Researchers claim they used 3D masks and photos to deceive facial recognition systems used by Alipay, WeChat Pay, Schiphol Airport, and train stations in China
Masks and simple photographs are enough to fool some facial recognition technology, highlighting a major shortcoming in what is billed as a more effective security tool.
Context & Ripple Effects
This is the second act of a spoofing saga that opened in 2016, when researchers fooled AI face systems with printed paper eyeglass frames — cheap props defeating expensive models. What changes here is stakes: the targets are no longer lab demos but live payment rails (Alipay, WeChat Pay) and border/transit checkpoints at Schiphol and Chinese train stations.
The aftermath coverage shows both sides escalating: by early 2020 Hanwang was selling masked-face identification to the Chinese government with claimed 95% accuracy (Hanwang's masked-face system), and by mid-2021 attackers had moved from physical masks to synthetic faces, with nine computer-generated 'master key' faces impersonating roughly half the faces in three top systems (master-key generated faces).
First-order effects
- Alipay, WeChat Pay, Schiphol and Chinese transit operators must treat face-only verification as spoofable today, forcing immediate investment in liveness detection rather than treating it as a future upgrade.
- Users of face-based payment and boarding gates absorb the risk directly: their face can be replayed by anyone with a photo or a mask, not just stolen in the abstract.
Second-order effects
- Vendors compete on anti-spoofing as a feature: Hanwang's pivot to identifying masked faces for the Chinese government shows the spoofing problem becoming a product line, not a patch.
- The attack toolkit migrates downstream to activists and fraudsters, as later reporting on mask, paint and identity-blending evasion documents, spreading payment-fraud exposure beyond the original research settings.
Third-order effects
- If physical spoofs are this cheap, face recognition cannot stand as a single-factor gate for money movement or borders, pushing deployments toward layered authentication — a shift the later master-key research reinforces by attacking the models themselves.
- Regulators and standards bodies gain a concrete failure case to cite when weighing mandatory accuracy and anti-spoofing requirements for biometric infrastructure in finance and transport.
The trend: Facial recognition is locked in an escalating spoof-versus-liveness-detection arms race, where each cheap attack — paper glasses, 3D masks, generated faces — forces vendors to sell resilience as the product.