ways of slicing up the body expose different aspects of its complex connectivity, and that optimizing over these patterns yields a richer model of how the body&#8217;s segments coordinate during locomotion. The combination of adaptive topology and flexible partitioning is what gives the framework its name: adaptive graph structure learning.</p>
<p>A third contribution is practical rather than algorithmic, but it may prove just as influential. The team constructed MoCap-Gait, a new multi-view motion capture dataset tailored specifically to forensic identification scenarios. Public gait datasets have historically been collected in relatively unconstrained settings, which is valuable for general benchmarking but does not always reflect the conditions under which forensic gait analysis is actually performed. By capturing walking data from multiple viewpoints using motion capture technology, and designing the collection around forensic use cases, the researchers have created a resource intended to test how well gait recognition methods hold up in the settings where they would matter most — courtrooms and criminal investigations, where the evidentiary value of a walking pattern may hinge on the reliability of the underlying algorithm.</p>
<p>The experimental case for AGSL-Gait rests on three distinct datasets. The first is CASIA-B, the most widely used benchmark in gait recognition, which contains walking sequences recorded under variations in clothing, carrying conditions and viewing angle. The second is OUMVLP-Pose, a large-scale pose-based dataset whose sheer volume tests whether a method scales beyond small laboratory collections. The third is the team&#8217;s own MoCap-Gait. Across all three, the researchers report that their approach achieves competitive performance, suggesting that the gains from adaptive graph learning generalize across data sources and capture conditions rather than being an artifact of one particular benchmark. The work was supported by the National Key Research and Development Program of China and by programs of the Ministry of Public Security, underscoring the applied, security-oriented motivation behind the research.</p>
<p>The broader significance of the study lies in a shift of philosophy that is playing out across machine learning more broadly. For years, the dominant practice in skeleton-based action and gait analysis was to encode human knowledge — anatomy, biomechanics, body-part hierarchies — directly into the architecture of the network. That approach is interpretable and reliable, but it caps performance at the limit of what human designers can anticipate. The AGSL-Gait framework represents the counter-trend: keep the human prior as a scaffold, but let the data decide the fine structure. As the authors put it in their abstract, adaptively learning graph topologies and partition patterns is crucial for uncovering discriminative features, precisely because human walking involves complex coordination that no fixed diagram can fully capture.</p>
<p>For the field of biometric identification, the implications are considerable. Gait is one of the few biometrics that can be acquired at a distance, without cooperation from the subject, and it is difficult to disguise — a person can change their face with a mask or their fingerprints with a covering, but altering the way they walk without breaking their stride is far harder. Systems that can extract more of the identifying information latent in skeletal motion, while remaining robust to clothing, carried objects and viewpoint changes, could strengthen surveillance, access control and forensic investigation alike. At the same time, the forensic orientation of the work is a reminder that accuracy claims will eventually be scrutinized in the most demanding forum of all: as evidence. With MoCap-Gait now available and adaptive graph learning demonstrating its value across three benchmarks, the study offers both a technical advance and a testing ground for the next generation of gait recognition systems.</p>
<p><strong>Subject of Research:</strong> Adaptive graph structure learning with graph convolutional networks for skeleton-based gait recognition and forensic identification</p>
<p><strong>Article Title:</strong> Adaptive graph structure learning for skeleton-based gait recognition</p>
<p><strong>Article References:</strong> Liu, Z., Guan, L., Feng, L., Zhang, S., Bao, H., Jiang, X., Zhao, X., &amp; Zheng, N. (2026). Adaptive graph structure learning for skeleton-based gait recognition. <em>Complex &amp;amp; Intelligent Systems</em>. <a href="https://doi.org/10.1007/s40747-026-02524-9" rel="noopener noreferrer">https://doi.org/10.1007/s40747-026-02524-9</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s40747-026-02524-9" rel="noopener noreferrer">10.1007/s40747-026-02524-9</a></p>
<p><strong>Keywords:</strong> gait recognition, graph convolutional networks, adaptive adjacency matrix, skeleton-based biometrics, forensic identification, motion capture, CASIA-B, OUMVLP-Pose, MoCap-Gait dataset, graph partitioning, machine learning, biometric security</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">218918</post-id>	</item>
		<item>
		<title>Four Ways Hackers Can Break Into Your Voice: The New Science of Audio Fraud</title>
		<link>https://scienmag.com/four-ways-hackers-can-break-into-your-voice-the-new-science-of-audio-fraud/</link>
		
		<dc:creator><![CDATA[Blake Davidson]]></dc:creator>
		<pubDate>Sun, 20 Sep 2026 21:02:22 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[advancements in speaker verification technology]]></category>
		<category><![CDATA[adversarial perturbations]]></category>
		<category><![CDATA[adversarial spoofing]]></category>
		<category><![CDATA[AI-driven audio fraud]]></category>
		<category><![CDATA[anti-spoofing]]></category>
		<category><![CDATA[anti-spoofing defense strategies]]></category>
		<category><![CDATA[audio deepfake]]></category>
		<category><![CDATA[audio fraud prevention]]></category>
