Multiple fraud type detection system and methods
A system and method for multiple fraud type detection includes anti-injection attack system that has a layered architectural approach that uses a includes combination of different specific models to detect the attacks in combination with image processing techniques, device signals and liveness checks to detect the variety of different types of fraud attacks or repeat fraud attacks. The anti-injection attack system applies the analysis of the tools used to create deepfake, face morph and face swap attacks to define the elements of its layered architecture that can these various types of attacks.
1 . A computer-implemented method comprising:
receiving first image data associated with a user;
performing a first detection type comprising a multi-frame deepfake detection model on the first image data to generate a first signal;
performing a second detection type comprising a single frame deepfake detection model on the first image data to generate a second signal;
performing a third detection type comprising a subject and scene segmentation analysis on the first image data, wherein performing the third detection type further comprises generating a vector embedding for the first image data, accessing a matrix of vector embeddings, searching for cosine similarities between embeddings in the matrix and the vector embedding generated, and generating a third signal based on the searching for the cosine similarities;
generating an aggregated fraud score based upon the first signal, the second signal and the third signal; and
accepting the first image data as genuine upon comparing the aggregated fraud score to a threshold to determine if the aggregated fraud score satisfies the threshold.
2 . The computer-implemented method of claim 1 further comprising: rejecting the first image data as fraudulent based upon the aggregated fraud score.
3 . The computer-implemented method of claim 1 wherein the first detection type is one from a group of: a deepfake model, a face morph model, a face swap model, an unknown injection attack anomaly model, a subject and scene segmentation analyzer, an injection checker, a device risk checker, a liveness detector, a face match and face analysis subsystem, an injection attack detector and a device risk detector.
4 . The computer-implemented method of claim 1 wherein the second detection type is one from a group of: a deepfake model, a face morph model, a face swap model, an unknown injection attack anomaly model, a subject and scene segmentation analyzer, an injection checker, a device risk checker, a liveness detector, a face match and face analysis subsystem, an injection attack detector and a device risk detector.
5 . The computer-implemented method of claim 1 wherein the first image data includes a selfie image and a document image, and the method further comprises performing a fourth detection type using the selfie image and the document image to generate a fourth signal, wherein the fourth detection type is a face match and face analysis that compares the selfie image to a holder portion of the document image and generates the fourth signal based on a match between the selfie image and the holder portion of the document image and
wherein the aggregated fraud score is generated based upon the first signal, the second signal, the third signal, and the fourth signal.
6 . The computer-implemented method of claim 1 wherein the first image data includes a selfie image and a document image, and the method further comprises performing the third detection type using the selfie image and the document image to generate the third signal, wherein the third detection type is a face match and face analysis that compares the selfie image to a holder portion of the document image and generates the third signal based on a match between the selfie image and the holder portion of the document image, and wherein the first image data is rejected as genuine based upon only the third signal.
7 . The computer-implemented method of claim 1 wherein the first image data is one from a group of a selfie and a video.
8 . The computer-implemented method of claim 1 wherein the first image data includes a selfie image, and the method further comprises:
receiving a document image;
performing the first detection type on the document image to generate the third signal;
performing the second detection type on the document image to generate a fourth signal; and
wherein the generating the aggregated fraud score is also based on the third signal and the fourth signal.
9 . The computer-implemented method of claim 1 wherein the first image data includes a selfie image, and the method further comprises:
receiving a document image;
extracting selfie metadata from the selfie image;
extracting document metadata from the document image; and
wherein the generating the aggregated fraud score is also based on the selfie metadata and the document metadata.
10 . The computer-implemented method of claim 1 wherein the first image data includes a selfie image and a document image, and the method further comprises performing the third detection type using the selfie image and the document image to generate the third signal, wherein the third detection type is a face match and face analysis that compares the selfie image to a holder portion of the document image and generates the third signal based on a match between the selfie image and the holder portion of the document image.
11 . The computer-implemented method of claim 1 wherein satisfying the threshold indicates that the first image data is acceptable and not satisfying the threshold indicates that the first image data is fraudulent.
