Very good. So, good afternoon. I'm Andrew Bud, founder and CEO of iProov. This is a rhetorical question. Let me start by asking, put your hand up if you work for a company that uses video ident, either for user authentication, user onboarding, or for employee onboarding today. It's widely used throughout the whole continent of Europe, and it is almost ubiquitous in Germany, where we are today. And the real question is, what's going to happen? What is its future?
So, video ident, for those of you who don't know, it is a process whereby you undertake an onboarding check of documents and faces by undertaking a two or three minute video call in which the customer or employee holds up their document and presents their face. This was introduced in Germany in 2013 and has widely spread throughout Europe, and it is very widely used.
And when it was introduced in 2013, it was an innovative and very effective way of solving a very serious problem, which was how to confirm a person who wasn't in your branch office, who wasn't physically in front of you, how to confirm that they were whom they claimed to be. And it was incredibly effective, and it overcame many of the problems that would otherwise have formed. The task was to mitigate two risks.
Firstly, was this the right person? Did the person who was presenting themselves look like the photo in their photo ID? And secondly, were they actually a real person and not, say, a photograph? You have to go back to 2013 and remember that in those days facial recognition technology worked really, really badly. Asking a facial recognizer to look at a remote person and automatically make a match was a really poor experience. Most of the time it didn't work.
Now, after 2016 and the introduction of deep learning-based face matching, the world changed, and by 2019, as we'll see in a second, it was completely different. But at the time when Video Identity was created, a video call was the best way of making sure that the person looked like the image on their identity document, and in those days it was already possible for people to produce color photocopies of their identity document, so it was important to make sure that they were holding up a real identity document and not a forged one.
But when let's talk about the people, as regards making sure that it was the right person but also a real person and not a photograph of themselves, which after all was an easy thing to do, even in 2013 it was understood that a person's face is not a secret. It's not some sort of secret that has to be held away and kept secret because real people's faces are all over the place and therefore the way you attack any biometric system is not by compromising the biometric but by producing a copy of it and by doing a video call you could make sure that you were looking at a real person, right?
But since 2013 you'll be astonished to know times have changed. The attacks that Video Identity was set up to create, that is the presentation attack, a physical, a photograph, or an object, or a mask, a lot of discussion about masks, in front of the camera that that was the primary way of attack has been displaced by a new attack method called the injection attack.
With an injection attack, a digital image typically created by generative or deep learning based AI of the person is digitally injected straight into the data stream of the originating device without ever passing through a camera and therefore without producing any of the cues that a physical presentation in front of a camera unwittingly creates. And whereas people are still preoccupied about photographs and masks, I get asked about masks a lot. Masks don't matter anymore because actually the injection attack is today the attack of choice.
Sorry, I've forgotten this was animated. The other thing that we've learned over the last over the last 10-12 years is that human beings are actually really quite bad at this. A year after Video Identity was introduced in Germany, a study was undertaken in South Australia where they tested under laboratory conditions the face-matching performance of trained passport officers and students. And what they found was that even the trained part, the difference was rather marginal, but even trained passport officers mismatched people 10% of the time. They had a false accept rate 10% of the time.
So actually even trained passport officers were not very good and if you think about minimum wage agents on the end of a video call, you can imagine that their performance was significantly poorer and therefore as face-matching tools they were better than nothing but not much better than nothing. As I said, today we're in the presence of deep fake attacks, imagery which is pixel perfect and indistinguishable to the naked eye.
We recently ran a large-scale practical survey of 2,000 adults around the world and we found that we found that one in a thousand of those could actually reliably detect a deep fake. So the day in which you could put an agent in front of an image or any kind of a person and look at a video and look at an image and kind of go, oh yes that's obviously deep fake. Gone. Passed. Not anymore. Deep fake imagery has become so good that it is undetectable to the naked eye and as an image undetectable also to software.
