Reality Defender says it successfully enrolled a real-time face swap into Google’s new selfie-video sign-in feature during two controlled tests, showing that the enrollment process accepted a synthetic identity supplied through manipulated camera input.
The security company used an eligible personal Google account under its control. A live operator followed the movements requested by Google while commercially available face-swap software presented another person’s appearance to the camera. Both enrollment attempts were accepted on a computer running Windows 11 and Microsoft Edge with an Nvidia graphics processor.
Google introduced the optional feature as a backup method for account access and recovery. An account holder records a short selfie video during enrollment and can later capture another video when Google needs to confirm that the same person is present. The design is intended to give users a recovery option when a password or device-based method is unavailable.
Reality Defender’s test targeted the first step. If a synthetic face is accepted during enrollment, the account may bind future recovery to the injected identity rather than the real appearance of the account holder. The company used an off-the-shelf face-swap tool and did not build a custom model or exploit a software vulnerability in Google’s systems.
The result does not show that an attacker can enroll a face without first having access to an account, nor does it demonstrate takeover of another person’s account or a successful recovery using the synthetic enrollment. It is evidence of an enrollment weakness under the specific hardware and software conditions tested. Reality Defender conducted two attempts, so the test does not establish a general success rate across devices or accounts.
The finding follows the rollout of Google’s selfie-video backup for eligible personal accounts. It illustrates why biometric recovery systems need to validate not only that a face is moving but also that the image originates from a live camera rather than a virtual or altered video stream.
Injection resistance has become a distinct requirement alongside presentation attack detection. Recent independent testing of Innovatrics’ liveness and identity verification tools, for example, separately examined attacks delivered through a digital video channel. Reality Defender argues that similar deepfake detection should be applied before a biometric reference is accepted for future authentication.
Sources: Reality Defender
–
By Ji-seo Kim








Follow Us