Glossary

Deepfake

A deepfake is synthetic or altered audio, video, image, or text made with artificial intelligence to convincingly imitate a real person or event. In identity verification, deepfakes can be used to bypass selfie, voice, or document checks.

Deepfakes use machine-learning models to generate or manipulate media. They may replace a face in a video, clone a voice from recordings, or create a realistic image of a person who was never photographed.

For identity verification, the concern is presentation attack fraud: an attempt to fool a biometric system by presenting an artificial face, voice, or recording instead of a live applicant.

How deepfakes affect IDV

A fraudster may use a real customer's leaked personal data and a generated selfie video or voice sample to try to pass remote onboarding. More advanced attacks can be injected directly into a device's camera feed rather than played on a screen.

  • Face deepfakes can target selfie matching and liveness detection, which assesses whether a real person is present.
  • Voice clones can target voice biometrics and call-center authentication.
  • Generated or edited images can support document fraud, including altered ID photos or fabricated supporting evidence.
  • Deepfake text and images can also strengthen social-engineering attempts to obtain identity documents or account access.

Detection and mitigation

IDV providers use presentation attack detection, often called PAD, alongside document authenticity checks, biometric matching, device and network signals, and fraud-risk analysis. Active liveness prompts, such as asking a user to perform a randomized action, can make simple replay attacks harder.

No single control reliably detects every deepfake. Effective programs combine technical controls with step-up review for higher-risk cases, monitor attack patterns, and test systems against current synthetic-media techniques.