Biometric liveness detection

Biometric liveness detection confirms a face sample is from a living person, not a photo or spoof. Essential for remote identity verification.

Biometric liveness detection is a security measure that confirms a biometric sample (typically a face) comes from a living person in the moment, not a photograph, video, mask or other spoof. Also known as presentation attack detection (PAD), it is a critical step in identity verification workflows, especially when onboarding users remotely: the system detects signs of life (eye movement, micro-expressions, response to challenges) or uses passive analysis (texture, depth, blood flow) to rule out replay attacks.

Liveness detection sits between biometric capture and face matching in the verification pipeline. It addresses presentation attacks - a spoof artefact such as a photo, mask or screen replay held up to the camera - as distinct from injection attacks, where a manipulated or synthetic video (for example a deepfake) is fed directly into the data stream, bypassing the camera. ISO/IEC 30107-3 sets out testing methodologies and reporting for presentation attack detection, including error rates for classifying attack attempts. Without effective liveness checks, an attacker could substitute a high-quality photo or deepfake video for a live face, defeating the entire identity assurance level.

Frequently asked questions

Back to glossary