Fraud & identity·Jun 11, 2026·7 min read

Liveness Checks Explained: How Machines Know You're You

How selfie-match, liveness checks and injection-attack defence work in identity verification, and what the published standards actually test.

Alfred BEditorial Reviews
Oil painting of an instrument-maker's bench where two workers inspect the same lens for two different faults

A selfie held next to a licence photo answers one question: do these two faces belong to the same person. It says nothing about whether the face in front of the camera was alive, present, or real at all. Three more questions, and the liveness checks that answer them are separate machinery tested against separate standards.

Liveness detection in identity verification is the set of techniques that decide whether a biometric sample came from a live person at the camera rather than from a photograph, a screen, a mask or a synthetic video. ISO/IEC 30107 calls this presentation attack detection. It sits above face matching and below injection-attack defence.

That last distinction is where most of the confusion lives, and it is the one worth understanding before anyone signs anything.

Where does liveness detection fit in the identity verification ladder?

The identity verification stack is a ladder of separate checks, each answering a narrower question than the one below it. Document authentication asks whether the ID is genuine. Face matching asks whether two images show the same person. Liveness asks whether the sample is from a live human. Injection detection asks whether the camera was ever involved.

These usually arrive bundled in one product. The standards treat them separately. ISO/IEC 30107-1:2023, the framework part published in August 2023, states plainly that attacks occurring outside the capture device during presentation fall outside its scope. It covers what happens in front of the lens, and stops there.

Each rung answers a different question, and passing one says nothing about the next.

RungThe question it answersWhat it does not cover
Document authenticationIs this identity document genuine and unaltered?Whether the person holding it is the person on it
Face comparison (1:1)Do the selfie and the document photo show the same person?Whether the selfie came from a living person
Passive livenessDoes this captured sample look like a live human, with no action requested?Attack types the algorithm was not trained on
Active livenessDid the person perform a requested action in real time?A synthetic face capable of responding in real time
Injection attack detectionDid this sample come from the real camera on the real device?Anything a genuine camera legitimately captured

Nothing on that ladder is redundant. Face matching with no liveness check is satisfied by a printed photo. Liveness with no injection defence looks very carefully at a stream no camera ever captured.

Active or passive liveness: what is the difference?

Passive liveness detection analyses a captured image or short video without asking the applicant to do anything. Active liveness asks for a deliberate action, such as turning the head or following a moving target, and checks that the response arrives correctly and in time. Passive is quieter. Active produces a stronger signal of real-time presence.

Worth knowing: the active and passive labels are industry vocabulary rather than terms defined in ISO/IEC 30107. NIST scoped its own evaluation to the passive case explicitly, publishing NIST IR 8491 in September 2023 on the performance of passive, software-based presentation attack detection algorithms.

The trade-off is not subtle once you have watched real applicants use these. An active check makes a borrower in a truck cab at dusk turn their head three times while the application sits open. A passive check asks nothing and the applicant often does not know it happened. Which fits depends on what the file is worth and how many attempts the applicant will tolerate.

What separates a presentation attack from an injection attack?

A presentation attack shows something fake to a real camera. An injection attack skips the camera and feeds a fake sample directly into the software. The European Union Agency for Cybersecurity drew exactly this line in its January 2022 report Remote Identity Proofing: Attacks and Countermeasures, noting that an injected video "is not a presentation attack instrument, as the video will be injected and not physically presented to the camera."

The same ENISA report called injection the most promising attack method according to market participants, and noted that passive liveness detection may be not as effective in deterring injected photo attacks, video reprojection attacks and deepfakes.

Standards work is catching up on the second category. CEN published CEN/TS 18099, Biometric data injection attack detection, in November 2024, defining the attack as replacing the sample provided at the capture device with another sample before feature extraction. Internationally, ISO/IEC 25456 on the same subject was still a working draft at stage 20.60 as of June 2025, so no published international standard for injection attack detection existed.

Certification programs have moved faster than the standards. The FIDO Alliance opened its Face Verification Certification in May 2024, testing five categories at once through accredited labs: deepfakes, facial liveness, bias, biometric matching and injection attacks.

This is the buyer's question, and it is a short one. Does the conformance evidence cover presentations to the sensor, injections into the pipeline, or both, and which lab issued it on what date.

How well do these systems actually perform?

Unevenly, and the unevenness is documented. NIST IR 8491 evaluated 82 passive face presentation attack detection algorithms from 45 developers across roughly 20,000 attack attempts and 21,000 genuine presentations. For photo print and replay attacks, protective face masks and flexible silicone masks, several algorithms reached error rates at or near zero. The same report found other attack types produced high error rates across every algorithm tested.

