Blog 23 May 2024 | Last Updated: 7 July 2026

Try Now

Get 10 FREE credits by signing up on our portal today.

Sign Up
Liveness detection: a complete guide to biometric anti-spoofing.

What Is Liveness Detection? The Complete Guide to Biometric Anti-Spoofing

Author: admin | 23 May 2024 | Last Updated: 7 July 2026

Deepfakes, synthetic identities, and biometric spoofing are making remote identity verification harder to trust. As AI-generated media becomes more realistic, businesses need more than a face match. They need confidence that the person being verified is genuinely present.

Facia’s internal deployment data indicates that its data science team recorded more biometric spoof attempts in Q1 2026 than in all of 2025.

This guide explains how liveness detection works, the attacks it helps detect, active vs. passive methods, key PAD standards and metrics, and what organisations should evaluate when choosing a solution.

Core Definition and Context

Liveness detection is a biometric security technology that checks whether a biometric sample comes from a real, physically present person. It helps detect spoofing attempts such as printed photos, video replays, silicone masks, and AI-generated deepfakes.

It is closely related to Presentation Attack Detection (PAD). NIST defines PAD as the automated determination of a presentation attack and describes liveness methods as techniques that help determine whether a biometric sample comes from a living subject present at capture.

Face matching asks whether a face matches the expected identity. Liveness detection asks whether the sample comes from a genuine live subject. Injection and deepfake defences examine whether the capture or media pipeline itself has been manipulated.

Why Is Liveness Detection Necessary?

In the case of remote verification, attackers can provide false biometric data without being physically checked.

Print and Replay Attacks

A print attack is when someone uses another person’s photograph; a replay attack is when they play back a prerecorded video on a screen. PAD systems can analyse texture, reflectance, temporal behaviour, image artefacts, and depth cues to detect the presence of a spoof.

3D Mask Attacks

A flat facial image is not as much of a close an approximation to facial shape as can be made by silicone, resin, latex or 3D-printed masks. Depth is more significant than surface properties and texture in these attacks, as are facial structure and reflectance.

See 3D Facial Liveness Detection for deeper coverage.

Deepfake and Injection Attacks

Generative AI can produce lifelike facial images and natural facial expressions and movements.

A deepfake on a physical screen may simulate a presentation attack. If a synthetic feed is injected via a virtual camera, modified application, emulator or other digital channel, it is an injection attack.

The video below demonstrates how liveness detection defends against real-world spoofing attempts in real time.

The difference matters because ISO/IEC 30107-3:2023 assesses vulnerability to presentation attacks at the biometric capture device, but it does not cover system-level vulnerability assessment.

Organisations should therefore not rely on PAD testing to guarantee protection against all deepfakes or injections.

How Does Liveness Detection Work?

There is no universal liveness algorithm. Modern systems can integrate computer vision, machine learning, image quality, motion analysis, texture analysis, depth analysis, and challenge response.

1. Image and Capture Quality

The system first checks whether a sample is suitable for analysis. Lighting, blur, resolution, occlusion, glare, and facial positioning can affect performance.

2. Motion, Texture and Life-Sign Analysis

Motion analysis evaluates how facial features change over time. Texture analysis looks for differences between genuine skin and presentation artefacts such as paper, screens, or masks.

Some systems also analyse micro-movements, natural facial behaviour, reflectance patterns, or other physiological signals. These signals are usually most effective when combined rather than treated as standalone proof.

3. Depth and Spatial Analysis

Depth analysis evaluates whether or not facial geometry is consistent with a true 3D face.

A real face has varying levels of depth around the eyes, nose, cheeks, forehead, lips and jaw. Those physical relationships can’t be reproduced in the same way in a flat photograph or even on an ordinary screen.

4. Decision and Risk Thresholding

The overall system eventually generates a liveness score, classification or risk signal.

A higher threshold can prevent more attacks, but can also prevent more valid users. It is a balance that will vary depending on factors related to the risk of fraud, mobile devices, user population, and business needs.

Active vs. Passive Liveness Detection

Active liveness and passive liveness are the two primary types of liveness detection. Both serve the same security goal, but they differ in mechanism, user experience, and resilience against different spoofing methods.

Types of liveness detection: active, passive and hybrid

Active Liveness

Active liveness requires an action from the user, such as turning the head, blinking, smiling or following an on-screen prompt.

It can provide real-time evidence but adds friction and may lead to more retries or accessibility issues.

Passive Liveness

Passive liveness analyses the biometric capture without a clear challenge.

The primary benefit is a smoother experience, but performance also depends on model quality, capture security, the attacks tested, and decision thresholds.

