All neural nets are vulnerable to adversarial examples. It's a fundamental property they hold, because they're essentially stacked linear models. So (for example) they get more confident about their predictions when given a sufficiently out-of-domain input - adversarial training is essentially just finding paths that trigger an out-of-domain response.
I don't see how an additional transformation before input precludes that.
Or do you mean attacking the inner network somehow from inside the system?
You don't need to produce the correct 3d surface if the surface recogniser is neural - you just need to produce a 3d surface that's adversarial. The adversarial surface could be completely unrealistic, like these adversarial images. (Although the adversarial generator could also be trained with "realism" as a constraint.)
Are they able to detect depth independent of the surface of a presented image? That would make it harder, but the point of failure then is just figuring out a way to dynamically fool them. I wouldn't be confident saying that's impossible.
Don't you think you are too enthusiastic saying 3D facial authentication cannot be fooled?
It is basically an exercise in projecting right image, something that already a large number of people are working on.
That is not what was said. The commenter stated that THIS 2D GAN method has no chance against FaceID, and if you understand the way FaceID works you would understand they are absolutely correct.
FaceID shines dots on the user’s face and measures the distortion of those dots across the facial topology. Using this method on a 2D surface will result in no distortion, and therefore fail.