SardineCon SF/2026

Learn More
AI & emerging fraud4 分で読めます

Live video deepfakeとは?

SUBSCRIBE

A live video deepfake is a fake video stream manipulated in real time to beat a live check, like a video ID review or an agent-assisted identity call. It is harder to pull off than a pre-made clip, but it defeats liveness prompts that assume a real camera and is often paired with tools that inject the feed directly.

What is a live video deepfake?

A live video deepfake is a deepfake generated and manipulated in real time during a live session, rather than recorded in advance. The attacker drives a synthetic face on a moving video stream as the check happens, so it can respond to prompts, turn, and react the way a genuine live participant would.

It targets the checks that were designed to be harder to fool: video ID reviews and agent-assisted identity calls, where a person or system watches someone in real time. The whole premise of a live check is that a recording cannot respond in the moment, and a live deepfake attacks exactly that premise by responding in the moment.

It is harder to pull off than a pre-made clip because it has to run convincingly in real time under interaction, but that difficulty is falling. It is frequently paired with injection tools that feed the manipulated stream straight into the camera feed, so the reviewing app or agent believes the video came from a real camera when it did not.

How a live attack works

A real-time deepfake session typically runs like this:

  1. Setup — Drive a synthetic face. The attacker runs a model that maps a target or synthetic face onto their own live movements.
  2. Inject — Feed it as the camera. Injection tools pipe the manipulated stream into the video feed so it appears to be a real camera.
  3. Interact — Respond in real time. The fake face follows the reviewer's prompts, turning and reacting as the session unfolds. Weak reviewTrusts the live feedA convincing real-time face passes because the check assumes a real camera.Strong reviewChallenge and integrityUnexpected prompts plus injection detection expose latency and artifacts.
  4. Clear — Pass the check. If the controls trust the interaction, the session is approved as a genuine live person.

What it looks like in practice

In practice

A high-value onboarding routes to a live video review, where an agent asks the applicant to hold up their ID and answer a few questions. The face on screen moves naturally and responds to the questions, and the ID matches, so on the surface it looks like a clean live check.

What the agent cannot see is that the video is an injected real-time deepfake. The tell only appears when the agent goes off script and asks the applicant to slowly pass a hand across their face and then look sharply to one side. In that unexpected moment the rendered face smears at the fingers and lags behind the motion, and the device telemetry shows a virtual camera rather than a real sensor. The live session was passed by the fake right up until the moment it was made to improvise.

Why a passed call is not proof

The dangerous assumption is that a real-time, interactive video session cannot be faked, so passing it proves the person is real. A live video deepfake breaks that assumption directly, which means a passed live session should be treated as one strong signal, not conclusive proof. A determined attacker can and does pass the call.

The defenses that hold up combine several layers: injection-attack detection to catch a feed that did not come from a real camera, challenge-response prompts that ask for an unexpected action the fake struggles to render in real time, device and telemetry integrity checks, and analysis of latency or visual artifacts. Because any one of these can be beaten by a good attacker, the right move is to weight the other evidence too and never let the live session carry the decision alone.

What to watch in the data

  • Virtual camera devices. Telemetry showing a virtual or injected video source instead of the device's real sensor.
  • Latency and lag. A face that responds a beat late to prompts, or motion that the render struggles to keep up with.
  • Improvisation failures. Warping or smearing when the reviewer asks for an unexpected, non-standard action.
  • Artifact under motion. Edge distortion around the face, hands, or hair that appears specifically during movement.
  • Feed integrity gaps. Missing sensor noise, lens behavior, or timing that a genuine live capture would show.

Quick questions

How is this different from a regular deepfake?

A regular deepfake can be a recorded clip. A live video deepfake is generated in real time during an interactive session, so it can respond to prompts, which is what lets it defeat live checks a recording could not.

Why is real time harder for attackers?

Rendering a convincing face that reacts instantly, under interaction, with no perceptible lag is technically demanding. That difficulty is why challenge prompts and latency analysis are effective, though the gap is narrowing.

What is injection-attack detection?

It identifies video being fed directly into the camera feed rather than captured by a genuine camera. Since live deepfakes are usually injected, catching the injection is a powerful defense.

Do challenge prompts really help?

Yes. Asking for an unexpected, specific action forces the fake to improvise in real time, which commonly exposes lag and warping that a scripted or pre-rendered fake would avoid.

Can an agent spot it by watching carefully?

Not reliably. Good live fakes pass human review. Agents should rely on injection detection, device telemetry, and structured challenges rather than judging authenticity by eye.

Is a passed live session ever enough alone?

No. Treat it as one strong signal and weight device, telemetry, and behavioral evidence alongside it, because a skilled attacker can pass the call itself.

Go deeper

Live video deepfakeと併せて知っておきたい用語