Deepfakes and face swaps
The attacker tries to pass verification with AI-generated imagery or footage morphed into someone else’s face.
An AI model performs passive liveness analysis and detects deepfake screen attacks.
AI-generated faces, replayed screen recordings and fake IDs are now commonplace. Prove ID analyses the document, chip, face and liveness layer by layer, and defeats pre-prepared attacks with random challenges that change in every session.
Explore the most common attacks on remote identity verification and the Prove ID controls that counter each one.
The attacker tries to pass verification with AI-generated imagery or footage morphed into someone else’s face.
An AI model performs passive liveness analysis and detects deepfake screen attacks.
A video or photo played on another screen is shown to the camera.
Screen attacks are detected in both the face and ID steps, and the frame is checked for multiple faces.
A recorded or generated video is fed into the verification flow.
Facial-gesture, finger and ID-tilt challenges change randomly every session; a prepared video cannot know the right move in advance.
An ID with a replaced photo, a digitally edited ID or a photocopy is used.
Holograms, guilloche, rainbow print and hidden images are checked; digital manipulation, pasted photos and photocopies are detected.
Documents that look flawless but whose chip data does not match are used.
Chip data is read via NFC and goes through active and passive authentication and a certificate validity check; the face is matched against the chip photo.
Previously caught individuals try again with new applications.
Face, national ID number and device blacklists are maintained; suspicious transactions are flagged in the dashboard.
Bypassing a single check is not enough for an attacker; Prove ID collects independent signals at every layer and combines the decision on the server side.
Verification challenges are chosen at random when the session starts. A pre-recorded, generated or injected video cannot know the move being requested at that moment.
#S-4821
In video calls guided by the digital assistant, voice, behaviour and process signals are monitored end to end.
The system checks that the same voice continues throughout; a change of person mid-call is noticed.
Signs of threat or coercion are detected from facial expressions.
Agreement and consent texts are confirmed verbally by the user and recorded.
A screen recording of the whole process and the verification media are stored in the dashboard for audit.
Our face verification model has been evaluated in tests by the US National Institute of Standards and Technology (NIST).
Techsign is listed with a published report card in the NIST FRTE face recognition evaluation.
View the NIST report cardProve ID analyses the image with an AI-based passive liveness model without requiring any extra movement, and detects deepfake and screen attacks in both the face and ID steps. In addition, active challenges chosen at random for each session are requested, and the result is re-verified on the server side.
Verification challenges are chosen at random when the session starts: eye, mouth and head movements, placing a finger on a random corner of the ID, tilting the ID horizontally or vertically, and reading out the ID serial number. Because a prepared video cannot know the move requested at that moment, the flow is resistant to such attacks.
Security features such as holograms, guilloche, rainbow print and hidden images are checked; digital manipulation, pasted photos and photocopies are detected. For NFC-enabled IDs, chip data goes through active and passive authentication and certificate validity checks, and the face is compared with the chip photo.
Prove ID maintains face, national ID number and device blacklists. When a blacklisted person or device starts a new verification, the transaction is blocked or flagged for review in the admin dashboard.
Yes. Techsign’s face recognition model is listed in the US National Institute of Standards and Technology (NIST) FRTE evaluation, and Techsign is the only Turkish company with a score above 90% at NIST. The false acceptance rate (FAR) in face verification is 0.0001%.
Yes. Prove ID provides remote KYC (eKYC) for individual customers: ID reading, NFC chip verification, face matching, liveness detection and video call verification. For corporate customers it supports a KYB business verification flow and verification of documents such as signature circulars and the Turkish Trade Registry Gazette. More than 60 institutions, led by banks, fintechs, payment, investment and crypto-asset companies, use Prove ID.
See with our team how Prove ID works against deepfake and fake ID attacks in your own flow.