Hybrid Liveness

Hybrid systems mix both. You can use passive verification for an initial trip and an active challenge only when confidence is low, or risk is high.

Read Active Liveness vs. Passive Liveness for a thorough comparison.

Liveness Detection Standards and Performance Metrics

Claims such as “99.9% accurate” mean little without knowing what was tested and which metric was measured.

ISO/IEC 30107-3

ISO/IEC 30107-3:2023 is part of the ISO/IEC 30107 series of standards that address how to assess and report PAD performance and classify the types of presentation attacks. It does not indicate resistance to all attacks on a biometric system.

NIST Digital Identity Guidance

NIST SP 800-63A-4 requires PAD when biometrics are collected and compared remotely for identity proofing and specifies an IAPAR below 0.07.

In the scenarios NIST SP 800-63B-4 addresses, PAD is required for face recognition authentication as well.

APCER, BPCER and IAPAR

APCER measures how often a Presentation Attack Detection (PAD) system incorrectly accepts a spoofing attempt as genuine. These attacks can include printed photos, replayed videos, or masks.

BPCER (Bona Fide Presentation Classification Error Rate) measures how often a PAD system incorrectly classifies genuine biometric presentations as spoofing attacks. In simple terms, it shows how frequently real users are wrongly rejected by the PAD system.

IAPAR (Impostor Attack Presentation Accept Rate) measures the proportion of impostor attack presentations that are incorrectly accepted as genuine. It indicates how often an attack succeeds under the specific testing methodology.

These are different from biometric matching metrics such as FMR and FNMR, which evaluate identity comparison rather than anti-spoofing performance.

8 Evaluation Points for Choosing a Liveness Solution

1. Independent PAD Testing

Ask which ISO version, attack species, devices, and configurations were tested.

Facia’s passive liveness solution underwent iBeta Level 2 PAD testing in 2024. The letter reports 1,500 presentation attacks and an APCER of 0% for those tested attacks.

2. Deepfake and Injection Protection

Ask how the solution handles virtual cameras, synthetic video, manipulated applications, emulators, and compromised capture paths.

3. Active, Passive or Hybrid Architecture

Evaluate how much user interaction is required and whether risk-based step-up verification is available.

4. Correct Performance Metrics

Request APCER, BPCER, and IAPAR for PAD, and suitable FMR/FNMR metrics for face matching. Ask which thresholds produced the results.

5. Capture and Device Security

Review SDK integrity, camera control, tamper detection, emulator detection, secure transmission, and other capture protections.

6. Real-World Performance

Test the devices, lighting conditions, networks, and markets your customers actually use.

7. Demographic Performance

Review evidence across representative demographic groups. ISO/IEC 19795-10:2024 addresses reporting of biometric performance variation across demographic groups.

8. Compliance and Deployment Documentation

Evaluate biometric-data handling, encryption, retention, hosting, access controls, privacy requirements, auditability, and integration documentation.

Also check whether vendors use current NIST terminology. The former FRVT program has been split into FRTE and FATE.

Building a Layered Anti-Spoofing Strategy

A stronger identity architecture can combine secure capture, PAD, face matching, deepfake detection, injection defences, device intelligence, document verification, and risk-based escalation.

The better question is not simply:

“Does this solution have liveness detection?”

It is:

“Which attacks has it been tested against, where can those attacks occur, and what evidence shows the complete system can detect them?”

How Facia Supports Liveness Detection

Facia provides facial liveness and biometric anti-spoofing capabilities for remote identity-verification workflows.

Its passive liveness solution underwent independent iBeta Level 2 PAD testing against ISO/IEC 30107-3 in 2024. Organisations should consider that testing alongside their own threat model, device requirements, user-experience goals, and exposure to synthetic-media or injection attacks.

Talk to a Facia liveness detection specialist today to evaluate your anti-spoofing strategy and find the right solution for your identity verification workflow. Book a Demo Today.

Frequently Asked Questions

What Is Liveness Detection in KYC?

Liveness detection in KYC helps verify that the biometric sample submitted during onboarding comes from a genuine person who is present during verification.

Is Liveness Detection the Same as Facial Recognition?

No. Facial recognition checks identity similarity; liveness detection checks whether the biometric sample appears to come from a genuine live subject.

What Is ISO/IEC 30107-3?

It is an international standard covering testing and reporting for biometric Presentation Attack Detection mechanisms.

Which Metrics Matter for Liveness Detection?

Important PAD metrics include APCER, BPCER, and IAPAR. These are different from matching metrics such as FMR and FNMR.

```