Deepfake detection generalises poorly, and the best public evidence for it is six years old and still unmatched in scale. Meta reported in June 2020 that the winning entry in its Deepfake Detection Challenge, from more than 35,000 models submitted by 2,114 participants, scored 82.56% accuracy on the public dataset and 65.18% against the black box dataset of unseen material. A detector tuned on known fakes is a different animal from one facing new ones.

Face matching carries its own documented variation. NIST IR 8280, published December 2019, found higher false positive rates for Asian and African American faces than for Caucasian faces in one-to-one matching, with differentials often ranging from a factor of 10 to 100 depending on the algorithm. A matching finding rather than a liveness one, but it lands on the same applicant.

For typologies rather than lab results, the US Financial Crimes Enforcement Network published alert FIN-2024-Alert004 on 13 November 2024, describing criminals using generative AI to alter or create identity document images and to respond to live verification prompts. Its red flags include repeated technical glitches during a live check followed by a request to switch communication method.

What does a liveness check cost the applicant?

More than most procurement conversations account for, and the standards say so themselves. iBeta, an NVLAP-accredited independent lab, tests products against ISO/IEC 30107-3 with a permitted bona fide presentation classification error rate of 15%. A product can pass Level 1 conformance while rejecting fifteen of every hundred genuine users under test conditions.

NIST's Digital Identity Guidelines, revision 4 of SP 800-63A published in July 2025, take the other side of the trade, specifying an impostor attack presentation accept rate below 0.07 for remote biometric collection. Two numbers, two directions, one dial.

The honest position is that the security setting and the completion rate are one setting, and it usually gets chosen by people who do not carry the conversion number. In private credit that conversation almost never happened. Risk picked the vendor, operations discovered the retry rate.

What we couldn't verify

No independent published data exists on how much applicant drop-off a liveness check causes. Every figure we found traced back to marketing or to case studies from the companies selling it, with no methodology attached. If a percentage is quoted at you, the useful question is who counted.

The circulating injection attack growth figures are vendor threat intelligence rather than independent research. The February 2025 threat intelligence report from the biometric vendor iProov reported face swap attacks up 300% against 2023 and native virtual camera attacks up 2,665%, drawn from that company's own detection network. Directionally useful, not independently replicable, and no regulator or academic body publishes comparable counts.

Canadian data is thin. The Canadian Anti-Fraud Centre reported in February 2026 that Canadians filed more than 112,000 fraud reports in 2025 with more than $704 million in reported losses, including 8,403 identity fraud reports and no dollar figure for that category. Nothing in those statistics separates biometric spoofing from other identity fraud. The Digital ID and Authentication Council of Canada publishes the Pan-Canadian Trust Framework and certifies against it, but no Canadian body publishes presentation attack detection results the way NIST does.

Common questions

What is liveness detection in identity verification?
Liveness detection is the set of techniques that determine whether a biometric sample came from a live person present at the camera rather than from a photo, screen, mask or synthetic video. ISO/IEC 30107 refers to this as presentation attack detection.

Is passive liveness less secure than active liveness?
Not inherently. Passive analyses the captured sample with no user action, active requires a real-time response. NIST IR 8491, published September 2023, evaluated 82 passive algorithms and found near-zero error rates against some attack types and high error rates across all algorithms against others.

Do liveness checks stop deepfakes?
Partially. Liveness detection under ISO/IEC 30107 covers attacks presented to a camera. A synthetic stream injected into the software never reaches a camera, which is why CEN published a separate injection attack detection specification, CEN/TS 18099, in November 2024.

What does iBeta Level 1 or Level 2 certification mean?
iBeta, an NVLAP-accredited lab, tests products for conformance with ISO/IEC 30107-3. Level 1 uses artefacts made from readily available materials, Level 2 uses costlier ones. iBeta states the result indicates conformance with testing and reporting requirements, not certification of the product.

Is there Canadian data on biometric spoofing?
Not in published form. The Canadian Anti-Fraud Centre recorded 8,403 identity fraud reports in 2025 without a dollar figure or a spoofing breakdown, and no Canadian body publishes presentation attack detection evaluations comparable to NIST's.


Carousel builds the intake layer that sits between an applicant and a decision, verification steps included. See how verification fits your flow

Fraud & identityidentity-verificationbiometricsliveness-detectiondeepfakesstandards