Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems

Bowen Hu

34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Authentication

Overview

In an era where facial recognition has become ubiquitous, securing these systems against sophisticated impersonation attempts is paramount. This talk, "Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems," presented by Bowen Hu from Nanyang Technological University, unveils a critical vulnerability in facial recognition systems that rely on near-infrared (NIR) imaging for anti-spoofing. The research, conducted in collaboration with Dr. Kolong and Professor Chip Hong Chong, demonstrates a novel and practical method to bypass these systems by crafting a digital display capable of projecting realistic NIR facial images.

Watch on YouTube · Slides

Visual summary for Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems by Bowen Hu
Visual summary for Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems by Bowen Hu

Key moments

  1. 0:00 Introduction to facial recognition and presentation attacks
  2. 3:00 NIR imaging as anti-spoofing, challenge to its robustness
  3. 4:20 The 'Red Bleed' concept and LCD limitations
  4. 6:00 Wire-grid polarizers enable clear NIR image projection
  5. 7:00 Pragmatic attack device successfully fools Windows Hello
  6. 8:10 Synthesizing realistic NIR faces from visible light video

Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems

Speakers: Bowen Hu

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=DkzXowYO52g

Overview

In an era where facial recognition has become ubiquitous, securing these systems against sophisticated impersonation attempts is paramount. This talk, "Red Bleed: A Pragmatic Near-Infrared Presentation Attack on Facial Biometric Authentication Systems," presented by Bowen Hu from Nanyang Technological University, unveils a critical vulnerability in facial recognition systems that rely on near-infrared (NIR) imaging for anti-spoofing. The research, conducted in collaboration with Dr. Kolong and Professor Chip Hong Chong, demonstrates a novel and practical method to bypass these systems by crafting a digital display capable of projecting realistic NIR facial images.

The core of the "Red Bleed" attack lies in challenging the long-held assumption that NIR cameras are inherently robust against digital display-based presentation attacks. By meticulously dissecting the optical components of standard LCD screens and identifying their limitations in the NIR spectrum, the researchers engineered a custom display that effectively spoofs NIR sensors. The work not only exposes a significant weakness in widely adopted biometric solutions like Windows Hello but also provides a pragmatic attack methodology, including the ability to synthesize realistic NIR facial videos from commonly available visible light footage using machine learning. The findings have led to a responsible disclosure process, culminating in a patch from Microsoft under CVE-2025-26644.

Background

▶ Watch: Introduction to facial recognition and presentation attacks (0:00)

Facial recognition technology has permeated nearly every aspect of modern life, offering convenient, contactless, and rapid authentication for devices, payments, border control, and banking. Its widespread adoption is largely attributed to advancements in sensor technology and artificial intelligence. However, this convenience introduces significant security concerns. Unlike passwords, an individual's face is public, easily captured from photos or social media, and once compromised, cannot be simply changed. This inherent public nature makes facial recognition systems particularly susceptible to presentation attacks (PAs), where an attacker presents a fake artifact—such as a photo, video, or mask—to the camera. Statistics show that over half of recent attacks on facial recognition systems fall into this category, as they do not require deep knowledge of system internals, but instead target the sensor directly.

To counteract these pervasive presentation attacks, many modern facial recognition systems have evolved beyond standard visible light cameras. One of the most effective countermeasures adopted is the use of near-infrared (NIR) imaging. Unlike conventional color cameras, which are heavily influenced by ambient light conditions, NIR cameras provide consistent and stable images regardless of the lighting environment, enhancing recognition reliability. Crucially, NIR imaging has been considered a powerful anti-spoofing tool. This is because artifacts designed for visible light, such as printed photos or digital screens, appear as blank or dark surfaces when viewed under an NIR camera. This distinct behavior allows the system to easily differentiate between a live person and a fake artifact, a defense mechanism previously believed to be highly robust. The central question driving this research was: Is it truly impossible for a digital display to fool an NIR sensor? This query formed the foundation of the "Red Bleed" investigation, challenging a fundamental assumption underpinning modern biometric security.