		<category><![CDATA[biometric security]]></category>
		<category><![CDATA[biometric voice authentication risks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data poisoning]]></category>
		<category><![CDATA[deep learning]]></category>
		<category><![CDATA[deep neural network voice recognition]]></category>
		<category><![CDATA[impact of deep learning on voice security]]></category>
		<category><![CDATA[machine learning security]]></category>
		<category><![CDATA[security challenges in smart speakers]]></category>
		<category><![CDATA[speaker verification]]></category>
		<category><![CDATA[speaker verification system security]]></category>
		<category><![CDATA[speech processing]]></category>
		<category><![CDATA[voice authentication]]></category>
		<category><![CDATA[voice authentication vulnerabilities]]></category>
		<category><![CDATA[voice password security]]></category>
		<category><![CDATA[voice spoofing attack methods]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=202392</guid>

					<description><![CDATA[A new survey in Artificial Intelligence Review unifies the four major attack vectors against voice authentication, finding that audio deepfakes and poisoning pose the greatest real-world risk while existing anti-spoofing defenses remain reactive and bypassable.]]></description>
										<content:encoded><![CDATA[<p>Voice is becoming the password of everyday life. Banks confirm identities over the phone, smart speakers unlock homes, call centers verify customers, and digital assistants authorize payments, all on the strength of a spoken phrase. A new comprehensive survey published in Artificial Intelligence Review argues that this convenience rests on foundations far more fragile than most users realize. Researchers Kamel Kamel, Keshav Sood, Hridoy Sankar Dutta, and Sunil Aryal of Deakin University systematically map the landscape of attacks against voice authentication systems and the anti-spoofing defenses built to protect them, and their unified analysis delivers an uncomfortable conclusion: the attackers currently hold the structural advantage.</p>
<p>The study arrives at a moment when the technology has undergone a genuine transformation. Early speaker verification systems relied on hand-engineered acoustic features, statistical models such as Gaussian mixture models, and carefully designed spectral descriptors that attempted to capture the distinctive qualities of an individual voice. Modern systems have largely abandoned that approach in favor of deep neural networks that learn speaker representations directly from raw audio. These deep embeddings have pushed accuracy on standard benchmarks to impressive heights, and they now sit inside commercial products used by hundreds of millions of people. Yet, as the survey emphasizes, every gain in capability has simultaneously opened new attack surfaces. A model that learns subtle statistical signatures of a voice can also be manipulated, fooled, or fed corrupted data in ways its designers did not anticipate.</p>
<p>The central contribution of the paper is its consolidation of what had previously been scattered literature. Earlier surveys tended to examine individual threats in isolation: one body of work on deepfake speech, another on adversarial examples, a third on data poisoning. The Deakin team instead treats the field as four primary attack vectors against voice authentication: data poisoning, adversarial perturbations, audio deepfakes, and adversarial spoofing. Crucially, they organize these vectors along three analytical axes: what the attacker knows about the target system, how the attack is delivered to the victim, and how broadly the attack generalizes across different speakers and inputs. This framework allows direct comparison between threats that are usually discussed separately, and it exposes a striking asymmetry in how mature each attack class has become.</p>
<p>Consider first adversarial perturbations, the best-studied family of attacks. Here an attacker computes a carefully crafted layer of noise, often imperceptible or nearly imperceptible to human listeners, and adds it to an audio sample so that a machine learning model misclassifies it. In the white-box setting, where the attacker has full access to the model&#8217;s architecture and parameters, gradient-based optimization reliably produces perturbations that flip a verification decision. The technical machinery is elegant: by knowing how the network computes gradients with respect to its input, an adversary can follow the direction of steepest error until the model confidently accepts the wrong speaker or rejects the right one. But the survey highlights a persistent weakness. These attacks are brittle in the physical world. When the crafted audio is played over a loudspeaker, traverses a room, and is re-recorded by a far-field microphone, reverberation, ambient noise, and channel distortion tend to scrub away the delicate perturbation. Over-the-air adversarial examples remain an active research challenge rather than a proven street-level threat, which is a genuine consolation for defenders, albeit a limited one.</p>
<p>Data poisoning occupies the opposite end of the attack lifecycle. Rather than attacking a deployed model, the adversary corrupts it during training, either by inserting malicious samples into the training corpus or by subtly modifying existing ones. Because voice authentication systems are increasingly trained on massive, loosely curated datasets scraped from the web, the opportunity for contamination is real. A poisoned model may develop hidden backdoors: it behaves normally on ordinary inputs, but a specific trigger phrase, a particular speaker&#8217;s characteristics, or a subtle acoustic marker causes it to grant access to an unauthorized person. The survey stresses that poisoning attacks are particularly insidious because the compromise is baked into the model&#8217;s weights, invisible to any evaluation performed on clean test data. Defense requires trust in the data supply chain, something few real-world systems can currently guarantee.</p>
