Facial recognition technology is becoming an increasingly common component of identity verification, supporting applications ranging from airport security and border control to retail fraud prevention and digital onboarding. While these systems offer significant convenience and automation benefits, they also introduce new security challenges as researchers continue to demonstrate ways that machine learning models can be manipulated. As organizations expand their use of biometric authentication, ensuring the integrity of facial recognition systems has become just as important as improving their accuracy.
Recent research highlights one such concern by showing how adversarial machine learning techniques can cause facial recognition systems to misidentify individuals under controlled conditions. Although these attacks currently require substantial expertise, computing resources, and knowledge of the target system, they illustrate why organizations must continuously evaluate the resilience of biometric security technologies against emerging threats.
Just two days ago there was the Rite Aid article describing push back the company received on its facial recognition implementation. Today, we have an MIT Technology Review article describing how facial recognition can be fooled so that it recognizes someone else as you. The research team did this on a system using facial recognition that compares a live picture to that of a passport photo. Here’s more from the article:
“A team from the cybersecurity firm McAfee set up the attack against a facial recognition system similar to those currently used at airports for passport verification. By using machine learning, they created an image that looked like one person to the human eye, but was identified as somebody else by the face recognition algorithm—the equivalent of tricking the machine into allowing someone to board a flight despite being on a no-fly list.
“If we go in front of a live camera that is using facial recognition to identify and interpret who they’re looking at and compare that to a passport photo, we can realistically and repeatedly cause that kind of targeted misclassification,” said the study’s lead author, Steve Povolny.”
The good news is that performing this trick reliably requires access to the system that will be fooled and a significant amount of time and expertise:
“While the study raises clear concerns about the security of face recognition systems, there are some caveats. First, the researchers didn’t have access to the actual system that airports use to identify passengers and instead approximated it with a state-of-the-art, open-source algorithm. “I think for an attacker that is going to be the hardest part to overcome,” Povolny says, “where [they] don’t have access to the target system.” Nonetheless, given the high similarities across face recognition algorithms, he thinks it’s likely that the attack would work even on the actual airport system.Second, today such an attack requires lots of time and resources. CycleGANs need powerful computers and expertise to train and execute.”
As facial recognition adoption continues to grow, organizations should recognize that no authentication technology is immune to sophisticated attacks. Research into adversarial machine learning provides valuable insight into potential weaknesses, allowing developers and security teams to strengthen biometric systems before these techniques become more practical for malicious actors.
For financial institutions, government agencies, and enterprises deploying facial recognition, the focus should extend beyond accuracy to include resilience against manipulation. Combining biometric authentication with layered security controls, continuous monitoring, and adaptive fraud detection will help ensure facial recognition remains a trusted component of modern identity verification.
Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group







