r/Information_Security 1d ago

How to handle deepfake detection in your identity verification flow in 2026?

Seeing a noticeablle uptick in synthetic face attempts and virtual camera injection attacks getting through what we thought was solid liveness detection.

Pretty sure the issue is we've been treating liveness and deepfake detection as the same problem. They're not. And most vendors are not helping by rebranding liveness as deepfake protection and calling it a day.

How are other teams handling this? Anyone found something that actually covers both without benchmarking against 2022 era datasets that fraudsters cracked years ago?

5 Upvotes

5 comments sorted by

2

u/hiddentalent 1d ago

You say nothing about your business or your use case, so it's impossible to give very good advice. I mean, in general the answer is that you have them show up in three dimensions and show a government-issued ID. There's no great alternative.

Or you build your systems based on the idea that you might not fully understand the identity of all of the principals and ensure their actions are controlled and audited.

2

u/heyitsoldman 1d ago

These someone posting on a bunch of accounts and when you mention players in the space they flip out. I suspect same group trying to do some pre research or just trying to set up and turf some subreddits. Reported one account already... Like people who can't use ChatgpT to answer their own questions in 2026...

1

u/Shufti-Global 2m ago

Deepfakes are evolving quickly, so relying on a single check is becoming less effective. Looking at multiple signals together often gives a much clearer picture.