
Liveness detection technology is the layer of a biometric identity verification system that confirms a real, live person is present at the moment of capture, not a photo, a video replay, a 3D mask, or a synthetic deepfake. Without it, even a highly accurate face-matching engine can be bypassed with a printed image or a generative AI face-swap. For security and identity teams evaluating solutions today, understanding how liveness detection actually works, and how to measure it objectively, is no longer optional.
This guide covers the threat landscape driving demand, the technical mechanics of active and passive liveness detection, the ISO 30107-3 standard and its key metrics, the difference between presentation attacks and injection attacks, and a practical framework for evaluating vendors.
Why Liveness Detection Has Become a Priority
The threat environment has changed substantially. In 2023, roughly 500,000 video and voice deepfakes circulated on social media; by 2025 that figure reached an estimated 8 million. The cost of producing convincing forgeries has also fallen sharply. What took cyberattackers weeks to produce in 2022 now takes minutes.
Regulators have taken notice. On November 13, 2024, the Financial Crimes Enforcement Network (FinCEN) issued FIN-2024-Alert004 to help financial institutions identify fraud schemes associated with the use of deepfake media created with generative artificial intelligence (GenAI) in response to increased suspicious activity reporting. FinCEN identified live verification checks, in which a customer is prompted to confirm their identity through audio or video, as one of the key tools to reduce vulnerability to deepfake identity documents.
The implication for compliance and security teams is direct: liveness detection is now a core control, not an enhancement.
What Liveness Detection Actually Does
Liveness detection is a technique used to determine whether a biometric sample, usually a face, is being presented by a real, live human at the time of capture. Its purpose is to prevent fraudsters from using photos, videos, masks, or synthetic content to impersonate someone.
Without liveness detection, biometric systems are vulnerable to presentation and injection attacks. With generative AI making deepfakes easier and more realistic, robust liveness detection is no longer optional.
Liveness detection sits inside the broader identity verification workflow: the system captures a biometric sample, checks for live presence, matches the face against a reference, and returns a decision. The liveness check is the step that validates the integrity of the capture itself.
The Two Core Approaches: Active and Passive Liveness Detection
There are two main types of liveness detection: active and passive. Each has distinct mechanics, trade-offs, and appropriate use cases.
Active Liveness Detection
Active liveness detection requires the user to perform a specific action, like blinking, turning their head, or smiling. These checks are intended to confirm that the person is real and not a static image or basic video.
The process follows a challenge-response model. The system presents a challenge to the user, such as "blink your eyes" or "turn your head to the left," and the user's response is captured via the device's camera. The system then analyzes whether the response matches the expected biometric behavior of a live person.
Passive Liveness Detection
Passive liveness detection works completely in the background without the user having to actively do anything. The software automatically analyses subtle biometric features such as skin texture, reflections in the eyes, depth information, or micro-movements to determine whether it is a real, living face.
The user simply looks at their camera during a normal action like a selfie; behind the scenes, AI analyses a single image or short clip for biological signs of life.
Passive liveness detection works by using artificial intelligence to confirm a person is physically present during identity verification, all from a standard selfie or a short video clip. The system examines the image for dozens of subtle indicators that distinguish a live person from a spoofing attempt, such as a printed photo, a digital screen, or a synthetic deepfake.
Choosing Between Active and Passive
The right choice depends on your risk tolerance, friction budget, and device environment. Many production systems use a hybrid approach. At Identomat, we call it Adaptive Liveness - an intelligent approach that combines passive and active liveness methods and dynamically determines which method to apply based on factors such as risk level, device signals, and user behavior. This allows businesses to maintain a smooth verification experience for genuine users while applying additional scrutiny when potential risk is detected.
The Threat Landscape: Presentation Attacks vs. Injection Attacks
Understanding the distinction between attack types is essential for evaluating whether a liveness solution actually covers your threat model.
Presentation Attacks
A presentation attack occurs when a fraudster holds a physical or digital artifact in front of the camera sensor. Common presentation attack instruments (PAIs) include:
- Printed photographs
- Video replays on a screen or tablet
- 2D and 3D masks, including silicone masks
- Deepfake images displayed on a device
The landscape of presentation attacks is constantly evolving, from simple 2D photos and video replays to sophisticated 3D masks and AI-generated deepfakes. ISO 30107-3 is specifically designed to benchmark a system's resistance to this category of attack.
Injection Attacks
Injection attacks are a more technically advanced threat. Face-swap attacks pair a pre-recorded video of the attacker with a photo of the victim and use generative models to superimpose the victim's face onto the attacker's moving head in real time. The attack reaches identity-verification systems through three paths: a native virtual camera, a device hijack, or a deepfake stream piped into a legitimate camera over a browser or driver shim.
ISO 30107-3: The Global Standard for Liveness Detection
ISO/IEC 30107 is the global standard that defines frameworks for detecting, preventing, and evaluating presentation attacks against biometric systems. It establishes how biometric verification should respond to fraudulent attempts, how systems must be tested, and how assessments should demonstrate trustworthiness.
Developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), the 30107 family is the de facto global benchmark for liveness detection, especially in biometric authentication.
The Key Metrics: APCER and BPCER
ISO 30107-3 introduces two primary performance metrics that every vendor should be able to report:
APCER (Attack Presentation Classification Error Rate) measures how often a spoof attack is incorrectly accepted as genuine. BPCER (Bona Fide Presentation Classification Error Rate) measures how often a legitimate user is incorrectly rejected.
These two metrics are in tension with each other. There is a direct link between APCER and BPCER: if the solution is designed to perform extremely well on APCER (correctly rejecting fakes), this can result in a higher BPCER (falsely rejecting live people). In a real-world scenario, this has to be balanced in order to create security and usability at the same time.
A Practical Framework for Evaluating Liveness Detection Vendors
Use the following criteria when assessing vendors for a regulated identity verification context:
1. Certification and Independent Testing
2. Attack Coverage
3. Active vs. Passive Architecture
5. Integration and Deployment Model
6. Regulatory Alignment
How Identomat Approaches Liveness Detection
For organizations in fintech, banking, crypto, and other regulated industries, liveness detection cannot be evaluated in isolation. It needs to work as part of a complete identity verification and compliance workflow that includes document verification, face matching, and AML screening.
Identomat is a KYC and AML identity verification platform built for regulated industries. Its liveness detection capability is designed to integrate directly with document verification and biometric matching, allowing the liveness check, document verification, and face comparison to operate as a unified workflow rather than as disconnected point solutions.
This matters because fraudsters increasingly combine synthetic identities and manipulated faces with forged or stolen documents. A liveness check that passes but is not cross-referenced against a verified identity document provides only limited assurance.
Conclusion
Liveness detection technology has evolved from a nice-to-have feature into a foundational control for organizations conducting remote identity verification. The threat landscape, driven in part by generative AI, has made biometric spoofing faster, cheaper, and more accessible than ever before.
Understanding the difference between active and passive liveness detection, knowing what ISO/IEC 30107-3 actually measures, and asking vendors the right questions can put your organization in a significantly stronger position than relying on marketing claims alone.
Organizations that want to strengthen their defenses should treat liveness detection as a technical discipline that requires rigorous vendor evaluation—not simply as a checkbox on a procurement form.



