Opening SecureFlowLive Deepfake Image Injection to Evade Mobile KYC Verification
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0033

Live Deepfake Image Injection to Evade Mobile KYC Verification

  • Predictive ML & Computer Vision
  • Credential & Identity Theft
  • Financial Fraud & Abuse

Facial biometric authentication services are commonly used by mobile applications for user onboarding, authentication, and identity verification for KYC requirements. The iProov Red Team demonstrated a face-swapped imagery injection attack that can successfully evade live facial recognition authentication models along with both passive and active liveness verification (https://en.wikipedia.org/wiki/Liveness_test) on mobile devices. By executing this kind of attack, adversaries could gain access to privileged systems of a victim or create fake personas to create fake accounts on banking or cryptocurrency apps.

Mapped threat techniques

Source

SourceMITRE ATLAS
Updated