FB pixel

Synthetic identity blends real and fake data to enable fraud, demanding new protections

Idiap and PXL Vision, Yoti, iProov work to make ID verification more secure
Synthetic identity blends real and fake data to enable fraud, demanding new protections
 

Faces are everywhere, stored and displayed in the millions on social media platforms. Generative AI technologies have enabled the large-scale harvesting and manipulation of face biometrics, and given us the new threat of synthetic identity fraud.

PXL Vision and the Biometrics Security and Privacy group at Idiap Research Institute have partnered to develop a “robust AI-based counterfeit detection solution,” according to a post on LinkedIn. A synthetic ID primer from PXL Vision explains that perpetrators of synthetic identity fraud use AI to “create a completely new identity from a mixture of stolen, manipulated and fictitious information.”

Manufactured synthetic identities merge and blend real identity details from different stolen identities. A real ID number might be paired with a fake name or address and linked to a deepfaked image that lines up with the hacked identity data. Manipulated synthetic identities are real identities that alter an existing identity document.

The widespread shift toward digital identity verification and authentication processes, as illustrated by the EUDI Wallet scheme, brings new risks: “the transition to digital identity opens up new areas of attack – precisely because AI-supported fraud scams are likely to become increasingly sophisticated in the future.”

PXL Vision uses near field communication (NFC) and liveness checks to recognize and prevent fraud attempts. Moreover, “another key component is video injection detection, which identifies manipulated or artificially generated videos for deception. This is done by analysing metadata, movement patterns and digital artefacts that may indicate manipulation.”

The deepfake project with Idiap is supported by the Swiss innovation promotion agency Innosuisse.

Yoti Liveness, injection detection defends against direct and indirect attack vectors

A new white paper from Yoti delves into the threat of Generative AI. “The rate of development of generative AI presents a problem to not just ensuring a person is who they say they are, but also to content platforms who need to be sure that the content added by a user is genuine,” says the paper. “Given the potential risks and challenges in detecting generative AI, Yoti’s strategy emphasises early detection at the source, addressing both direct and indirect attack vectors.”

While presentation attacks (PAD) are a “relatively mature and well understood issue across the verification space,” well defended by effective liveness detection, more recently popularized injection attacks attempt to bypass liveness detection by hacking directly into a hardware device or virtual camera.

Yoti says the latest version of its MyFace SICAP (Secure Image CAPture), “a new way of adding security at the point an image is being taken for a liveness or facematch check,” is able to detect both hardware and software attacks.

Report from iProov highlights scale of identity attack arsenal

The recently released Threat Intelligence Report from iProov highlights the “skyrocketing increase in Native Virtual Camera and Face Swap attacks.”

“Native Virtual Camera attacks have become the primary threat vector, increasing by 2665 percent due partly to mainstream app store infiltration,” says the report. “Face Swap attacks surged 300 percent compared to 2023, with threat actors shifting focus to systems using liveness detection protocols.”

The company also issues a bit of warning on providers: “When a vendor claims to offer ‘complete deepfake protection,’ it is critical to inquire about which of the 115,000 known attack combinations they have tested,” it says. “We have documented 127 face swap tools, 91 virtual cameras, and 10 emulators – each of which creates distinct attack vectors.”

Related Posts

Article Topics

 |   |   |   |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Biometrics testing, more user control contrast with US surveillance expansion

Biometrics and digital identity technologies and policies are being upgraded by providers and implementers to increase trust, as seen in…

 

Sri Lanka digital ID launch by March 2026: President

Sri Lanka has set plans to launch the first digital ID by March next year, President Anura Kumara Dissanayake stated….

 

Former Microsoft CSO named Princeton Identity Executive Advisor

Brian K. Tuskan, former Chief Security Officer for Microsoft and ServiceNow, has joined Princeton Identity as its newest Executive Advisor….

 

US DoD and Intelligence Community veteran joins ROC Board

ROC has announced the appointment of Brian A. Hibbeln, a 30-year veteran of the Department of Defense and the U.S….

 

With passkey sign-in secured, FIDO Alliance looks to frontier of digital credentials

According to the Passkey Index, a benchmark from the FIDO Alliance, 93 percent of user accounts across member firms are…

 

ADVP steps up to defend UK DIATF as new digital ID scheme threatens to ditch it

The Association of Document Verification Professionals (ADVP) has issued an open letter to the Secretary of State for the Cabinet…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events