Key Findings

▶ Watch: The 'Red Bleed' concept and LCD limitations (4:20)

The "Red Bleed" research culminated in several critical findings that fundamentally challenge the efficacy of NIR imaging as a standalone anti-spoofing mechanism for facial biometric systems. The primary discovery was that standard LCD components, particularly their polarizers, are inherently unsuitable for effective operation in the near-infrared spectrum. While designed to control visible light, these polarizers leak NIR light in an uncontrolled manner, making them the Achilles' heel of an otherwise robust defense strategy.

To overcome this limitation, the researchers successfully engineered a custom digital display by replacing the standard polarizers with specialized wire-grid polarizers and pairing them with a custom 850 nanometer NIR backlight. This modification enabled the creation of a display capable of projecting sharp, high-contrast images visible only in the NIR spectrum. This custom device, dubbed the "Red Bleed" attack module, demonstrated the practical feasibility of such an attack, with component costs amounting to approximately $350 for a high-resolution LCD panel and the specialized polarizers.

The efficacy of this pragmatic attack was rigorously tested against commercial facial recognition systems. Using pre-recorded NIR videos of 22 different subjects, the "Red Bleed" device achieved a 100% success rate in unlocking Windows Hello modules on HP, Dell, and Lenovo PCs. This demonstrated that to the targeted facial recognition systems, the displayed NIR frames were virtually indistinguishable from a live person's face.

Furthermore, recognizing the practical limitation of requiring pre-recorded NIR footage, the team developed an advanced Variational Autoencoder (VAE)-based machine learning model. This model was trained on the Cassia Nirv 2.0 dataset to synthesize realistic NIR face videos from easily obtainable visible light videos. While the model still required a minimal number of "ground truth" NIR photos for optimal performance, it achieved a remarkable 97% success rate against Windows Hello with just nine ground truth NIR samples, and an impressive 61% success rate with only a single ground truth sample. This significantly enhances the practicality and stealth of the "Red Bleed" attack.

Finally, the research exemplified responsible disclosure. Upon confirming the vulnerability, the team immediately notified Microsoft, HP, Dell, and Lenovo, collaborating with them for over six months before public disclosure. This led to Microsoft assigning the vulnerability CVE-2025-26644 and issuing a security update to enhance face anti-spoofing features within Windows.

Technical Deep Dive

▶ Watch: Wire-grid polarizers enable clear NIR image projection (6:00)

The technical ingenuity behind the "Red Bleed" attack lies in a deep understanding and manipulation of the optical properties of Liquid Crystal Displays (LCDs) and their interaction with near-infrared light. A standard LCD panel operates by using a backlight to produce white light, which then passes through a series of filters and layers. Crucially, a rear polarizer, a liquid crystal layer, and a front polarizer work in concert to control the amount of light passing through each pixel, ultimately forming the visible image.

The initial conceptual breakthrough for the researchers was to hypothesize what would happen if the standard visible backlight of an LCD panel were replaced with a custom NIR backlight. Early experiments, however, yielded only a very faint, ghostly pattern visible under an NIR camera, largely unusable for a sophisticated attack. This phenomenon was aptly named "Red Bleed" by the researchers, drawing a parallel to the common "backlight bleed" issue in normal LCDs, but specifically occurring in the NIR spectrum due to the replacement of the white backlight with an NIR one.

Through meticulous investigation, the team pinpointed the root cause of this inefficiency: the polarizers. Standard LCD polarizers are meticulously designed and optimized to function exclusively within the visible light range. Their performance, particularly their ability to block polarized light, drops off dramatically in the NIR range. Essentially, these off-the-shelf polarizers simply cannot effectively block polarized NIR light, leading to uncontrolled light leakage and the "ghostly pattern" observed.

The elegant solution involved replacing these inadequate standard polarizers with specialized wire-grid polarizers. Wire-grid polarizers are a distinct class of optical components designed to operate effectively across a much wider electromagnetic spectrum, including the NIR range, by utilizing subwavelength metallic gratings. The researchers meticulously sandwiched the original liquid crystal cell from a commercial LCD panel between two of these wire-grid polarizers. This modified assembly was then paired with a custom 850 nanometer NIR backlight. The results were transformative: the modified display could now project a sharp, high-contrast, and clear image that was exclusively visible in the NIR spectrum, effectively becoming an "NIR-only" display. This custom display formed the core of the "Red Bleed" attack device, which was deemed a "pragmatic attack" due to its feasible construction, with total component costs for a high-resolution panel and specialized polarizers estimated at around $350.

