IJIEEB Vol. 18, No. 4, 8 Aug. 2026
Cover page and Table of Contents: PDF (size: 1377KB)
PDF (1377KB), PP.50-71
Views: 0 Downloads: 0
Biometric Authentication, Mobile Banking, Presentation Attack Detection, Risk-Aware Fusion, Fairness-Aware Authentication, Financial Risk Optimization
This research examines RAFA-BioAuth, a risk-adaptive, fairness-aware framework for mobile banking in cases of presentations and facial occlusions. The proposed solution combines aspects of: Identity Similarity, Passive Presentation Attack Detection (PAD), Asymmetric Financial-Risk Estimation and Fairness Regularization at the Identity Level. For evaluation purposes, all benchmark datasets were split into subject disjoint training, validation, and testing sets. The threshold values from the validation set were used. Bootstrap resampling was employed to estimate the variance. Monte Carlo simulations were performed to estimate the risk. The results showed that identity verification (AUC = 0.548) and PAD (AUC ≈ 0.55) were poor. Comparing RAFA to the AND rule resulted in FAR = 0.20, FRR = 0.31, and expected risk = 340. On the other hand, the AND rule had lower FAR of 0.09, but increased FRR to 0.78. Finally, a conservative end-to-end approach produced an FRR of 0.686. Thus, our results indicate trade-offs rather than production-readiness as we did not perform deployment, cross-device, or cross-dataset validations on our solutions. We present the contributions of this research as being an interpretable integration and not a new algorithm.
Dendy K. Pramudito, Jufriadif Na'am, Ferda Ernawan, "RAFA-BioAuth: Risk-Adaptive and Fairness-Aware Biometric Authentication for Secure Mobile Banking", International Journal of Information Engineering and Electronic Business(IJIEEB), Vol.18, No.4, pp. 50-71, 2026. DOI:10.5815/ijieeb.2026.04.04
[1]E. Birgisdóttir, “Exploring the security of mobile face recognition: Attacks, defenses, and future directions,” Appl. Sci., vol. 15, no. 24, p. 13232, 2025, doi: 10.3390/app152413232.
[2]M. Taşkıran, N. Kahraman, and Ç. Erdem, “Face recognition: Past, present and future (a review),” Digit. Signal Process. 106, vol. 102809, 2020, doi: 10.1016/j.dsp.2020.102809.
[3]N. Waykole, “Secure facial recognition systems: A machine learning review of spoofing detection via parameter quality metrics,” J. Inf. Syst. Eng. Manag., vol. 10, no. 31s, pp. 493–501, 2025, doi: 10.52783/jisem.v10i31s.5103.
[4]A. Adedapo, Ọ Ọdẹ́jọbí, and T. Taiwo, “Countermeasures against bias and spoofing in modern facial recognition systems,” World J. Adv. Res. Rev., vol. 25, no. 1, pp. 1914–1930, 2025, doi: 10.30574/wjarr.2025.25.1.0011.
[5]A. Aziz, “Effects of visible and near infrared polarized lights on spoofing face detection,” J. Comput. Sci., vol. 15, no. 2, pp. 288–301, 2019, doi: 10.3844/jcssp.2019.288.301.
[6]B. Chettri, T. Kinnunen, and E. Benetos, “Deep generative variational autoencoding for replay spoof detection in automatic speaker verification,” Comput. Speech Lang. 63, vol. 101092, 2020, doi: 10.1016/j.csl.2020.101092.
[7]J. Solanki, “Robust framework for antispoofing face recognition mechanism for mitigating image attacks,” Int. J. Res. Appl. Sci. Eng. Technol., vol. 6, no. 3, pp. 1436–1439, 2018, doi: 10.22214/ijraset.2018.3222.
[8]Z. Wang, S. Wang, W. Yu, B. Gao, C. Li, and T. Wang, “Accurate real-time live face detection using snapshot spectral imaging method,” Sensors, vol. 25, no. 3, p. 952, 2025, doi: 10.3390/s25030952.
[9]A. Guleria, K. Krishan, V. Sharma, and T. Kanchan, “Impact of prolonged wearing of face masks—Medical and forensic implications,” J. Infect. Dev. Ctries., vol. 16, no. 10, pp. 1578–1587, 2022, doi: 10.3855/jidc.16618.
[10]M. Gündoğar and Ç. Erdem, “Presentation attack detection for face recognition using remote photoplethysmography and cascaded fusion,” Turkish J. Electr. Eng. Comput. Sci., vol. 29, no. 7, pp. 3240–3258, 2021, doi: 10.3906/elk-2010-93.
[11]N. Kumar, S. Sharma, P. Sharma, P. Mishra, B. Sharma, and A. Sharma, “Digital banking under siege: Trends and challenges in emerging security threats,” J. Inf. Syst. Eng. Manag., vol. 10, no. 3, 2025, doi: 10.52783/jisem.v10i3.4760.