And then just to close it off, a couple of years ago the Chaos Computer, two and a half years ago, the Chaos Computer Club actually demonstrated an entire video ident session in which an identity document was held up and it was matched to the face of the person. The identity document had been completely deep faked, the face of the person had been completely deep faked. They demonstrated vividly what it must be said the the BSI had shown back in 2016, but nobody listened, that actually video ident no longer was fit for purpose.
Now you could argue this is because the agents aren't trained, that if you train the agents on modern attacks and modern methodology they will keep up, but they can't. Because the threats, the rate at which the threats are evolving is much much faster than any human capability can ever hope to keep up with. From our biometric security operations center, which is by the way the only one in the world that actually observes these things, we saw an eightfold, almost a ninefold increase in injection attacks taking place in the last year.
That means that the old world of presentation attacks of photographs and masks legacy. We have been overwhelmed by injection attacks and the vast majority of those injection attacks are face swap attacks. We'll talk a little bit more about that in a second, quadrupling of them.
And when you look at the different attack variants, the different models, the different tool sets, and there are over 100 tool sets available to do face swaps, the different ways of injecting, the different ways of bypassing injection detection software on phone talks by using native webcams, there are over 100,000 different variants and I'm afraid you can't train agents on the large enough scale to spot that and you probably wouldn't succeed anyway. So we're in an environment in which, we're in a threat environment which doesn't look anything like that of 12 years ago.
The threat environment is moving extremely quickly, driven primarily by for example the face swap. I defy any of you to tell me which of these is the real image. So this is face swap technology. I'm sure many of you have seen it, but there may be one or two of you who are not aware that the days in which you could determine whether a person was real was by asking them to turn their head and smile are so long gone as to be laughable. This is the technology attack mode of preference for attackers today. The tool sets are either free or at low cost.
There are over 100 tool sets on the internet that will enable you to do this and in the attack forums that we monitor, this is the way that the hackers are currently breaking onboarding. So today, methods of remote onboarding have to guard not against two, have to mitigate not two, but three major threats.
Yes, you have to detect whether it's the right person, sorry they're transposed, whether it's the right person and that using modern deep learning based face matching is hundreds of thousands of times more accurate than a person and is dead easy. You have to detect that it's a real person and not a presentation attack. You still have to do that, but it's legacy. What you have to make absolutely sure is that you're dealing with a real person present right now and not Tom Cruise but without the bank account. So how can you solve this problem?
There are many who will claim that deep fakes are dead easy to detect. You just train your networks on the latest deep fakes and you'll spot them and I'm afraid it doesn't work. It's quite clear that it doesn't work because the range and variety of deep fake generators that are out there is so vast and they are moving so fast and it's so easy to perturb them that you cannot detect a deep fake image reliably. Nor can you detect when it has been injected reliably.
There are methods that will catch the incompetent injectors but using the new generation of native virtual webcams running in, for example, Android which bypass all the injection detection, the methods that people have traditionally used to detect behaviorally a deep fake don't work and we have evidence of that.
The way that we found that does work is to combine the creation of physical unpredictability to alter the physics of the very capture scene itself to go beyond the digital domain and into the physical domain and create an unpredictable perturbation and then monitor continuously and we'll talk, detect what's going on, monitor that and adapt and change as fast as the environment. Well sounds fine. What does it look like in practice? Well this is what it looks like in practice.
The way we change the physics is that we illuminate the user's face with a rapidly changing and unpredictable sequence of colors. We're changing the physics of the scene itself and as that face is being illuminated by the screen of the device, any device, we stream video of her face back to our servers where we study the way that the light is interacting with her face. We look at the spatial spectral and temporal characteristics of that reflection and its interaction with the environment.
That creates and it's passive, it's completely passive as you can see the user doesn't have to do anything but it creates an extremely peculiar and difficult problem which attackers can forge badly but fortunately cannot forge well because we are half a billion data points ahead of them in those terms. But what's really important is not just to say great we've got a piece of technology and we've solved the problem and it's all going to work fine forever.