<p>The third and perhaps most socially alarming vector is the audio deepfake. Text-to-speech synthesis and voice conversion models have advanced to the point where a few seconds of publicly available audio, harvested from a podcast, a lecture recording, or a social media video, can be enough to produce convincing synthetic speech in a target&#8217;s voice. Unlike adversarial perturbations, deepfakes do not require any access to the target model. They scale effortlessly, they are delivered through ordinary playback, and they exploit the very features that make a voice distinctive. The survey notes that deepfakes routinely fool not only automated verification systems but also human listeners, who have proven remarkably poor at distinguishing cloned voices from genuine ones. This dual threat, machine and human, is what elevates deepfakes above other attack classes on the authors&#8217; maturity assessment: they are cheap, accessible, effective, and already documented in real fraud incidents involving impersonated executives and fabricated instructions to financial staff.</p>
<p>Adversarial spoofing rounds out the taxonomy, covering attacks that deliberately engineer presentation attacks against the biometric channel itself, from replayed recordings to synthesized or converted speech tuned to slip past specific countermeasures. What links this vector to the others is the uncomfortable finding about the defenses. Anti-spoofing countermeasures, the survey finds, remain largely reactive. They are typically trained on known spoofing algorithms and the datasets generated from them, which means they excel at detecting yesterday&#8217;s attack and struggle with anything novel. Worse, the countermeasures themselves are machine learning models and inherit the same vulnerabilities they are meant to guard against. Adaptive attackers who know a countermeasure exists can optimize their synthetic speech to fool both the authentication system and the spoofing detector simultaneously, a cat-and-mouse dynamic in which the mouse keeps one step ahead.</p>
<p>The three-axis framework makes the comparative picture stark. Adversarial perturbations demand intimate model knowledge and often collapse outside the lab. Deepfakes demand nothing more than a laptop, a few audio clips, and commercially available generative tools, and they travel through the same speakers and microphones that legitimate speech uses. Poisoning attacks require upstream access to training data but yield durable, stealthy compromises. By plotting each vector against knowledge requirements, delivery mechanisms, and generalization capacity, the survey gives security engineers, for the first time in a single reference, a prioritized view of where the danger actually concentrates. The answer is uncomfortable: the attacks that are easiest to launch are the hardest to stop, while the attacks that are hardest to launch are at least detectable under controlled conditions.</p>
<p>The authors close with a research agenda that reads as a rebuke of the field&#8217;s current trajectory. They call for standardized threat models so that results from different labs can be meaningfully compared, noting that inconsistent assumptions about attacker knowledge and delivery have muddied the literature for years. They argue for defenses that act proactively and in real time rather than responding to spoofing techniques after they have already caused damage. And they point toward the need for robustness evaluation that reflects deployment realities, including over-the-air playback, noisy channels, and adaptive adversaries, rather than benchmark performance on pristine recordings. Funding for the work came from the Air Force Office of Scientific Research, and the paper itself is open access, reflecting a deliberate effort to equip the broader security community with a shared map of the battlefield.</p>
<p>For the public, the takeaway is straightforward. Voice, once assumed to be as unique and unforgeable as a fingerprint, should be treated as one factor among several rather than a standalone key. As generative audio becomes a consumer commodity, the window in which organizations can harden their voice-based systems before abuse becomes routine is closing. The Deakin survey does not claim that voice authentication is doomed; deep learning has made the technology remarkably accurate and genuinely useful. But it makes clear that accuracy on clean benchmarks is not security, that the most scalable attacks require no special expertise, and that a defensive posture built on reacting to the last attack is a posture designed to lose the next one. The science of eavesdropping on ears and fooling machines has matured. The science of stopping it now has to catch up.</p>
<p><strong>Subject of Research:</strong> Threats to voice authentication and anti-spoofing systems, including data poisoning, adversarial perturbations, audio deepfakes, and adversarial spoofing</p>
<p><strong>Article Title:</strong> A survey of threats against voice authentication and anti-spoofing systems</p>
<p><strong>Article References:</strong> Kamel, K., Sood, K., Dutta, H. S., &amp; Aryal, S. (2026). A survey of threats against voice authentication and anti-spoofing systems. <em>Artificial Intelligence Review</em>. <a href="https://doi.org/10.1007/s10462-026-11709-0" rel="noopener noreferrer">https://doi.org/10.1007/s10462-026-11709-0</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10462-026-11709-0" rel="noopener noreferrer">10.1007/s10462-026-11709-0</a></p>
<p><strong>Keywords:</strong> voice authentication, speaker verification, anti-spoofing, audio deepfake, adversarial perturbations, data poisoning, adversarial spoofing, biometric security, deep learning, speech processing, machine learning security, cybersecurity</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">202392</post-id>	</item>
	</channel>
</rss>
