This is the defining story. During adversarial testing, I escalated through three phases of attack complexity: physical presentation attacks (printed photos, screen replays, 3D masks), generative AI attacks (deepfakes, face swaps, face morphs using 40+ tools), and injection attacks (virtual camera injection, API-level synthetic image submission).
One of the earliest and most consequential discoveries was also the simplest. A $2 nylon stocking mask successfully spoofed the liveness detection. The mask preserved enough facial geometry to pass depth analysis while defeating texture detection. This wasn't just a Facia vulnerability. I tested the same attack against Amazon Rekognition, one of the most widely deployed facial recognition services in the world. It worked. I also spoofed BioID's liveness detection.
I documented the AWS finding publicly on LinkedIn. The point wasn't to embarrass a vendor. It was to demonstrate an industry-wide gap. If a $2 mask can defeat a billion-dollar cloud provider's liveness check, the entire industry needs to rethink its approach to presentation attack detection.