[12]D. Muhtasim, M. Pavel, and S. Tan, “A patch-based CNN built on the VGG-16 architecture for real-time facial liveness detection,” Sustainability, vol. 14, no. 16, p. 10024, 2022, doi: 10.3390/su141610024.
[13]M. Parvadhi, S. Kishore, N. S, L. K, and P. S, “Enhanced face spoofing detection through geometric temporal dynamic analysis,” Int. J. Tech. Res. Sci., vol. 9, no. Spl, pp. 27–35, 2024, doi: 10.30780/specialissue-iset-2024/012.
[14]P. Prasad et al., “Robust facial biometric authentication system using pupillary light reflex for liveness detection of facial images,” Comput. Model. Eng. Sci., vol. 139, no. 1, pp. 725–739, 2024, doi: 10.32604/cmes.2023.030640.
[15]S. Santhoshini, “Deep Guard: Face spoofing detection using Swin transformer and rPPG signal,” Int. J. Res. Appl. Sci. Eng. Technol., vol. 13, no. 10, pp. 923–928, 2025, doi: 10.22214/ijraset.2025.74700.
[16]K. Jha, A. Jain, and S. Srivastava, “Feature-level fusion of face and speech based multimodal biometric attendance system with liveness detection,” AIP Adv., vol. 14, no. 11, 2024, doi: 10.1063/5.0234430.
[17]S. Kumar, Y. Asish, and S. Ganapathy, “A new hybrid CNN–LSTM model with non-softmax functions for face spoof detection,” Soft Comput., vol. 26, no. 19, pp. 10151–10162, 2022, doi: 10.1007/s00500-022-07418-9.
[18]M. Singh, R. Singh, and A. Ross, “A comprehensive overview of biometric fusion,” Inf. Fusion, vol. 52, pp. 187–205, 2019, doi: 10.1016/j.inffus.2018.12.003.
[19]R. Zhang and Z. Yan, “A survey on biometric authentication: Toward secure and privacy-preserving identification,” IEEE Access, vol. 7, pp. 5994–6009, 2019, doi: 10.1109/ACCESS.2018.2889996.
[20]A. K. Hanumanthaiah and M. B. Eraiah, “Challenge responsive multi modal biometric authentication resilient to presentation attacks,” Int. J. Intell. Eng. Syst., vol. 15, no. 2, pp. 494–507, 2022, doi: 10.22266/ijies2022.0430.44.
[21]K. Okereafor, O. Osuagwu, and C. Onime, “Biometric anti-spoofing technique using randomized 3D multi-modal traits,” Int. J. Simul. Syst. Sci. Technol., vol. 19, no. 5, pp. 5.1-5.8, 2018, doi: 10.5013/ijssst.a.19.05.05.
[22]H. Heidari and A. Chalechale, “A new biometric identity recognition system based on a combination of superior features in finger knuckle print images,” Turkish J. Electr. Eng. Comput. Sci., vol. 28, no. 1, pp. 238–252, 2020, doi: 10.3906/elk-1906-12.
[23]D. R. Kale and S. Kulkarni, “Integrating fusion levels for biometric authentication system,” IOSR J. Electron. Commun. Eng., vol. 12, no. 1, pp. 65–72, 2017, doi: 10.9790/2834-1201016572.
[24]J. Devi, S. Parveen, N. Naeem, and N. Abbas, “Facial verification along with spoof attacks,” Int. J. Adv. Res., vol. 5, no. 5, pp. 2264–2268, 2017, doi: 10.21474/IJAR01/5291.
[25]M. N. Favorskaya, “Face presentation attack detection: Research opportunities and perspectives,” Intell. Decis. Technol., vol. 17, no. 1, pp. 159–193, 2023, doi: 10.3233/IDT-220197.
[26]Z. Ming, M. Visani, M. Luqman, and J.-C. Burie, “A survey on anti-spoofing methods for facial recognition with RGB cameras of generic consumer devices,” J. Imaging, vol. 6, no. 12, p. 139, 2020, doi: 10.3390/jimaging6120139.
[27]J. Bok, K. Suh, and E. Lee, “Verifying the effectiveness of new face spoofing DB with capture angle and distance,” Electronics, vol. 9, no. 4, p. 661, 2020, doi: 10.3390/electronics9040661.
[28]A. Hassani, J. Diedrich, and H. Malik, “Improving monocular facial presentation-attack-detection robustness with synthetic noise augmentations,” Sensors, vol. 23, no. 21, p. 8914, 2023, doi: 10.3390/s23218914.
[29]D. Karmakar, P. Mukherjee, and M. Datta, “Spoofed facial presentation attack detection by multivariate gradient descriptor in micro-expression region,” Pattern Recognit. Image Anal., vol. 31, no. 2, pp. 285–294, 2021, doi: 10.1134/S1054661821020097.
