Presentation Attack Detection (Liveness / PAD)

Techniques and tests that detect spoofed biometric samples (e.g., masks, replays, synthetics) to ensure the sample is from a live, consenting subject.

Overview

Presentation Attack Detection (PAD) protects biometric systems from spoofs such as printed photos, silicone fingerprints, recorded voices, or AI-generated samples. It’s a cross-cutting layer used with face, voice, fingerprint, iris and other modalities.

How it works

  1. Capture: Sensor or camera acquires the sample.
  2. Signal analysis: Algorithms look for cues inconsistent with live traits (e.g., texture, reflectance, micro-motions, audio artifacts).
  3. Decision & score: The PAD subsystem outputs a score or decision (bona fide vs attack).
  4. Policy: Systems combine PAD with biometric matching and business rules to accept/deny or request step-up verification.

Common use cases

  • Remote onboarding / selfie match
  • Contactless border checks
  • KYC and high-risk transactions
  • Access control and workforce auth
  • Dating-app trust and safety
  • AI-platform account abuse prevention
  • Proof-of-life checks for benefits or pensions

Strengths and limitations

Strengths: Mitigates common spoofs; complements matching; standard metrics for evaluation.
Limitations: Attack diversity; new synthetic media; environment variability; false rejections at strict thresholds.

Key terms

  • APCER/BPCER: Core PAD error metrics from ISO/IEC 30107-3.
  • PAI (Presentation Attack Instrument): The artifact used to attack.
  • Attack potential: Effort/resources required to mount an attack.

Current market signal

PAD has moved from a back-end biometric security feature into a visible trust layer for consumer platforms. Recent coverage connects liveness to dating safety, AI-account verification, stablecoin onboarding, and public-benefit proof-of-life checks. This means PAD should be interpreted as both a biometric security control and a platform-integrity control.

References

Vendors using Presentation Attack Detection (Liveness / PAD)

Latest Data Cards

  • Data Card

    BoyleSports selects Jumio for player identity verification

    2026-07-13CC-BY-4.0document-verification-nfcfacial-recognitionpadjumio

    BoyleSports selected Jumio Identity Verification and Doc Proof to automate player onboarding and compliance checks across the UK and Ireland.

    • The deployment combines identity verification, document checks, biometric screening, and automated AML screening.
    • The workflow supports compliance with Ireland's new Gambling Regulatory Authority requirements.
    • BoyleSports reported higher automatic verification rates and less manual review after deployment.
  • Data Card

    Innovatrics and Boom ID bring contactless palm recognition to authorization

    2026-07-07CC-BY-4.0palmprint-recognitionpadinnovatrics

    Innovatrics partnered with Boom ID to add contactless palm recognition and liveness checks to transaction, workforce, visitor, vendor, and physical-access authorization workflows.

    • The system captures a palm with standard cameras rather than requiring dedicated contact hardware.
    • Innovatrics combines contactless palm matching with liveness detection.
    • Boom ID applies the biometric check at the point of a sensitive action, not only at initial login.
  • Data Card

    Anthropic adds ID and selfie verification for selected Claude users

    2026-06-23CC-BY-4.0digital-idfacial-recognitionpad

    Anthropic began requiring government ID and selfie verification for some Claude users, adding document and biometric checks to account trust controls for AI access.

    • The checks apply to selected user tiers or accounts flagged by trust-and-safety systems.
    • The flow combines a government-issued photo ID with a live selfie check.
    • The move shows AI platforms adopting identity proofing controls to manage abuse, anomalous API activity, and policy enforcement.

Frequently Asked Questions

What metrics does ISO/IEC 30107-3 define?
APCER (attack presentations misclassified as bona fide) and BPCER (bona fide misclassified as attacks). Vendors often report operating points across attack species and attack potential.
Is PAD the same as liveness?
‘Liveness’ is commonly used, but PAD is broader: it covers detecting presentation attacks of many kinds (physical and digital), not only vitality cues.
How is PAD evaluated in practice?
Independent labs test across PAI types and attack potentials, reporting APCER/BPCER at defined thresholds; results are separate from core matcher accuracy.