To overcome the significant practical limitation of requiring existing NIR video of a target, the research took a crucial step further by incorporating advanced machine learning. The goal was to synthesize realistic NIR face videos from readily available visible light videos, which can often be found on social media platforms. For this, the team leveraged a Variational Autoencoder (VAE)-based model. VAEs are a type of generative model capable of learning complex data distributions and generating new, similar data samples.

The model was trained on the Cassia Nirv 2.0 data set, a public dataset containing both visible and NIR images, crucial for learning the mapping between the two modalities. The core design principle of their VAE model was to disentangle a person's identity from the image modality. This meant the model learned the essential, identity-defining facial features from both visible light photos and NIR face photos independently. Subsequently, it could then "re-render" those learned visible light identities into new, synthetic, but photorealistically looking NIR faces. The internal architecture of the encoder and decoder components of the VAE was built using ResNet and Attention blocks, which are common and powerful building blocks in deep learning for image processing tasks, known for their ability to capture fine-grained details and contextual information. While a larger, more comprehensive dataset would further enhance performance, the model demonstrated remarkable capability even with limited "ground truth" NIR samples, showcasing the power of generative AI in bypassing biometric defenses.

Demo / Proof of Concept

▶ Watch: Pragmatic attack device successfully fools Windows Hello (7:00)

The practical demonstration of the "Red Bleed" attack involved two primary phases: first, using directly recorded NIR videos, and second, employing machine learning-synthesized NIR videos.

For the initial proof of concept, the researchers constructed their assembled attack device, which comprised the modified LCD panel with its custom wire-grid polarizers and 850nm NIR backlight. To execute the attack, a pre-recorded NIR video of the victim was simply played on this custom display. The device was then pointed directly at the target computer's facial recognition module. The primary target for this demonstration was Windows Hello, Microsoft's facial recognition solution for Windows PCs, serving as an alternative to password-based login.

The attack was tested against three distinct Windows Hello modules integrated into laptops from prominent manufacturers: HP, Dell, and Lenovo. The team recorded short NIR videos of 22 different subjects. The results were unequivocal: the "Red Bleed" device achieved a 100% success rate, successfully unlocking every machine for every subject. Visual evidence presented during the talk vividly illustrated this efficacy. A frame captured from a live person and a corresponding frame from the "Red Bleed" NIR display in action were shown side-by-side. To the facial recognition systems, these two inputs were almost indistinguishable, highlighting the deceptive power of the custom display.

Recognizing the practical limitation of needing to capture actual NIR videos of targets, the research extended its demonstration to include the synthesized NIR videos generated by their VAE-based machine learning model. For this phase, 5-second synthetic NIR videos were used to attack the same Windows Hello systems. The results, though slightly lower than with direct recordings, remained highly effective. With nine ground truth NIR photos of the target used to train the generative model, a success rate of over 97% was achieved. Even more impressively, with just a single ground truth NIR photo, the system could still be bypassed over 61% of the time.

A compelling scenario was demonstrated: a normal user, who had registered their face with Windows Hello months prior, successfully logged into their system. After locking the screen and leaving, an attacker approached the device. Using the "Red Bleed" attack module with either recorded or synthesized NIR footage, the attacker successfully unlocked the laptop. The system, as shown by the captured frames from the NIR camera, could not differentiate between the real face and the replayed video, confirming the attack's effectiveness in a real-world context against the tested modules. The talk explicitly stated a 100% success rate for this specific HP module test using the Red Bleed module, further emphasizing the severity of the vulnerability.

Defensive Implications

▶ Watch: Synthesizing realistic NIR faces from visible light video (8:10)

The "Red Bleed" attack presents significant defensive implications for the design and deployment of facial biometric authentication systems, particularly those relying on NIR imaging for anti-spoofing. The primary takeaway for defenders is that simple 2D NIR imaging, while superior to visible light for consistency, is no longer a sufficient standalone defense against sophisticated presentation attacks.

