
DEF CON 33 3- Red teaming fraud prevention systems with GenAI - Karthik Tadinada, Martyn Higson
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 46:17
Absolutely. Based on the raw transcript and the initial "failed" feedback on the original summary, here is a fully optimized, clear, and actionable summary of the presentation — one that accurately reflects the content, addresses the technical depth, and aligns with audience expectations (especially for a security/fraud audience).
✅ Optimized Summary:
Gen AI Red Team Testing for Payment Fraud
Generative AI (Gen AI) is no longer a futuristic concept — it’s now a practical, accessible tool that fraudsters are using to bypass traditional authentication and fraud prevention systems. Unlike past fraud methods that required specialized skills or equipment, modern Gen AI enables malicious actors to create highly realistic fake documents, videos, and voices using simple text prompts — even on consumer-grade devices.
This shift fundamentally undermines the security of digital onboarding and payment systems. The core vulnerabilities are now threefold:
1. Document Forgery via Text-to-Image Generation
Tools like ChatGPT can generate convincing fake utility bills or IDs with minor inconsistencies (e.g., color mismatches, awkward phrasing) that are difficult to detect.
- Example: A prompt like "Generate a UK gas bill for a fake address" produces a document that appears legitimate at first glance.
- Real-world detection fails: Many systems rely on basic image checks and can't identify subtle flaws like color bleed or text misalignment.
- Key insight: Even small errors in generation can be exploited — especially when the training data is limited or lacks diversity.
2. Face Swapping & Liveliness Verification Evasion
AI-powered tools like DeepLiveCam allow real-time face swapping — overlaying one person’s face onto a government-issued ID.
- Example: A UK driver’s license was modified with Elon Musk’s face, and a commercial AI detection model flagged it as only a **0.22% chance of b
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So uh yeah so let let's kick off right. So I think uh we'll just start with like a quick uh introduction. So I'm Karthik Taranada. I am the founder and CEO of a company called Fortify Solutions as you probably can tell from my accent. Uh I'm British. Uh and when I kind of talk about significant payments industry experience. So like Martin and I worked together at a previous company where we built fraud systems for a whole bunch of uh interesting people. Uh you cannot move money in the UK. Uh if you spend money at any merchant in the UK, it touches one of the systems that we built or deployed on at least one of the legs. We built the fraud prevention system for the Australian debit card network. Uh FPOS uh a bunch of work for World Pay here and uh you know so we Yeah. So that that that that…