All posts
4 August 2026· 3 min read

Can Your Robot Tell a Human From a Projection?

Security researchers scored real commercial robots as low as 39.9% on face-recognition and liveness maturity. As humanoid systems move among people, that's the gap that decides who they trust.

Security researchers ran the same spoofing tests used against banking apps and border kiosks against three commercial robots on the market today, Pepper, G1 EDU, and Digit. The security maturity scores ranged from 39.9 to 79.5 percent across the three platforms. Printed photos, replayed video, and 3D-printed masks all had a real chance of passing as a live human, depending on which robot was doing the checking.

That gap matters more for a robot than it does for a phone. A phone that's fooled by a spoofed face unlocks a screen. A humanoid or autonomous system that's fooled by a spoofed human presence can misjudge who to follow, who to hand something to, or who to treat as a person in its environment at all. As these systems move out of controlled labs and into homes, hospitals, warehouses, and public spaces, the question stops being abstract: can the system in front of you actually tell a human being from something built to look like one, on-device, in real time, without a person reviewing the footage afterward.

Presentation attacks against face recognition split roughly into two kinds. 2D attacks use a printed photo, a screen replay, or pre-recorded video held up to a camera. 3D attacks use a mask or a printed head shaped to fool a depth sensor as well as a flat image. Robots built with off-the-shelf face recognition inherit whatever weaknesses that recognition already had, and the research above suggests those weaknesses are still wide open on hardware shipping today.

The humanoid robotics market is projected to reach $8 to 15 billion by 2030 and $38 billion or more by 2035. Every one of those systems will need the same underlying capability: recognition that's fair and accurate across demographics, paired with anti-spoofing that catches a synthetic projection of a human presence before the system acts on it. This isn't a feature that gets added once a robot ships. It's a safety component that has to be trained in alongside recognition itself, because the two are inseparable in practice, a system that recognizes faces well but can't tell a real one from a fake one hasn't solved the problem, it's just gotten better at the wrong task.

Training that kind of on-device recognition and anti-spoofing requires the same thing every detection problem in this space requires: a wide, demographically calibrated set of real and synthetic examples to test against, reproducible on demand rather than harvested one incident at a time.

TessLabs' foundry produces exactly that, mathematically locked synthetic identities with controlled attribute sweeps, built to train recognition systems on the edge cases they currently fail.

See the Studio to explore sample identities and attribute controls.

FAQ

Can a robot's face-recognition system be fooled with a photo or mask?
Yes. Security researchers testing commercial robots, including Pepper, G1 EDU, and Digit, found face-recognition and liveness maturity scores as low as 39.9 percent. Both 2D attacks (printed photos, screen replays) and 3D attacks (masks, printed heads) had a real chance of passing as a live human.

Why does spoofing matter more for a robot than for a phone?
A spoofed phone unlocks a screen. A spoofed humanoid or autonomous system can misjudge who to follow, who to hand an object to, or who to treat as a person at all, which is a physical safety failure, not just an access-control one.

Is anti-spoofing part of standard robot safety certification today?
Not consistently. Most humanoid safety standards emerging in 2026 focus on physical safety, collision avoidance, and fallback logic. Anti-spoofing and human-presence verification are still treated as a feature to add later rather than a core safety requirement trained in alongside recognition.

Case study: robot face-recognition security testing, via Optica/OPN.

Measuring this on your own model

The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.