iProov says a mobile KYC attack scenario developed by its internal red team has been accepted as a case study in MITRE ATLAS, the threat knowledge base focused on adversarial techniques against AI-enabled systems. The company frames the inclusion as recognition that modern remote verification risk extends beyond classic presentation attacks.
In the scenario described by iProov, the attacker bypasses the physical camera entirely by replacing the live feed at the software layer. That approach allows synthetic video to enter the capture pipeline upstream of liveness detection and face analysis, which iProov characterizes as a "defeat the sensor" attack because it targets the integrity of the camera path itself.
iProov outlines a toolchain that combines real-time face-swap generation with an Android camera injection method, using OBS for streaming and a virtual camera application called Virtual Camera: Live Assist. The company says the technique can work on non-rooted Android devices, increasing the practicality of the attack against real-world mobile onboarding and account access flows in sectors such as financial services and cryptocurrency.
Alongside the MITRE ATLAS publication, iProov points to CEN 18099 as a relevant European standard for evaluating how remote identity verification systems hold up against camera injection. The company argues that resilience to injection-style attacks should be explicitly tested and procured for, rather than treated as an implicit property of liveness checks.
Sources: iProov, MITRE ATLAS
—
By the ID Tech Editorial Team