Warning on multi-layered security in identity verification as deepfake risks grow

The proliferation of AI-powered deepfake content has called into question the security of remote transactions based solely on facial recognition.

12punto

The rapid development of generative artificial intelligence technologies is bringing new security debates to remote identity verification processes. Deepfake content, produced from the images and voices of real people, can target verification methods used in areas where remote transactions are conducted, particularly in banking, telecommunications, insurance, and public services.

biOnay, a developer of identity verification solutions, stated that in the face of these risks, systems based solely on facial images may not be sufficient. According to the company, security should be supported by scanning the chip-enabled Republic of Turkey Identity Card, checking the secure areas on the card, and, when necessary, verifying the fingerprint stored on the chip.

AI-powered technologies are bringing new security needs to the forefront of identity verification systems.

FACIAL RECOGNITION MAY NOT BE ENOUGH ON ITS OWN

While deepfake technologies can mimic facial images, it is emphasized that it is not possible to replicate physical chip-enabled identity cards and the fingerprints stored on the chip in the same way. For this reason, experts point out that models that do not rely on a single biometric data point and instead use different security elements together are gaining importance.

The Personal Data Protection Authority's (KVKK) document titled "Recommendations on the Protection of Personal Data in Artificial Intelligence Systems" also states that AI systems can create new risks regarding personal data. The document specifically states that principles of data minimization, security, and accountability must be observed in the processing of biometric data.

In the Electronic Identity Verification System (EKDS) approach, verification is not based solely on image analysis. The process uses the secure information on the individual's chip-enabled identity card in conjunction with a simultaneous fingerprint verification of the cardholder. Thus, security is moved beyond a single-layer check like facial recognition.

The protection of biometric data is among the critical topics of identity security in the age of artificial intelligence.

biOnay General Manager Ümit Yaşar Usta said that artificial intelligence is not only used on the defense side, but that attackers can also benefit from the same technologies. Usta stated, "Artificial intelligence is not only used on the defense side. The same technology can also be used to create more realistic deepfake images and to develop new methods to deceive identity verification systems."

Usta noted that relying solely on facial recognition technologies, especially in video conferencing or remote identity verification processes, could create greater risks in the future, and that identity verification should be supported by a secure element possessed by the individual. He expressed that multi-layered models, where chip-enabled identity cards, cryptographic verification, and biometric checks are used together, can provide stronger protection.

It is also emphasized that not storing biometric data in central systems creates an additional layer of security in terms of protecting personal data. Usta reported that in some cases, fraudsters who managed to open bank accounts with fake identities were detected during the chip and fingerprint verification used at Land Registry Offices.