...

AI-created fake ID images – can they fool identity verification technology?

A new fear of businesses has been unlocked: realistic fake ID images created by AI. In February 2023 news agencies picked up a story about darkweb app known as OnlyFake which purports to use neural networks to generate fake ID images that can be used to fool remote identity verification tools. Sites like Bitcoin, which require only a photo of an ID to sign up, are at risk from customers using AI-generated fake IDs to sign up under a false identity.

Major advances in the capabilities and availability of artificial intelligence have been a concern for fraud watchdogs over the past several years, so our team quickly jumped to action to see just how good these AI-created fake IDs could be.

Testing the OnlyFake App

The site OnlyFake is easily accessible via a Google search. It is a free site for AI-generation of adult images. As most of the news articles referenced “Only Fake” we decided to briefly try the site to see if it was the culprit, responsible. A quick prompt of “woman’s Louisiana drivers license” quickly produced the following image.

OnlyFake generated image

Although all AI needs prompts and training to generate the desired result, this image was so far off from a visually passable ID, let alone one that would scan and fool an ID scanner, we figured this site couldn’t be the location that fraudsters were using to generate their forged documents.

Secret Telegram Channel for Fake ID Images

Several of the news articles referenced the Telegram application and a shared channel where fraudsters were discussing their new, AI-created fake ID images. At the beginning of the now-locked thread we saw the following message in reference to the recent news.

AI-created fake IDs

In the thread were dozens of messages, many in Russian, discussing availability of various fake document formats (both drivers licenses and passports). Linked from the Telegram thread is the .RU site Passport Cloud, which has a fake ID generator with a user friendly interface and a familiar face on the sample ID. Passport Cloud claims to have examined 5,000 drivers licenses to build their AI.

Cloud Passport fake ID generation tool

Once into the tool it becomes obvious that while AI may have been used to create visual templates, the bogeyman site is simply just a programmatic fake ID generator. The user selects their country and then enters the desired data for the fake identity they want to use. Notably, the site offers all North American jurisdictions: every Canadian province and every US state. So we started the process to see if Cloud Passport could generate a fake ID that could pass parsing or barcode security.

Notably, because the tool is only generating an image of a fake ID, these IDs will be useless in any brick-and-mortar scenario, or when used to attempt to bypass ID authentication (as they will not have ultraviolet or infrared markings). The only way these AI-generated fake IDs can be used is in scenarios in which an image of an ID can be uploaded. So any company who is requiring a live capture of an identity document, or who is performing document liveness, can consider themselves safe from these fraudulent IDs.

Do AI-generated fake IDs work?

From the Telegram thread we pulled several examples of fakes generated on the Passport Cloud website. This Pennsylvania ID looks legitimate and has the visual features you would expect on a real ID,but the question is: will it scan?

Front and back of AI-generated fake ID

We quickly ran the ID through our software to see if the barcode generated by CloudPassport would fool any of our barcode security tools. The AI-generated fake ID does not pass our identity verification software.

Unfortunately for fraudster John Wick, his ID was flagged as a fake immediately with a simple 2D barcode scan. Although Cloud Passport claims they know how to generate a PDF417 barcode that is scannable, when we used AI to examine the way the data is formatted inside the barcode our software determined something was off and flagged the ID as fake.

AI generated fake caught by VeriScan software

Although we can’t share the exact reasons we were able to identify this John Wick ID as fraudulent as our algorithms are proprietary, rest assured that we successfully flagged all of the IDs generated from Cloud Passport. This highlights the importance of 2D barcode security. If software is merely reading/parsing the data on the ID, and not looking for data anomalies based on a large data-set of scanned IDs, you might let an AI-generated fake ID slip through.

Cloud Passport addresses the issue of scannable fake IDs in their FAQ.

Do barcodes pass verification in such scanners as BCS and Show me ID, as well as when verifying exchanges and other services?

Yes. Our barcodes are 100% similar to the original. But it is also worth considering the fact that such scanners as BCS and Show me ID can even detect real DL or FAKE, especially old versions of DL.

So Cloud Passport can’t seem to decide whether they claim to actually produce passable fakes, or whether the fakes can be caught use basic ID scanner apps.

AI-generated fake passports

Passport Cloud also offers the option to generate a fake passport, and this should be slightly more concerning to businesses. While passports have many physical security features, and RFID chips, these features become moot when the passport is converted to a 2D image. A 2D image of a passport will be read/ingested using MRZ reading, which converts the data in the passport MRZ into text fields. MRZ scans can do some security checks to ensure the data is formatted correctly, but due to the relatively small amount of data stored in a machine readable zone, and the global standardization, MRZ formatting is straightforward and most fake passports will be parseable. This is why live document capture is crucial in fraud prevention.

Catching AI-created fake ID documents

There are three important protocols to ensure your business is protected from AI-generated fake IDs:

  • 2D barcode security which examines the ID’s barcode for anomalies and formatting issues. Our AI has been trained on millions of ID’s and can catch many fake IDs without even examining the visual elements on the ID.
  • Live document capture. Allowing customers to upload previously captured images allows them to use ID documents that they do not currently possess. We recommend all customers only allow for document capture using the camera on their mobile device.
  • Third party checks. A check against the DMV database or IdentiFraud will tell your business whether the ID number, address, name, and date of birth match IDs they have issued.

Pairing a stolen identity with an AI-created fake ID

More concerning than the fake ID-generator itself was the talk in the Telegram thread of fake identities for sale. These identities would allow fraudsters to create fake IDs using real personal information such as name, address, and date of birth. The inclusion of real personal data means that even third party checks could potentially pass as legitimate. This is why all three methods for catching fake ID documents are critical.

Are AI-generated fraud tools a key risk

Absolutely. Fraudsters have more tools than ever at their disposal. However, fraud tools like Cloud Passport have likely not examined enough IDs and passports to create truly 1-to-1 fake IDs using AI. And there are multiple layers of protection that businesses can easily implement to make fraud more difficult, even with the use of an AI-generated fake ID.

If your business is worried about the thread of fake IDs, contact us to see how we can combat all types of identity fraud.