Can a deepfake beat facial biometrics? How liveness detection works

Opening an account, approving a large transfer, recovering a password, signing a government contract: at some point over the last few years, your face became the key to all of it. Facial biometrics spread across Brazil because it solves a real problem — a stolen ID document in someone else's hands. But it raises a new and unavoidable question in an era when any face can be synthesized: if AI can fabricate a face on video, can't it fabricate mine in front of the bank? The short answer is "it's much harder than it looks" — and understanding why reveals where the scam actually happens.
What liveness detection checks (it isn't just the face)
Serious face verification has two layers: recognition itself — does this face match the document? — and liveness detection, which answers a different question: is there a living, flesh-and-blood person in front of the camera right now? It's the second layer that scams try to break, and it's where anti-fraud engineering has concentrated a decade of work.
Attacks split into two families, and that distinction explains almost everything:
- Presentation attacks: showing something to the camera — a printed photo, a video on another phone's screen, a mask. This is the old family, and the best-solved one: certified systems (the industry standard is ISO/IEC 30107) detect paper texture, screen moiré, the absence of depth. That photo on your profile does not unlock your bank.
- Injection attacks: showing the camera nothing — replacing the camera. The fraudster uses a virtual camera or a tampered device to inject a deepfake video straight into the app, one that responds to the challenges. This is the new family, the one growing in the industry's fraud reports, and the real arms race today: on the other side, systems check device and app integrity, sensor metadata and statistical artifacts of synthetic video.
That's why modern liveness combines active challenges (turn your head, move closer, follow the light) with passive analysis you never notice — screen reflections on your face, involuntary micro-movements, how skin responds to changing light. A real-time deepfake that survives all of it, inside an intact app, on an untampered device, is an expensive targeted attack — not the retail scam aimed at you.
Where the scam really happens
And here's the inversion that matters: because breaking biometrics is hard, retail crime goes around it — by convincing you to do the biometric check for the scammer. The variants are already circulating:
- The fake re-registration: a message saying "your account will be blocked, update your biometrics" with a link to a page that mimics the bank — and records your selfie video answering the classic challenges (turn left, smile). That material becomes raw input for opening accounts and requesting credit in your name.
- The selfie on approach: scammers posing as a delivery driver, a surveyor or a "health plan verification" asking for a quick photo or video of your face, sometimes holding your ID. Nobody legitimate asks for that outside the official app.
- The loan taken on the victim's own phone: in a street robbery of an unlocked phone, the criminal doesn't need to fool any liveness check — they point the camera at you (or use coercion) and the owner "approves" the transaction. Biometrics authenticate presence, not consent.
- The stockpile of leaked faces: selfies-with-ID collected in older scams, identities stolen for hiring fraud and leaked databases all feed injection attempts — one more reason to treat your image as sensitive data, which is exactly what data protection law already does.
Should I accept facial biometrics at my bank, or is refusing safer?
Accept it — it protects more than it exposes. Well-implemented biometrics are a layer on top of your password, not a fragile substitute for it: the scammer who already has your leaked data runs into liveness, and the one attempting a SIM swap to hijack your number discovers that a cloned SIM doesn't carry your face. The risk that matters to you isn't the bank being fooled by a deepfake of your face — it's you being talked into handing over your biometrics outside the official channel.
How to protect your face-password
- Biometrics only inside the official app, initiated by you. Arrived via link, SMS, WhatsApp or a phone call? It's a scam, no exceptions — the same reflex that applies to passwords applies to selfies.
- Never record a "test" video at a third party's request — recorded liveness challenges are precisely what fraudsters collect.
- Shrink the public stockpile: high-resolution frontal video is raw material. You don't have to erase your life — you do have to know that an open account is a dataset donation, as we detailed in the context of the most common AI scams.
- Protect the device, because it's the vault: a strong lock, the banking app with its own biometric gate, and transfer limits configured — because the realistic fraud scenario is a phone in the wrong hands, not a deepfake in the cloud.
- Be suspicious of "an error with your biometrics" over the phone: it's the current hook for fake support. When in doubt, hang up and go to the bank through the app — and to recognize synthetic faces in other contexts, the guide on how to spot a deepfake still holds.
Facial biometrics aren't invincible — no lock is — but the economics of crime are pragmatic: fooling a certified liveness check is expensive; fooling a person in a hurry costs one message. As long as your face is a password, the rule is the same as for every other password: you only enter it in the right place. The difference is that this one you can't change after the leak — so treat the front camera with the respect your balance deserves.




Comments