[30]H. Vinutha and G. Thippeswamy, “Antispoofing in face biometrics: A comprehensive study on software-based techniques,” Comput. Sci. Inf. Technol., vol. 4, no. 1, pp. 1–13, 2023, doi: 10.11591/csit.v4i1.pp1-13.
[31]Y. Tian, Y. Huang, K. Zhang, Y. Liu, Z. Sun, and F. Chen, “Polarized image translation from nonpolarized cameras for multimodal face anti-spoofing,” IEEE Trans. Inf. Forensics Secur., vol. 18, pp. 5651–5664, 2023, doi: 10.1109/TIFS.2023.3310348.
[32]K. Kavita, G. Walia, and R. Rohilla, “A contemporary survey of multimodal presentation attack detection techniques: Challenges and opportunities,” SN Comput. Sci., vol. 2, no. 1, 2021, doi: 10.1007/s42979-020-00425-3.
[33]H. Mandalapu et al., “Audio-visual biometric recognition and presentation attack detection: A comprehensive survey,” IEEE Access, vol. 9, pp. 37431–37455, 2021, doi: 10.1109/ACCESS.2021.3063031.
[34]G. Ali, M. Dida, and A. Sam, “Two-factor authentication scheme for mobile money: A review of threat models and countermeasures,” Futur. Internet, vol. 12, no. 10, p. 160, 2020, doi: 10.3390/fi12100160.
[35]S. Tatineni, “Customer authentication in mobile banking-MLOps practices and AI-driven biometric authentication systems,” J. Econ. Manag. Res., pp. 1–5, 2022, doi: 10.47363/jesmr/2022(3)201.
[36]M. Waliullah, M. George, M. Hasan, M. Alam, M. Munira, and N. Siddiqui, “Assessing the influence of cybersecurity threats and risks on the adoption and growth of digital banking: A systematic literature review,” ajates, vol. 1, no. 01, pp. 226–257, 2025, doi: 10.63125/fh49gz18.
[37]S. Alotaibi, A. Alruban, M. Alotaibi, A. Alshumrani, and A. Altamimi, “Smartphone users transparent verification approach for mobile applications,” Int. J. Intell. Comput. Res., vol. 10, no. 2, pp. 977–987, 2019, doi: 10.20533/ijicr.2042.4655.2019.0119.
[38]N. Ammour, Y. Bazi, and N. Alajlan, “Multimodal approach for enhancing biometric authentication,” J. Imaging, vol. 9, no. 9, p. 168, 2023, doi: 10.3390/jimaging9090168.
[39]C. X. Tan et al., “A survey on presentation attack detection for automatic speaker verification systems: State-of-the-art, taxonomy, issues and future direction,” Multimed. Tools Appl., vol. 80, no. 21–23, pp. 32725–32762, 2021, doi: 10.1007/s11042-021-11235-x.
[40]A. Tharwat, “Classification assessment methods,” Appl. Comput. Informatics, vol. 17, no. 1, pp. 168–192, 2020, doi: 10.1016/j.aci.2018.08.003.
[41]D. Koutsoyiannis, “Trade-off between entropy and Gini index in income distribution,” Entropy, vol. 28, no. 1, p. 35, 2025, doi: 10.3390/e28010035.
[42]V. Conti, L. Rundo, C. Militello, V. Salerno, S. Vitabile, and S. M. Siniscalchi, “A multimodal retina-iris biometric system using the Levenshtein distance for spatial feature comparison,” IET Biometrics, vol. 10, no. 1, pp. 44–64, 2020, doi: 10.1049/bme2.12001.
[43]S. Ayeswarya and K. J. Singh, “Enhancing security and usability with context aware multi-biometric fusion for continuous user authentication,” Sci. Rep., vol. 15, no. 1, 2025, doi: 10.1038/s41598-025-14833-z.
[44]J. Chen, U. Hengartner, and H. Khan, “MRAAC: A multi-stage risk-aware adaptive authentication and access control framework for Android,” ACM Trans. Priv. Secur., vol. 27, no. 2, pp. 1–30, 2024, doi: 10.1145/3648372.
[45]D. Hintze et al., “CORMORANT: Ubiquitous risk-aware multi-modal biometric authentication across mobile devices,” Proc. ACM Interactive, Mobile, Wearable Ubiquitous Technol., vol. 3, no. 3, pp. 1–23, 2019, doi: 10.1145/3351243.
[46]A. Lonkar, S. Dharmadhikari, N. Dharurkar, K. Patil, and R. A. Phadke, “Tackling digital payment frauds: A study of consumer preparedness in India,” J. Financ. Crime, vol. 32, no. 2, pp. 257–278, 2024, doi: 10.1108/JFC-01-2024-0029.
[47]I. Riasat, M. Shah, and M. S. Gonul, “Strengthening cybersecurity resilience: An investigation of customers’ adoption of emerging security tools in mobile banking apps,” Computers, vol. 14, no. 4, p. 129, 2025, doi: 10.3390/computers14040129.