Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Deepfake detection and identity verification: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Deepfake defence is an early-detection problem, targeting presentation attacks and injection attacks at the point of verification or authentication, with its technology also positioned against account takeovers, identity theft, bot attacks, and SIM swaps, according to Yoti. The identity lesson is that verification controls now have to assume manipulated inputs, not just weak users.

NHIMG editorial — based on content published by Yoti: On the threat of detecting deepfakes

By the numbers:

Questions worth separating out

Q: How should security teams handle deepfake risk in identity workflows?

A: Security teams should treat deepfakes as a trust and verification problem inside identity workflows.

Q: Why are AI deepfakes a problem for identity verification?

A: AI deepfakes weaken verification because they make voice and video far less reliable as identity signals.

Q: What breaks when liveness detection is treated as a standalone tool?

A: What breaks is the link between detection and decision.

Practitioner guidance

  • Separate presentation and injection control paths Map which identity journeys depend on camera-based liveness, and which depend on transport or session integrity.
  • Bind liveness checks to decision points Use liveness detection only where it changes an enrollment, recovery, or authentication decision.
  • Review recovery flows for synthetic identity abuse Focus on account recovery, SIM swap handling, and step-up authentication where attackers often convert a weak identity proof into account takeover.

👉 Read Yoti's analysis of deepfake detection and identity verification risk →

Deepfake detection and identity verification: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Deepfake defence is now an identity assurance problem, not just a content problem. Once synthetic media can be produced cheaply and at scale, the first control that fails is the assumption that the presented signal is authentic. That changes the job of verification and authentication teams, which must treat input integrity as part of the identity decision itself. Practitioners should frame this as source trust, not only fraud detection.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly remediation can trail exposure according to Ultimate Guide to NHIs.

A question worth separating out:

Q: How should security teams handle account recovery when synthetic identities are in play?

A: Treat recovery as a privileged re-entry path, not a support convenience. Use layered verification, require stronger evidence than ordinary login, and remove knowledge-based questions or SMS-only recovery where possible. The goal is to make recovery harder to abuse than initial enrolment, because attackers often wait for the weakest step rather than the front door.

👉 Read our full editorial: Deepfake detection moves identity verification toward source control



   
ReplyQuote
Share: