247 IQProduct team

The face that belongs to two people

The most dangerous forgeries are not badly printed. They carry a real document, issued by a real authority, with a photograph that was engineered to match two faces at once.

Section
Security
Published
Length
3 min

For a long time, document fraud meant a fake document. The threat has moved. Generative tools now make it cheap to alter a face, blend two faces, or produce a convincing face that belongs to nobody, and those images do not need a forged document to cause harm. They can travel through a genuine one.

Two kinds of attack on the face

Attacks on a face check come in two families. A presentation attack puts something in front of the camera: a printed photo, a screen, a mask. An injection attack skips the camera altogether and feeds a recorded or synthetic video straight into the session. Liveness detection has to handle both, because a check that only looks for masks will wave through a perfect synthetic stream.

Morphing: one photograph, two holders

A morph is a photograph built by blending the faces of two people until the result resembles both. It is submitted with a genuine application, printed by the issuing authority into a genuine passport, and from then on either person can present the document and match the photograph.

Nothing about the document is fake. The paper, the inks, the chip and the data are all real. A check that only asks whether the document is authentic will pass it every time, which is exactly why morphing is used.

Catching it means analysing the photograph itself: the traces that blending leaves in texture, symmetry and detail, which a person looking at the picture for two seconds cannot see.

Deepfakes: a face that was never in front of the camera

In remote onboarding, the risk is not the document but the person holding it. A deepfake can put a different face in front of the camera in real time, or replay a recording of someone who never agreed to the session.

This is where liveness detection matters. The check has to establish that a real, present person is in front of the lens, and that the face it sees is the face on the document, not a screen, a mask or a synthetic stream.

Synthetic identities: a person who does not exist

The third pattern combines real and invented data into an identity that has no real owner. It passes checks that look for a known bad actor, because there is no one to find. It grows slowly, opens accounts, builds history, and disappears.

No single check catches a synthetic identity. It surfaces when the document, the face and the public record fail to tell the same story, which is why document verification, biometrics and open-source intelligence sit on the same platform.

Why the models never stop training

Every one of these techniques improves every month. A detection model trained once and left alone becomes a record of last year's fraud. The models behind the verdict train continuously on new threats and improve every week, so that the check keeps pace with the tools used against it.

  • Morphing: analysis of the document photograph for blending artefacts.
  • Deepfakes: liveness detection and face-to-document matching on every live session.
  • Synthetic identities: consistency between the document, the face and the public record.

What the agent sees

None of this reaches the counter as a lecture. The agent sees one verdict, accept or escalate, and a reason when it escalates. The analysis runs in the cloud in the same few seconds as the rest of the check, so catching the harder frauds does not cost the customer any extra time.

Questions about morphing and deepfake fraud

What is a face morphing attack?

A passport photo made by blending two faces so that it matches both. The document is issued genuinely, and either person can then travel or open accounts with it. Detecting it means analysing the photo itself for the traces blending leaves.

Can liveness detection stop deepfakes?

It is built to establish that a real, present person is in front of the lens, not a screen, a mask or a synthetic stream, and that the live face matches the document photograph.

How do you catch a synthetic identity?

By checking whether the document, the face and the public record tell the same story. A synthetic identity can pass each check alone; it rarely passes all three together.

Do the detection models keep up with new techniques?

They train continuously on new threats and improve every week, so the check does not become a record of last year's fraud.