>Such manipulation of photos is typically invisible to the human eye, the researchers found.
I think its more like attacking a machine learning model - the difference in the photos may not be apparent at all, so a human reviewer might not catch something.
Face recognition gives the green light, since (part of) the picture is a perfect match.
A human may not be fooled, automated face recognition may.