With the large-scale implementation of face recognition technology, how to protect personal privacy?

Editor’s note: This article comes from WeChat public account “Zero One Finance” (ID: Finance_01) , author: Onsen .

On the evening of November 29, CCTV reported that face information was publicly sold on the Internet, with more than 5,000 faces, and only 10 yuan for packaging.

This is not the first time face data has been discovered for sale. In September of this year, there were media reports that 170,000 face data were sold online. On November 19 this year, the Beijing News reported that 30,000 yuan can buy 30,000 face photos. With the rapid implementation of face recognition applications, the issue of facial data leakage has received increasing attention from the media and the public.

The large-scale application of face recognition started around 2017. It has been widely used in security, finance and other fields. Many office buildings, traffic security gates, banks, and mobile APPs will use face recognition technology for identity authentication.

While face recognition offers a lot of convenience, identity information protection has also ushered in a huge challenge like never before.

The amount of data will far exceed the public security system

The final application of face recognition is identity authentication, which is to confirm the true identity of a real person.

Authentication is always there. The National Citizen Identification Number Inquiry Service Center was established in 2001. It is a public security system institution that is responsible for the construction, management and operation of the national citizenship information system, and provides national citizenship information services for government departments and all sectors of society.

Previously, the identity authentication method was that when individual citizens carried out social and economic activities (such as going to telecommunications and banks for related services), they actively presented their resident identity documents to the relevant agencies. After the staff of the relevant agencies obtained the citizen’s authorization, they would Data such as the “citizenship number” and “name” of the certified person are transmitted to the “National Population Information Society Application Platform” of the Ministry of Public Security through the network channel of the telecommunications operator for comparison, and the comparison result of “consistent” or “inconsistent” .

Face recognition technology has become the preferred authentication scheme for many businesses. Because directly comparing the name and ID number is not enough in many practical applications, the merchant needs to know the real identity of the living person, not just the authenticity of the certificate.

Face recognition technology companies are becoming the organization with the largest amount of face data, and will even exceed public security systems in the future. A financial app insider told Zero One Finance that, for example, in your last app, you will be asked to authenticate your face, and you will be asked to blink, nod or shake your head.Each action can have more than a dozen screenshots in the background. In this way, a face recognition company can have a photo of a person from various angles and actions.

“Over time, this is much more than that data in the National Citizen ID Card Number Inquiry Service Center.” The source said frankly, “The National Citizen ID Card Number Inquiry Service Center has national ID information and photos. Everyone is the photo on the ID card. And the face recognition company has dozens of photos for everyone. “

In actual business, the photos of face recognition companies are more useful. The above person explained that there is only one ID photo, and many of the photos may not be clear. In most cases, it was many years ago. It is more laborious to identify real people. Face recognition photos are much better in sharpness, angle, and real-time. In addition, in many cases, the financial APP requires uploading a photo of an ID card. On one photo, the information of the person and the certificate is very comprehensive.

How big is this? You can see it in the prospectus of AI Unicorn Despise Technology. According to the Prospectus Prospectus, as of June 40, 2019, Kuankuo regarded more than 1,100 corporate customers to provide Face ID solutions, and processed an average of approximately 2.4 million Face ID verification requests from customers every day. In addition to Face ID, Vision also provides customers with face contrast, keying and other services through “Face ++”. In the past, there were media calculations. If different types of face recognition calls are counted together, the total number of face recognition calls that are overlooked exceeds 20 million / day.

The tide of data leakage will start

With such a wealth of data, In the existing data protection environment, it can be said that leakage is almost inevitable.

The market has a lot of demand for face data. Earlier media reports said that most of the face photos currently on the market are used to train face recognition models. What needs to train a face recognition model is a technology company that does face recognition technology. Face recognition is one of the most active application areas of artificial intelligence technology at present. The larger the amount of data, the more it helps to train more accurate recognition technology.

According to data from the Institute of Foresight Industry, the face recognition market size is 3.45 billion yuan in 2019, and the face recognition market size will maintain a growth rate of more than 20% in the next five years, and the market size will reach about 10 billion yuan by 2024. .

At the same time, Face recognition is used for identity verification, and the data is transferred in layers in the middle. The middle part is the hardest hit area for data leakage.

A financial app insider gave ZeroOne Finance an example, taking the verification of the identity information of financial apps as an example, “National Citizen ID Card Number Inquiry Service Center-First-level Channel Provider-Face Recognition Vendor- Financial APP “, this is a financial APP for identity verificationThe shortest path to authentication services is to connect financial apps and face recognition vendors to data. Face recognition vendors upload photos through a data channel in the background for identity verification.

It is worth noting that This is the shortest path. In practical applications, there are more than one channel vendor involved in the National Citizen ID Number Inquiry Service Center and face recognition vendors, but several.

“As long as the data has been passed from these channels, it will almost always be cached. That is to say, during the process of uploading face photos for verification, almost all the channel dealers on the entire link will have a copy of the same face photo. .If the verification is passed, these channel dealers will also receive the verification result, which is equivalent to having a face database. “The above person disclosed to Zero One Finance.

The problem of leaking data among these intermediate channel vendors is very serious. According to Zero One Finance, the National ID Number Inquiry Service Center had provided the “ID Card Re-inquiry Query Service” in the early years. Due to the inadequate supervision of this service, crimes such as fraud occurred repeatedly and were banned repeatedly, so national citizenship The ID Number Inquiry Service Center closed the “ID Card Returning Inquiry” service. On November 21st,