Content Moderation

Biometric Spoofing Attack Simulation for Face Recognition Systems

Image

We supported a long-term biometric security project focused on testing and improving face recognition systems under real-world attack scenarios. We acted as the operational link connecting a large, diverse contributor base with the client’s anti-spoofing platform, resulting in realistic attack data and actionable performance insights.

The project was built around controlled print and replay attacks, where participants actively attempted to bypass the client’s system. This hands-on approach allowed the client to continuously evaluate system robustness and track improvements over time.

Image

Task

The client needed real-world spoofing attempts to test and improve their face recognition and liveness detection system. Participants were invited to actively try to bypass the system, rather than simply submit passive data.

The main attack types included:

  • Print attacks using printed photos manipulated in different ways
  • Replay attacks attempting access via replayed visual material on devices

Each attack attempt was evaluated by the client’s system and assigned a score, reflecting how convincing and successful the attempt was.

Key challenges included:

  • Attracting and retaining participants willing to repeatedly test and “break” the system
  • Ensuring high variability across attacks (devices, print quality, lighting, backgrounds)
  • Coordinating technical integration between crowd platforms and the client’s interface
  • Capturing detailed behavioral data without direct access to the client’s internal system

Solution

Preparation and technical setup

  • Integrated with the client’s platform through an external execution interface, redirecting participants from the crowd platform to the client’s system
  • Worked via an existing enterprise account to manage task launches and participant access
  • Designed task flows that encouraged experimentation rather than one-off submissions

Attack execution process

  • For print attacks, participants received a facial image, printed it, and physically manipulated it (bending, rotating, folding) while attempting to pass system checks
  • Successful or near-successful attempts unlocked the option to return and retry, motivating participants to improve their techniques
  • Replay attacks were collected in parallel and reached target volume faster, while print attacks required longer-term iteration
  • Ensured broad diversity across:
    • age groups
    • ethnic backgrounds
    • devices and cameras
    • print materials and presentation styles

Monitoring and reporting

  • Tracked participant behavior step by step: number of attempts, repeat participation, and attack outcomes
  • Delivered weekly reports to the client, including:
    • number of new attacks
    • print vs. replay breakdown
    • new vs. returning participants
    • system response trends
  • Held regular review calls to align on findings and system performance changes
StageInputWorkflow ScopeMain Quality Checks
Project SetupClient platform & anti-spoofing requirementsIntegration via external interface, task flow design, access configurationSystem connectivity / Task logic robustness
Participant OnboardingGlobal contributor poolRecruitment, onboarding, adversarial task briefingParticipant diversity / Instruction clarity / Attack readiness
Attack ExecutionUser devices, printed images, replay materialsPrint & replay attacks, iterative submissions, retry-based engagementAttack variability / Scenario realism / Adversarial complexity
Behavior TrackingAttack attempt dataTracking retries, repeat participation, attack progressionData completeness / Iteration patterns / Strategy consistency
Validation & AnalysisSystem-scored attack dataScore review, performance analysis, false acceptance signal detectionScore reliability / Attack success signals / Edge-case identification
Reporting & IterationValidated attack datasets Weekly reporting, trend analysis, continuous feedback loopTrend accuracy / Model response shifts / Continuous performance alignment
Pilot & Setup
2 weeks
Participant Onboarding
3 weeks
Attack Collection & Iteration
ongoing
Monitoring & Reporting
weekly, ongoing

The Results

  • Generated a large and diverse set of realistic spoofing attempts over a two-year period
  • Helped our client continuously refine and harden their biometric system
  • Observed measurable improvement in system resistance as attack strategies evolved
  • Built a sustainable feedback loop between real users and biometric security engineers
A system tested only in controlled conditions hasn't really been tested, the gaps always show up in production.
Hanna Parkhots
Hanna Parkhots
Data Collection Project Manager

Similar Cases

Arabic Language Data Annotation for LLM Evaluation

  • Telecom, AI
  • 7 weeks
Learn more

Fight Detection for Surveillance Systems

  • Security, Video Analytics
  • 200 professionally produced 4K videos
  • 2 weeks
Learn more

Image Data Collection for Hair Loss Classification Task

  • Medicine
  • 200 annotated sets
  • 1.5 months
Learn more

AI stress-testing for a Biometric Liveness Detection Model

  • Biometrics
  • 1 week
Learn more

Audio Data Collection for Emotion-Sensitive Voice Systems

  • Development of child response systems for laughter and crying
  • 750 unique audio files featuring children's voices
  • 1 month
Learn more

Ready to get started?

Tell us what you need — we’ll reply within 24h with a free estimate

    Andrew
    Head of Client Success

    — I'll guide you through every step, from your first
    message to full project delivery

    Thank you for your
    message

    It has been successfully sent!

    We use cookies to enhance your experience, personalize content, ads, and analyze traffic. By clicking 'Accept All', you agree to our Cookie Policy.