Real-Time Deepfakes: Live Face Swaps on Video Calls
A real-time deepfake is a face swap that runs live on camera, so the fraudster can blink, turn and answer questions as someone else. It defeats active liveness prompts and fools people on video calls. Stopping it takes two layers working together: liveness to confirm a live person, and deepfake detection to confirm that person’s face is real.
Real-Time Deepfakes vs Recorded Deepfakes: What Changed
Most early deepfakes were recorded clips. Someone trained a model, rendered a video, then played it back. That made them easy to beat with a simple request, such as “turn your head to the left”, because the clip could not respond.
A real-time deepfake removes that weakness. The fraudster faces a webcam while software replaces their face with the target’s face frame by frame, as they move. Because a real person drives the video, it responds naturally to any instruction. Some setups add a cloned voice, so the face and the voice both belong to someone else.
The tools are no secret. Open-source projects for live face swapping sit near the top of search results, often with install guides. Many need only one photo of the target and run on a consumer graphics card. That is the shift fraud teams need to plan for: a live, interactive impersonation that costs little to produce.
How a Live Face Swap Beats Active Liveness Prompts

Active liveness asks the user to do something: blink, smile, nod or turn. The logic is that a photo or a replayed video cannot follow a random instruction. That logic holds against recordings. Against a live swap, however, it breaks down, because the person behind the swap simply follows the prompt.
So the liveness model sees exactly what it expects. There is a real human, in real time, responding correctly. It is not wrong about that. The flaw is that liveness exists to prove presence, while a real-time deepfake keeps presence and fakes identity instead.
Two delivery routes matter here:
- Through a virtual camera. The swap output feeds the app or browser as if it were a webcam, which is an injection attack.
- Through a second screen. The swap plays on a monitor in front of a real phone camera, which is a presentation attack with live content.
Each route leaves different traces, so each needs a different check. That is why a single control, even a good one, leaves a gap. For the broader comparison of what each control does, see our guide to liveness vs deepfakes.
Real-Time Deepfake Risk in Video KYC and Agent-Assisted Onboarding
Video KYC adds a human agent to the selfie check. The customer joins a video call, shows an ID and answers questions while the agent watches. Many teams treat it as the safer option for high-risk accounts. Against a real-time swap, though, the agent is the weak point, because people are poor at spotting synthetic faces in live video.
Three patterns show up in practice:
- Stolen identity onboarding. The fraudster swaps in the face from a stolen ID and passes the agent’s visual comparison.
- Repeated attempts after rejection. A rejected applicant returns with a different swap and a different ID, since the cost per attempt is tiny.
- Convenient glitches. The video freezes or drops whenever the agent asks for an unusual movement, and the caller asks to switch channels.
The last pattern is worth training on. FinCEN’s November 2024 deepfake alert flags two of these behaviours: customers using webcam plugins in live checks, and excessive technical glitches. Agents should treat both as reasons to escalate, not to finish the call faster.
Executive Impersonation on Video Calls: One Documented Case
The best-known case did not involve onboarding at all. In January 2024, an employee in the Hong Kong office of engineering firm Arup joined a video conference with what looked like the company’s chief financial officer and several colleagues. All of them were deepfakes.
According to CNN, which reported Arup’s confirmation in May 2024, the employee made 15 transfers to five Hong Kong bank accounts. According to a June 2024 Legislative Council reply, the losses in that video-conference case came to about HK$200 million. The firm later said attackers had not breached its systems. Instead, the attack worked on people and process.
The case matters for identity teams for one reason. It showed that a live, multi-person deepfake call is practical today, not a lab demo. The same tooling that fooled a finance employee can sit behind a customer on a verification call. Similar attacks are spreading across Southeast Asia, as our look at deepfake risks in Asia shows.
Two-Layer Defence Against Real-Time Deepfakes: Liveness Plus Deepfake Detection

The defence follows from the attack. A real-time deepfake keeps a live person and fakes the face. So you need one check that proves presence and a second that judges whether the face itself is genuine.
| Layer | Question it answers | What it catches in a live swap |
|---|---|---|
| Liveness detection | Is a live person present right now? | Replays and still images used to steady the swap, plus screen artefacts on the second-screen route |
| Deepfake detection | Is this face real or generated? | Blending edges, lighting mismatches, texture and frame-to-frame flicker in the swapped face |
| Device and injection checks | Did a real camera capture this? | Virtual cameras, emulators and hooked apps on the injection route |
Both checks must analyse the same capture, in the same session. If they run separately, a fraudster can satisfy one with live video and the other with something else. The VeriSecure SDK works this way: it puts active liveness and deepfake detection in one flow, and it checks the device for emulators, root access and injection before the decision.
Process Controls That Still Help
Technology handles the face, but process handles the context. These controls cost little and catch what models miss:
- Out-of-band confirmation. For payments or account changes requested on a call, confirm through a number already on file.
- Occlusion and angle checks. Ask the caller to pass a hand across their face or show a full side profile. Older swap models still distort here, although newer ones handle it better.
- Escalation on glitches. Treat dropped video during unusual requests as a signal, not bad luck.
- Dual approval for large transfers. A single person on a single call should never be enough.
For more on why face models alone struggle, our guide to deepfake detection methods covers the artefacts these systems look for.
Frequently Asked Questions About Real-Time Deepfakes
What is a real-time deepfake?
A real-time deepfake is a face swap, sometimes with a cloned voice, that runs live during a video stream. The person behind it can move, speak and respond to questions while appearing to be someone else.
Can active liveness detection stop real-time deepfakes?
Not on its own. Active liveness asks for movements such as blinking or turning, and a live swap follows those prompts because a real person drives it. Pair it with deepfake detection, which checks whether the face itself is genuine.
How can you tell if someone is using a deepfake on a video call?
Look for edges flickering around the jaw or hairline, lighting that does not match the room, and distortion when a hand passes over the face. Repeated freezes during unusual requests are also a warning sign. Automated detection is more reliable than the eye.
Do fraudsters use real-time deepfakes in KYC fraud?
Yes. Fraudsters use live face swaps to pass selfie checks and video KYC calls with stolen IDs. Because the swap responds to prompts, it can beat checks that rely only on challenge-response liveness.
What happened in the Arup deepfake case?
In January 2024, an Arup employee in Hong Kong made transfers after a video call with deepfaked colleagues, including a fake chief financial officer. The Hong Kong government put the loss at about HK$200 million, according to a 2024 Legislative Council reply.
Real-Time Deepfakes Turn Liveness Into Half of the Answer
For years, liveness was the answer to “is this a real person?” Real-time deepfakes split that question in two. Yes, a real person is present. No, it is not the person on the ID. A check that only answers the first half will keep approving the second.
The practical fix is not exotic. Run liveness and deepfake detection together on one capture, check that a real camera produced it, and back the technology with simple process rules for high-value requests. Teams that do all three make live impersonation slow and expensive again, which is the most any defence can promise.
Running video KYC or face checks on high-value accounts? Talk to Verihubs about testing your flow against live face swaps.