This is an anti-biometric authentication is all about the liveness problem and the liveness problem is a fraud problem and a fraud problem continuously changes.
So it's absolutely essential not just to create the signals using these changing colors but to detect what's going on, to detect the attacks, to pick out of the noise the signal that is there are sequences of attacks, to study, to analyze and to study what the attackers are doing, what new methods they're doing, identify which parts of the academic literature, which parts of the of the dark web these methods are being discussed, to replicate them and to train the systems so that they adapt and respond and are then deployed in real time to all platforms across multiple geographies immediately.
We do this many times a month. We have to do this many times a month and we do it worldwide because otherwise we just create huge holes of vulnerability in our systems. This is the only thing that works. We get attacked we get attacked tens of thousands of times a month and only by continuously keeping up and changing our systems on a daily, on a weekly or daily basis can we stay ahead of the attackers and keep our customers safe.
Last year we did nearly a hundred, we verified nearly a hundred million people and as far as we know and those of our and our customers tell us not a single one of those was a forgery. So let's think for a second because we're in Germany and this is a very very hot topic, very hot topic at this moment in Germany and in Europe. How should we combine humans and software in determining, in doing these remote biometric verifications? There is a very powerful current of opinion in Europe at the moment which says that it should be fully manual.
Let's plot this on the scalability versus security graph. Fully manual as I've shown you is really really poor from a security point of view and it's really really poor from a scalability point of view. It costs 20, 20, 10, 20, 30 euros a time, takes five minutes, requires thousands of people. It's very poorly scalable and as my previous graph showed it doesn't work anyway.
If you allow the user, if you provide an automated tool but have a user supervising what will often happen you might, what will often happen is that the user, is that the agent might take the automated system's advice or it might not and if it overrides it you've actually just degraded the security of the system well still further. If it requires both the automated system and the manual system to agree you do actually get improved security but unfortunately what you'll find is your conversion rate goes down, is destroyed and it doesn't in any way improve the the scalability.
So human in the loop manages to combine lousy scalability and high cost with extremely poor security. But sometimes that is, there is a dialectic created in which you say well the only alternative to this is clearly a fully automated piece of software. Here's a disk, off you go. Many of our competitors supply a disk, a piece of software and say there you are, there's the, there you go. It's very scalable, I mean it works very fast, you can do it at very high speed, you can do it on a global basis.
It's great from a scalability and the day that disk goes out it might very well work extremely well. But over time and when I'm talking time I'm talking days and weeks, the attackers experiment with it and very quickly, very quickly they develop tools, sometimes they'll even train their tools on it which degrade it. So on day one it may be very good from a security point of view but after a relatively short time it ceases to be.
And then if you're lucky after a few months you'll get an upgrade which has, you'll get an upgrade which has to be distributed, maybe you'll get back to the security again but it'll never be as good because it's not informed.
The only thing that actually delivers scalability with security is this hybrid model and that's the term that is being used in the discussions that are taking place in the context of the EU digital identity wallet, in the context of CEN standards, in the context of ISO standards, a hybrid model in which you, it is automated but with expert human analysis adaptation and response powered by signals that give you some chance of success. So after video identification we are going to find this new hybrid and video identification is going to morph, it may continue because maybe customers like it.
Already today many many people are being hired using a form of video identification called the remote interview where people actually are interviewed using video conferencing technology and actually never physically met but are hired.
No before talked earlier, talked last year about the fact that they had done this and managed to hire some guy from middle America, a software coder, very qualified, very capable, interviewed very beautifully, they sent him his his laptop and it was only afterwards that they discovered they'd actually hired a North, a member of the North Korean secret service who had deep faked his face.
