SardineCon SF/2026

Learn More
AI & emerging fraud4 min de lectura

¿Qué es Face swap?

SUBSCRIBE

A face swap replaces one face with another in an image or video to beat face-match or impersonate a specific person during a check. It shows up in selfie checks, video ID reviews, and account-recovery flows, and it is increasingly injected straight into the camera feed rather than held up to the lens.

What is a face swap?

A face swap is a specific deepfake technique that replaces one person's face with another in a photo or video. In fraud it serves two goals: getting past a face-match check with a synthetic or borrowed face, and impersonating a particular real person, for example to take over their account or recover access in their name.

It attacks any flow that trusts a face as identity: selfie checks at onboarding, video ID reviews, and account-recovery paths that ask you to prove you are the account holder. Because the swapped face can be made to match a target's document or profile photo, it defeats the simple logic of comparing a live face to a stored one.

The important trend is how the fake reaches your system. Rather than holding a screen up to the camera, attackers increasingly inject the swapped video directly into the camera feed, so the app receives a manipulated stream while believing it came from a real lens. That injection is what fools tools built on the assumption that whatever arrives from the camera is genuine.

How a face-swap attack runs

A typical injected face-swap attack moves through these stages:

  1. Target — Pick the identity. The attacker chooses a real person to impersonate or a synthetic face to onboard.
  2. Build — Generate the swap. A model maps the chosen face onto a driving video so it can move, blink, and respond.
  3. Inject — Feed the stream. Instead of showing a screen to the lens, the fake video is piped straight into the camera feed. Weak checkPassive liveness onlyStudies a still selfie and can be satisfied by the injected face.Strong checkActive plus injection detectionUnexpected prompts and feed-integrity checks trip the fake up.
  4. Pass — Clear the check. If the controls trust the feed, the swapped face passes as the real person.

What it looks like in practice

In practice

A customer calls in locked out, and the recovery flow asks for a quick selfie video to confirm identity against the photo on file. The video comes back and the face matches; on the surface, the recovery should go through. But the risk system flags that the video shows no real camera characteristics, no natural sensor noise, no expected lens behavior, and the app reports a virtual camera device rather than the phone's own.

When an agent adds a live challenge, asking the caller to turn their head a specific way and read an unexpected phrase, the swapped face lags and warps at the edges. The match was real, but the face was not; the feed-integrity and challenge signals, not the resemblance, exposed it.

Why passive liveness is not enough

Passive liveness, the kind that studies a still selfie for signs of a real person, was designed for a world where the attacker had to physically present something to a camera. A face swap injected into the feed sidesteps that assumption entirely, because there is no physical presentation to catch and the injected face can be made to look alive enough to satisfy a passive check.

The stronger posture combines liveness detection, injection-attack detection, and consistency checks across the face, the document, and the device. Active prompts that ask for an unexpected action are hard for a prepared swap to follow in real time, and feed-integrity checks catch a stream that did not come from a genuine camera. The rule of thumb: never let a passive selfie stand alone, because that is exactly the check a face swap is built to beat.

What to watch in the data

  • Virtual cameras. The app reporting a virtual or unknown camera device instead of the phone's real sensor.
  • Feed without a camera. Video that lacks the sensor noise, lens behavior, and timing of a genuine live capture.
  • Edge artifacts. Warping, blurring, or flicker around the hairline, jaw, and ears, especially during motion.
  • Challenge failures. Lag or distortion when the user is asked to perform an unexpected action in real time.
  • Face, document, device mismatch. A face that matches the photo but sits on a device or session with inconsistent or impossible signals.

Quick questions

How is a face swap different from a deepfake?

A face swap is one type of deepfake, specifically replacing one face with another. Deepfake is the broader category that also covers fully generated faces, voice clones, and manipulated video.

What does injecting the feed mean?

Instead of showing a screen or photo to the camera, the attacker pipes the fake video directly into the camera feed using a virtual camera or injection tool, so the app receives a manipulated stream as if it were live.

Why do challenge prompts help?

A prepared swap struggles to respond correctly to an unexpected, real-time action. Asking for a specific movement or phrase forces the fake to improvise, which often reveals lag and warping.

Can a face swap beat photo match?

Yes, easily, because the swap is built to match the target's face. Photo match alone is weak against it; pair it with liveness, injection detection, and device consistency.

Where do face swaps hit most?

Selfie checks at onboarding, video ID reviews, and account-recovery flows, anywhere a face is treated as proof of who someone is.

Is a passed selfie ever enough on its own?

No. Treat a passed face check as one signal among several. Weight device integrity, feed authenticity, and behavior so a single spoofable check never carries the whole decision.

Go deeper

Qué saber junto con Face swap