Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Deepfake injection attacks and liveness checks: are your controls holding up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: 3.2 million injection attacks were reported in 2025, and 97% of MyFace liveness transactions happened on mobile, according to Yoti research, while an August peak of 527,013 attacks followed the UK Online Safety Act rollout. The signal is clear: identity verification now has to absorb AI-generated spoofing without weakening genuine-user completion.

NHIMG editorial — based on content published by Yoti: analysis of liveness detection, bias, and deepfake injection attacks in 2025

By the numbers:

Questions worth separating out

Q: How should security teams defend biometric verification against deepfake attacks?

A: Security teams should defend the entire biometric capture path, not just the matching algorithm.

Q: Why do liveness checks fail even when a biometric model is accurate?

A: Liveness checks can fail when the input path is weak, because an accurate model cannot recover from a compromised or low-quality capture.

Q: How should security teams reduce false declines without weakening fraud controls?

A: Start by separating hard fraud stops from soft operational failures, then improve the context used in payment decisions.

Practitioner guidance

  • Harden the capture path before verification scoring Use client-side capture controls, quality thresholds, and session checks so only images meeting minimum standards reach the liveness model.
  • Measure rejection and completion rates by device and region Track how often genuine users fail liveness checks across device classes, camera quality tiers, and geographies.
  • Separate anti-injection controls from model accuracy discussions Review whether your verification stack can stop synthetic media before it reaches the liveness engine.

What's in the full article

Yoti's full post covers the operational detail this post intentionally leaves for the source:

  • The full rejection breakdown for mobile users, including the image-quality reasons that were not fully enumerated here.
  • The regional success-rate table for MyFace liveness, including the NIST region groupings used to assess bias.
  • The explanation of how client-side face capture reduces data sharing and removes specific rejection causes.
  • The longer trend view on why attack peaks changed after the UK Online Safety Act rollout.

👉 Read Yoti's analysis of deepfake injection attacks and liveness detection →

Deepfake injection attacks and liveness checks: are your controls holding up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Deepfake resistance is now an identity assurance requirement, not a fraud add-on. Once synthetic media can convincingly imitate a face, the trust problem moves from content quality to source authenticity. Liveness detection becomes the control that separates a real presenting subject from a generated surrogate, which makes it part of core IAM assurance rather than a niche fraud layer. Practitioners should treat this as a shift in verification design, not a tuning exercise.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.

A question worth separating out:

Q: What does presentation attack detection add that face matching does not?

A: Presentation attack detection checks whether the subject is genuinely present at the time of capture, while face matching checks whether two faces are similar enough to belong to the same person. Both are useful, but they solve different problems. If PAD is weak, a convincing fake can reach the matcher and undermine the whole verification flow.

👉 Read our full editorial: Deepfake injection attacks are testing liveness controls in 2025



   
ReplyQuote
Share: