Rise of deepfake threats means biometric security measures won't be enough
- Reference: 1706813108
- News link: https://www.theregister.co.uk/2024/02/01/deepfake_threat_biometrics/
- Source link:
Or so says consultancy and market watcher Gartner, as deepfakes dominate the news since [1]sexually explicit AI-generated viral images of popstar Taylor Swift prompted fans, Microsoft, and the White House to call for action.
However, the relentless march of AI technology can also be the cause of headaches for enterprise security. Remote account recovery, for example, might rely on an image of the individual's face to unlock security. But since these could be beaten by images copied from social media and other sources, security systems employed "liveness detection" to see if the request was from the right individual.
[2]
As well as matching an individual's image to the one on record, systems relying on liveness detection also try to test if they are really there through an "active" request such as a head movement or "passive" sensing of micro facial movements and the focus of the eyes.
[3]
[4]
Yet these approaches could now be duped by AI deepfakes and need to be supplemented by additional layers of security, Gartner's VP Analyst Akif Khan told The Register .
He said that defense against the new threat can come from supplementing existing measures or improving on them.
[5]
"Let's say, for example, the vendor knows that an IP verification process shows the user is running an iPhone 13 and understands the camera resolution of the device, then if the [presented deepfake doesn't match these parameters] it might suggest that it's been digitally injected," he said.
[6]Dems and Repubs agree on something – a law to tackle unauthorized NSFW deepfakes
[7]'I'm sorry for everything...' Facebook's Zuck apologizes to families at Senate hearing
[8]It took Taylor Swift deepfake nudes to focus Uncle Sam, Microsoft on AI safety
[9]AI political disinformation is a huge problem – but harder to fight than ever
Other examples of supplementary security might include looking at device location or frequency of requests from the same device, he said.
Security system developers are also trying to use AI – typically deep neural networks – to inspect the presented images to look for signs that they are deepfakes. "One vendor showed me an example of several deepfake images that they had detected, and the faces looked very different," Khan told us.
"However, when you really zoomed in there were on each of the heads three or four hairs, which were all in the absolute exact same kind of configuration of like three or four hairs overlapping with each other in a way that just looked eerily identical across these like three or four different people. That was like an artifact that they use to determine that actually these are synthetically created images."
Organizations should use both approaches to defend against deepfake threats to biometric security, he said.
[10]
"It's classic defense-in-depth security. I would not want to say one approach was better than any other because I think the best approach would be to use all of the layers available." ®
Get our [11]Tech Resources
[1] https://www.theregister.com/2024/01/30/nudes_taylor_swift_action/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zbwin7KKzWZPVXzUFf9JPgAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zbwin7KKzWZPVXzUFf9JPgAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zbwin7KKzWZPVXzUFf9JPgAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zbwin7KKzWZPVXzUFf9JPgAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2024/01/31/ai_defiance_act/
[7] https://www.theregister.com/2024/01/31/senate_social_media_zuckerberg/
[8] https://www.theregister.com/2024/01/30/nudes_taylor_swift_action/
[9] https://www.theregister.com/2024/01/17/ai_political_disinformation/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zbwin7KKzWZPVXzUFf9JPgAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Biometrics
Should be ok with a decent (3D, IR) sensor, but deepfake will trick the "show us your face on the camera" approach that the banks like to use*.
* Natwest restrict how much I can send from my account as I refuse to enable it.
Re: Biometrics
The 3D sensors like Face ID would be fooled by a 3D model, and given enough 2D images from various angles the right software could transform that into a "program" for a 3D printer to print a model of the person's face that would pass.
Sounds like Apple might need to upgrade Face ID in future phones so that it checks for "liveness" via stuff like seeing a pulse under the skin and require some evidence of movement of the eyes (maybe the involuntary movements everyone does would be enough) They probably don't need to worry about this today, but the clock is ticking.
It's like those who push this stuff are completely technically illiterate or their approach to risk is they think it's all "that science fiction stuff" or "as I saw in
Baldur's Gate approach needed
In that game there's one altar, stone, bowl or what-not after another that unlock treasure, gate, thingamabob by giving blood. I squirm every time my character pulls out a honking big knife and goes **slice**.
But maybe that's what we need. We'll all be more anaemic than visitors to a vampire convention.
Icon is what happens when you bumble into a red dragon's den and roll a critical fail.
Biometric Security
Has always been an oxymoron.