Video Injection Detection
Controls that detect injected, replayed, or pre-recorded video streams used to bypass selfie and liveness checks during remote identity verification.
Overview
Video injection detection focuses on identifying attempts to feed a verification system a manipulated or pre-recorded stream (for example, via virtual cameras, screen replays, or intermediaries) instead of a live capture from the user’s device camera.
Typical signals and controls
- Capture pipeline integrity checks (e.g., detecting virtual camera sources).
- Consistency checks across frames and metadata (timing, encoding artifacts).
- Challenge-response or motion prompts combined with PAD/liveness.
Where it shows up
- Remote onboarding / selfie identity verification
- Account recovery re-verification
- High-risk transaction step-up checks
References
Vendors using Video Injection Detection
Latest Data Cards
Data Card Researchers detail an Android toolkit that feeds fake video into live KYC checks
2026-08-28CC-BY-4.0video-injection-detectionpadCybernews researchers documented an Android toolkit that feeds saved photographs, prerecorded video, or a remotely controlled stream into a verification app as though it came from the phone camera.
- The toolkit injects prerecorded media or remote streams into the camera subsystem on rooted devices.
- It can spoof hardware signatures, location data, and security profiles.
- Researchers found no evidence of widespread production exploitation and recommend server-side dynamic liveness challenges and hardware nonce verification.
Data Card GetReal adds continuous identity verification to deepfake detection platform
2026-05-18CC-BY-4.0deepfake-detectionvideo-injection-detectionGetReal Security added continuous identity verification to GetReal Protect, extending its live communications security platform from initial deepfake detection to ongoing participant verification.
- The feature is designed to verify that a person who joins a voice or video session remains the same person throughout the call.
- GetReal Protect combines multimodal deepfake detection, impersonation detection, continuous verification, and threat intelligence.
- The capability targets live-session risks where fraud can begin after a one-time authentication event.
Data Card Aware reports zero injection attack bypasses in BixeLab CEN/TS 18099 evaluation
2026-05-13CC-BY-4.0padvideo-injection-detectionfacial-recognitionawareAware said its Intelligent Liveness technology recorded zero successful injection attack bypasses across 900 BixeLab test scenarios aligned with CEN/TS 18099:2024.
- The evaluation included 600 injection attack transactions across 10 instrument species and four attack methods.
- The reported result included zero successful injection bypasses and a 0 percent bona fide presentation classification error rate.
- CEN/TS 18099 focuses on internal injection attacks that bypass the camera sensor, a different threat class from traditional presentation attacks.