12 . The computer-implemented method of claim 1 , further comprising:
performing the third detection type on the first image data to generate the third signal; and
wherein the first image data is rejected as genuine based upon only the third signal.
13 . A system comprising:
one or more processors; and
a memory operably coupled with the one or more processors, wherein the memory stores instructions that, in response to execution of the instructions by the one or more processors, cause the one or more processors to:
receive a first image data associated with a user;
perform a first detection type comprising a multi-frame deepfake detection model on the first image data to generate a first signal;
perform a second detection type comprising a single frame deepfake detection model on the first image data to generate a second signal;
perform a third detection type comprising a subject and scene segmentation analysis on the first image data, wherein performing the third detection type further comprises generating a vector embedding for the first image data, accessing a matrix of vector embeddings, searching for cosine similarities between embeddings in the matrix and the vector embedding generated, and generating a third signal based on the searching for the cosine similarities;
generate an aggregated fraud score based upon the first signal and the second signal and the third signal; and
accept the first image data as genuine based upon comparing the aggregated fraud score to a threshold to determine if the aggregated fraud score satisfies the threshold.
14 . The system of claim 13 , wherein the instructions cause the one or more processors to reject the first image data as fraudulent based upon the aggregated fraud score.
15 . The system of claim 13 , wherein the first detection type is one from a group of: a deepfake model, face morph model, a face swap model, an unknown injection attack anomaly model, a subject and scene segmentation analyzer, an injection checker, a device risk checker, a liveness detector, a face match and face analysis subsystem, an injection attack detector, and a device risk detector.
16 . The system of claim 13 , wherein the second detection type is one from a group of: a deepfake model, face morph model, a face swap model, an unknown injection attack anomaly model, a subject and scene segmentation analyzer, an injection checker, a device risk checker, a liveness detector, a face match and face analysis subsystem, an injection attack detector and a device risk detector.
17 . The system of claim 13 , wherein the first image data includes a selfie image and a document image, and the system is further configured to performing a fourth detection type using the selfie image and the document image to generate a fourth signal, wherein the fourth detection type is a face match and face analysis that compares the selfie image to a holder portion of the document image and generates the fourth signal based on a match between the selfie image and the holder portion of the document image, and wherein the aggregated fraud score is generated based upon the first signal, the second signal, the third signal, and the fourth signal.
18 . The system of claim 13 14 , wherein the first image data includes a selfie image and a document image, and the system is further configured to performing the third detection type using the selfie image and the document image to generate the third signal, wherein the third detection type is a face match and face analysis that compares the selfie image to a holder portion of the document image and generates the third signal based on a match between the selfie image and the holder portion of the document image, and wherein the first image data is rejected as genuine based upon only the third signal.
19 . The system of claim 13 , wherein the first image data is one from a group of a selfie and a video.
20 . The system of claim 13 , wherein the first image data includes a selfie image, and the instructions cause the one or more processors to:
receive a document image;
perform the first detection type on the document image to generate the third signal;
perform the second detection type on the document image to generate a fourth signal; and
wherein the aggregated fraud score is also based on the third signal and the fourth signal.
21 . The system of claim 13 , wherein the first image data includes a selfie image, and the instructions cause the one or more processors to:
receive a document image;
extract selfie metadata from the selfie image; and
extract document metadata from the document image, and wherein the aggregated fraud score is also based on the selfie metadata and the document metadata.
22 . The system of claim 13 wherein the first image data includes a selfie image and a document image, and wherein the instructions cause the one or more processors to perform the third detection type using the selfie image and the document image to generate the third signal, wherein the third detection type is a face match and face analysis that compares the selfie image to a holder portion of the document image and generates the third signal based on a match between the selfie image and the holder portion of the document image.
23 . The system of claim 13 wherein satisfying the threshold indicates that the first image data is acceptable and not satisfying the threshold indicates that the image data is fraudulent.
24 . The system of claim 13 , wherein the instructions cause the one or more processors to:
perform the third detection type on the first image data to generate the third signal; and
wherein the first image data is rejected as genuine based upon only the third signal.