News Security Technology

Global Digital IDs Need Upgrade To Combat AI Deepfakes : Report

facial-recognition-technology-scan-detect-people-face-identification
Cybersecurity threats to national identity systems have quadrupled since 2020, driven by generative AI’s ability to bypass biometric checks, according to The Alan Turing Institute

Governments worldwide must immediately implement a comprehensive “Digital ID Safety Pack” to protect their national digital public infrastructure (DPI) from highly sophisticated cyber-attacks, warned a new report from The Alan Turing Institute’s Cyber Threat Observatory.

The report, released as part of the Institute’s Trustworthy Digital Infrastructure initiative, highlights an unprecedented rise in threats, arguing that the proliferation of generative AI tools has made it easier for malicious actors to create deepfakes and manipulated synthetic biometrics that can bypass identity verification systems.

The alarming trend is backed by data showing that Common Vulnerability Exposures (CVEs) associated with identity systems have increased by 300 per cent between 2020 and 2024.

AI Threat Bypassing Verification

The Observatory’s analysis focused on how attackers can leverage AI to create synthetic or manipulated biometric content. Real-world examples already underscore the danger: research cited in the report found that deepfake videos successfully passed face biometrics checks in Nigeria’s remote voter registration system 80 per cent of the time.

This synthetic threat manifests across the digital identity lifecycle, from biometric presentation attacks to document injection and the creation of entirely synthetic ID documents.

According to the Institute, advanced economies have already seen sudden surges in identity fraud, with the UK experiencing a 500 per cent increase in attacks using synthetic identities over three years. With countries across the Global South rapidly expanding their own DPI systems, the report stresses the critical need for early, robust protection.

Mandatory ‘Safety Pack’

To meet a minimum cybersecurity baseline and preserve the integrity of DPI, The Alan Turing Institute advocates for a multi-layered defence, encapsulated in its recommended “Digital ID Safety Pack.”

The core technical components of this essential upgrade include:

Zero Trust Architecture: Moving away from traditional perimeter security models.

Biometric Anti-Spoofing: Mandatory liveness detection to ensure the biometric sample is coming from a live person, not a presentation attack like a mask or photo.

Multi-modal Verification: Using a combination of biometrics (e.g., face, fingerprint) to increase security.

Encryption for any stored biometric templates.

Deepfake Detection: Utilising AI specifically to identify manipulated content.

Secure API Design and rate limiting to prevent brute-force attacks.

Beyond technology, the Safety Pack requires policy measures, including establishing coordinated threat intelligence sharing platforms, adopting internationally aligned standards, and incorporating DPI safeguard principles around harm, exclusion, and providing effective redress for citizens affected by fraud.

The most common vulnerabilities exploited in recent years, the report noted, were related to improper or missing authentication, incorrect authorisation, and the exposure of sensitive information, often found in federated digital identity and single-sign-on (SSO) systems.

The findings will be formally presented at an online workshop next week, where the Institute will discuss the implementation roadmap for the proposed safety measures.

Leave a Reply

Your email address will not be published. Required fields are marked *