Stocking masks making a criminal comeback
en-GBde-DEes-ESfr-FR

Stocking masks making a criminal comeback


You may have seen the scene in which Nicolas Cage pulls a pair of tights over his head before attempting, with limited success, to rob a convenience store of a pack of nappies in the comedy Raising Arizona?

Yet, despite the nylon mask achieving iconic status in popular culture in the 1980s and 1990s, there is little to suggest that it was actually used to any great extent by real criminals. Stocking masks were probably too revealing and impractical in reality.

Professor Raghavendra Ramachandra, cybersecurity expert at NTNU in Gjøvik, warns that this is about to change.

Nylon masks are not being used to conceal a criminal’s identity, but give them someone else’s.

Vulnerable to attacks

Ramachandra has been investigating how to secure digital systems designed to prevent unauthorised access to your mobile phone or online bank account. He has conducted this research together with colleagues from NTNU and several universities around the world.

“Many of these systems are now based on biometrics. This means that we no longer need to remember passwords or carry around as many keys and access tokens as we used to. Instead, these systems secure our devices using our own unique biological characteristics,” says Ramachandra.

These characteristics can include anything from your face and fingerprints to your eyes. Although such systems are in many ways reliable, convenient and user-friendly, they are also vulnerable to certain types of attack.

“There are good reasons why biometric security systems are used today by banks, at passport controls and in many other areas where security is paramount. At the same time, these systems have proved vulnerable to what we call presentation attacks,” says Ramachandra.

Presentation attacks

A presentation attack involves an attacker presenting a biometric system with a copy of the necessary biological characteristics.

“Many newer phones, for example, have built-in facial recognition,” explains Ramachandra. “Imagine that someone wants to gain access to my phone. They could go to my Facebook profile, download my profile picture and print it out on a sheet of paper. If they then present my phone with that piece of paper in an attempt to gain unauthorised access, they are carrying out a presentation attack.”

Whether the attack actually succeeds depends entirely on how sophisticated both the attack method and the recognition system are. Most modern facial-recognition systems would probably not be fooled by a paper printout.

“But let’s say that someone who follows me on social media gets hold of several selfies of me taken from different angles,” suggests Ramachandra.

“That could provide the basis for creating a 3D model of my face. And if you have a 3D model of my face, you can carry out sophisticated presentation attacks,” explains the NTNU researcher.

Very high attack potential

Ramachandra picks up a lifelike silicone mask. It not only gives the imitation face realistic depth and exactly the right proportions between the nose, eyes and mouth. Because it is made from silicone, even the texture of the skin can be reproduced with a high degree of realism.

“This means that we consider such masks to have very high attack potential. In other words, there is a strong chance that they will succeed in fooling a biometric system,” explains the researcher.

“Many recognition systems would struggle with this,” says Ramachandra.

The mask is so realistic that you might wonder how it is possible to secure a system against something like this at all.

“One way of solving the problem is to use two recognition systems in parallel. These masks may be able to fool a purely facial recognition system. But if the system also uses voice recognition, you won’t be granted access,” says the researcher.

The drawback is that this quickly makes things much more cumbersome for users: not only do they have to show their face, they also have to use their voice.

“Our goal is therefore to create one system capable of handling several different types of attack on its own, including new methods that have not previously been encountered,” says Ramachandra.

An old favourite in a new guise

Before taking a closer look at how such a system works in practice, it is time to say a little more about the notorious nylon mask. Where exactly does it fit into Ramachandra’s research?

As we have seen, silicone masks have high attack potential. However, there are certain factors that make them difficult to use. For example, they are expensive and complicated to produce.

“Because everyone has a different head shape, these masks have to be custom-made for the person who will wear them so that the proportions are not distorted when the mask is put on. That quickly makes the process expensive and cumbersome,” explains the cybersecurity expert.

That is not the case with nylon masks.

“The nylon masks we used in this research can easily be purchased online. A high-resolution image of the person being impersonated is printed directly onto the surface in a way that preserves even the smallest facial features when the material is stretched,” says Ramachandra.

Nylon masks may not be as realistic as silicone masks, but experiments carried out by Ramachandra and his colleagues nevertheless show that they have relatively high attack potential and can fool advanced biometric systems.

The fact that these masks can be ordered easily and cheaply online also demonstrates just how feasible such attacks have become in real-world situations, according to the researcher.

Skin, eyes and micro-movements

Nylon masks are just one of the latest tools in the ever-expanding toolbox used by cybercriminals to gain access to our digital devices.

“It is a constant game of cat and mouse to keep up. As soon as we find ways of detecting one attack method, another soon appears,” says Ramachandra.

As mentioned, the researchers’ goal is therefore to develop a system capable of detecting several attack methods at once – including new and previously unknown ones.

They have already come a long way towards achieving this.

“Using machine-learning algorithms trained on things such as skin texture, eye movements and so-called micro-movements, we have developed a tool that can detect these attack methods and also performs well against new ones,” explains Ramachandra.

Micro-movements are tiny movements that all humans make constantly without being aware of them. They occur, for example, when we breathe, swallow or unconsciously raise an eyebrow.

“This tool can be integrated into mobile phones, online banking services and other access-control systems. Our experiments show that the system can also detect types of attack it has not previously been trained on,” explains the researcher.

In other words, if the face presented to the system behaves in a way that differs from how a real face would be expected to behave, the system identifies it as an attempted attack.

Ramachandra and his colleagues are now also investigating whether it is possible to identify the person behind the mask. He reveals that preliminary experiments suggest this may be possible using a multispectral camera.
If this technology is realised, then Nicolas Cage’s character in Raising Arizona would have stood even less of chance!
Fichiers joints
  • Presentation attacks can be carried out using anything from paper printouts to hyper-realistic silicone masks. Photo: Mads Wang-Svendsen, NTNU
  • Minister of Digitalisation and Public Governance, Karianne Tung, testing the new security system developed by Ramachandra and his colleagues during the opening of the Norwegian University of Science and Technology (NTNU) Gjøvik’s new centre for combating digital fraud, 10 August 2026. Photo: Mads Wang-Svendsen, NTNU
  • Lifelike masks can fool biometric systems, posing a threat to the security of everything from mobile phones to access-control systems, warns Raghavendra Ramachandra, Professor at the Norwegian University of Science and Technology (NTNU) in Gjøvik. Photo: Mads Wang-Svendsen, NTNU
Regions: Europe, Norway
Keywords: Business, Telecommunications & the Internet, Applied science, Computing, Technology, Science, People in science

Disclaimer: AlphaGalileo is not responsible for the accuracy of content posted to AlphaGalileo by contributing institutions or for the use of any information through the AlphaGalileo system.

Témoignages

We have used AlphaGalileo since its foundation but frankly we need it more than ever now to ensure our research news is heard across Europe, Asia and North America. As one of the UK’s leading research universities we want to continue to work with other outstanding researchers in Europe. AlphaGalileo helps us to continue to bring our research story to them and the rest of the world.
Peter Dunn, Director of Press and Media Relations at the University of Warwick
AlphaGalileo has helped us more than double our reach at SciDev.Net. The service has enabled our journalists around the world to reach the mainstream media with articles about the impact of science on people in low- and middle-income countries, leading to big increases in the number of SciDev.Net articles that have been republished.
Ben Deighton, SciDevNet
AlphaGalileo is a great source of global research news. I use it regularly.
Robert Lee Hotz, LA Times

Nous travaillons en étroite collaboration avec...


  • The Research Council of Norway
  • SciDevNet
  • Swiss National Science Foundation
  • iesResearch
Copyright 2026 by DNN Corp Terms Of Use Privacy Statement