Reality Defender red team enrolls fake faces in Google’s biometric account protection

Security researchers at Reality Defender successfully bypassed Google's biometric liveness checks using synthetic face-swapping software. The experiment demonstrated that current video-based enrollment protections can be vulnerable to sophisticated deepfake manipulation.
Why it matters
As biometric authentication becomes standard for account security, the ability to spoof these systems poses a growing risk to digital identity and cybersecurity.
Biometric liveness checks do not effectively protect Google’s selfie biometrics via video for account enrollment, log-in and recovery against synthetic identities, according to a red team assessment by Reality Defender.Google says its new feature, launched near the end of July, includes active liveness detection to protect against spoof attacks using fake photos or videos and anti-deepfake protections. It is still in the process of rolling out.The brief announcement referred to “multiple layers of security to help prevent impersonation attempts” and “standard security practices to detect and help prevent suspicious sign-in attempts.”A post by Reality Defender AI Researcher and Red Team Specialist Dharva Khambholia explains how a team member used synthetic faces with an eligible Google account owned by Reality Defender.Two enrollments were attempted by a Reality Defender employee using commercially available software for real-time face-swapping and camera manipulation techniques.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in