So what we're going to find is video identification becomes a subset, effectively becomes a subset of video conferencing but video conferencing as we've seen before is going to be completely worthless, in fact it's going to be almost weaponized unless it's secured by strong liveness detection and when it's secured by long, by strong liveness detection you're going to start to find very interesting questions of user engagement with the spoofs. What do you do if some, if the North Korean hacker pops up do you go, ha ha you're a North Korean hacker and I claim 200 dollars?
So there's going to be a whole new paradigm which we've explored in recent years. Just to close off, I've emphasized to you the security, how critical from a security point of view strong liveness is. Biometrics on their own don't matter anymore, they're an irrelevance, they're really almost an irrelevancy in the security model, the only thing that matters is strong liveness and how do you assess strong liveness? Well you could, you could believe the vendor's own claims, good luck with that, doesn't end well.
You can look for, you can look for standardized tests and certification, the only problem is within the strong liveness sector there is only one standard in the whole world that is a proper recognized international standard with a certification model behind it and that is the new FIDO standard launched last year for biometric verification during onboarding and that works, it's a proper standard, it's well designed, there is a proper certification structure behind it. I think to date at the moment there are either one or two companies in the world that have been certified.
Most vendors who will be knocking on your door will conveniently not have, not have passed this, that tells you something. The third thing you can do is to look for accredited and custom third-party certifications of business processes. The best of these is the EIDAS.
So EIDAS has a mechanism, EIDAS has a mechanism called module certification which permits third-party certification bodies recognized by EIDAS to actually go in and look at the business system, the software and algorithm life cycle to make sure that not only does this system work according to the certification on day one but that there are business processes involved in business processes under the bonnet or the hood depending on which country you're from that will keep the system safe week after week.
There are vendors, including us, who are certified to level of assurance high for qualified trust service at qualified level under article 24 for the delivery of the highest level of certification. And finally, frankly, you look at what other customers have done. One of our customers we believe spent nearly 10 million dollars certifying us. They got an Israeli side, a government got an Israeli cyber security, military cyber security penetration company to spend, to put a team of eight people to spend one year trying to penetrate our deepfake defenses.
If you haven't got those resources, and I think very few people, this was a matter of national security for them, or like the American government, they just they gave a team of similar size only three months to try to break us. These are enormous sums of money which you probably don't have. Most organizations try to assess liveness by taking a couple of photocopies and shoving them in front of the camera and if that if it blocks them then you're good.
This is, these are not toys, this is the core to your security architecture and you'd better take the security of them seriously, in my view, and if you can't afford to spend millions of dollars on testing them, then why go and talk to the people like UBS who spent a year evaluating us, who do. If you'd like to know more about us, come and talk to us. We're on booth 22 on this floor, just on the other side.
We'd be delighted to engage with you, understand your questions, understand your issues, answer your questions and go as deeply as you like into what is, to my mind, the most important and most interesting area of the entire authentic cyber security authentication landscape today. Thank you very much.
Now, Joe, you're going to stay with us for the next session because you're a part of the panel but if anyone wants a question, especially for Joe right now, there's time. Yes, sir, please. When your biometric is doing the flashing colors, how do you tell people when that triggers an illness?
With what, sorry? When it triggers an illness. So there are, that's a very important question. To those of you who don't know, flashing lights can cause photosensitive epilepsy. Fortunately, an international standard, this is not just a problem of iProof, this is a problem for video games, it's a problem for television, it's a problem for all sorts of things.
So fortunately, an international standard, a British standard, was created in 1991, which became a European standard later on in the year, which became an international standard and has been built in both into the Americans with Disabilities Act and to the WCAG accessibility guidelines, which is very precise about the speed at which the flashing should take place. So there is a specific standard that says if you do this, then you are safe for photosensitive epileptics.
And in the 34 years since that standard was introduced by Ofcom, there is not one known recorded incidence of photosensitive epilepsy being triggered by flashing that met the international standards. And we are independently certified to that standard. It's a very good question. It's something we took seriously very from the beginning. But as far as the international answer is concerned, we're safe.
Thanks, Joe.