The most robust defense against this specific type of attack lies in migrating to 3D facial recognition systems. Technologies like Apple's Face ID, which incorporate depth information alongside 2D imaging, are inherently more resilient. The "Red Bleed" attack, by its nature, creates a 2D projection of a face in the NIR spectrum but cannot replicate the genuine depth map of a human face. Therefore, systems that utilize structured light, time-of-flight sensors, or other depth-sensing technologies to build a 3D model of the face will not be fooled by a flat 2D NIR display.

Crucially, the responsible disclosure process initiated by the researchers led to a direct mitigation. Microsoft has since patched this vulnerability, assigning it CVE-2025-26644, and has issued a security update that includes an enhanced face anti-spoofing feature within Windows Hello. This means that users and organizations should prioritize keeping their Windows operating systems fully updated to benefit from these patches. Defenders should verify that their systems are running the latest security updates to protect against this specific "Red Bleed" attack variant.

Beyond software patches, future hardware enhancements for NIR sensors could also play a role. Rather than merely capturing 2D NIR patterns, sensors might need to incorporate capabilities to detect specific spectral characteristics, material properties, or subtle liveness cues that a modified LCD cannot replicate. This could involve multi-spectral NIR analysis or active illumination techniques that look for specific responses from living tissue.

Furthermore, the adoption of multi-modal biometrics offers a broader defensive strategy. Combining NIR imaging with other authentication factors or liveness detection techniques, such as active illumination for specular reflection analysis, thermal imaging, or even behavioral biometrics, could significantly increase the overall robustness of facial recognition systems. The principle here is to create a more complex challenge for attackers, requiring them to spoof multiple distinct biometric modalities simultaneously.

Finally, while the generative model for synthesizing NIR videos enhances the attack, advancements in machine learning can also contribute to defense. Developing more sophisticated anti-spoofing models trained on larger, more diverse datasets (including synthetic attack data) could help systems better detect the subtle artifacts or inconsistencies present in generated or displayed spoofing attempts.

Key Takeaways

  • NIR Imaging is Not Foolproof: Near-infrared (NIR) imaging, previously considered a robust anti-spoofing measure, is vulnerable to sophisticated digital display-based presentation attacks.
  • Polarizers are the Weak Link: Standard LCD polarizers, designed for visible light, are the critical vulnerability, allowing uncontrolled NIR light leakage and enabling spoofing.
  • "Red Bleed" is a Pragmatic Attack: The research demonstrates a practical and affordable method (approx. $350) to build a custom NIR-only display capable of bypassing facial recognition systems.
  • AI Enhances Attack Practicality: A Variational Autoencoder (VAE) based machine learning model can synthesize realistic NIR face videos from visible light footage, significantly reducing the attacker's requirements.
  • Windows Hello Was Vulnerable: The attack achieved a 100% success rate against Windows Hello modules on HP, Dell, and Lenovo PCs, highlighting a significant security flaw.
  • Patch Issued (CVE-2025-26644): Microsoft has patched this vulnerability, and users should update their systems. 3D facial recognition systems (e.g., Apple Face ID) remain immune to this specific 2D display attack.

About the Speaker(s)

Bowen Hu is a researcher from Nanyang Technological University, Singapore. He presented the "Red Bleed" research, which was a joint effort with his colleagues Dr. Kolong and Professor Chip Hong Chong. Their work focuses on discovering novel vulnerabilities in facial recognition systems, particularly those employing near-infrared imaging. The team's commitment to responsible research and the reproducibility of their findings was acknowledged by USENIX Security, where they received badges for making their artifacts available, functional, and reproducible.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, original hardware-meets-ML attack research that cracks a widely held assumption — that NIR imaging is inherently spoof-resistant — with a reproducible, low-cost ($350) physical build and a generative model that removes the hardest practical prerequisite. 100% success rate against Windows Hello across three major OEMs and a resulting CVE make this more than an academic exercise.

Heather Calloway (CISO) — SOLID

Technically rigorous research that breaks a real assumption and produced a real patch. But the institutional and governance dimensions — who deploys these systems at scale, who bears liability when they fail, and what procurement or policy decisions should change — are left entirely to the audience to infer.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)