right, adversarial attacks are tricky, we wrote about it a while ago - https://blog.ycombinator.com/how-adversarial-attacks-work/
In reality, the production-grade security comes from a compound effect of three components: face-recognition, antispoofing for face recognition, and traditional controls of industry-standard protocols like SAML 2.0, OIDC, etc. Taking one of three out of the equation renders security nonexistent.