E-Banking Security ABCD Annex: Good Practices for Countering Deepfake Attacks
The regulator issues an annex outlining good practices for authorized institutions to strengthen defenses against deepfake attacks targeting identity verification. Institutions are required to implement robust device security controls, diverse liveness tests, and advanced image analytics to detect fraudulent attempts. Additionally, the document mandates enhanced fraud monitoring, end-to-end security integration, regular system reviews, and comprehensive staff training to maintain a multi-layered defense system.
Annex
Good Practices for Countering Deepfake Attacks
To further enhance AIs’ defence against common deepfake attacks that target
their identity verification solutions, AIs should review the relevance of the
following good practices and take appropriate action(s) to enhance deepfake
detection capabilities:
Strengthen device security controls – implement robust controls to ensure
that customers’ devices are secure and that mobile banking applications can
directly access device cameras for secure image capture without
manipulation (e.g. video injection1
).
Ensure the robustness of identity verification solutions – incorporate a
diverse and randomised set of liveness action tests during identity verification,
and take appropriate follow-up actions in response to abnormal verification
attempts.
Equip systems with deepfake detection capabilities – as part of these
deepfake detection capabilities, AIs are strongly encouraged to implement
image analytics solutions, such as face similarity detection and background
analysis, to further enhance their ability to detect fraudulent verification
attempts.
Enhance fraud monitoring capabilities – collect and analyse abnormal
digital footprints and transaction patterns that may signal potential deepfake
attacks.
Implement end-to-end controls to support deepfake detection – establish
comprehensive processes that integrate deepfake detection solutions with
other security controls, such as device security checks, transaction
monitoring, manual reviews, and quality assurance checks, to provide a
multi-layered defence system.
Conduct regular reviews – conduct regular reviews to assess the
effectiveness of facial recognition solutions, including deepfake detection
capabilities.
Equip and train staff – provide comprehensive training to staff responsible
for manual checks, equipping them with necessary skills to effectively
identify and respond to deepfake attacks.
1
This involves compromising device security to feed images and videos directly to a device, thereby
substituting the device’s genuine camera source.
More like this from HKMA
HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.