Liveness detection is what stops a stolen selfie passing as a live customer. The types explained, the attacks they catch, and the gap that top-tier certification still leaves open.
Identity fraud has not just grown since 2023, it has industrialised. Shufti’s Identity Fraud Index Report 2026 projects deepfake-powered identity fraud to rise 495% in 2026 over 2025, based on proprietary fraud-attempt data processed across its global verification network.
Synthetic identity accounted for 42.3% of AI-enabled fraud incidents in 2025, followed by live video deepfakes at 28.1%, face swaps at 17.6%, and document deepfakes at 11.9%. The mix matters more than the headline number, because a control tuned for one attack type leaves the other three open.
Most deepfakes are forged by using AI and ML technologies, holographic models allow these criminals to create a simulated mesh through machine learning. The question is the legitimacy of the deepfakes, how are they able to bypass security protocols? This is because they use stolen information from users, and individuals subjected to data breaches and identity theft also become victims of deepfake forgery. Their stolen information is used to forge and simulate a deepfake. This way, criminals stay in the shadows and use someone else’s identity to commit crimes.
Biometric Facial Recognition: Its Use in IDV
To effectively battle the threat of criminals using forged identities to bypass security protocols, businesses need to ensure that they have a robust security solution in place.
Biometric facial recognition is a mechanism that is often paired with the identity verification process to ensure that any forged documents are not being used to carry out fraud. Biometric facial recognition is carried out using both active and passive verification methods. Once users enter their information, they must complete a face ID check in real-time or upload a verified picture. The most common biometric facial recognition methods are:
- Facial Recognition
- Iris Recognition
- Retina Recognition
- Behavioral Biometrics
- Facial Thermography
Real-time facial recognition is more efficient as it is more likely to catch criminals using stolen on-paper information. Biometric facial recognition verifies unique facial features, such as skin and iris patterns, to authenticate the user. An entity using stolen information is very likely to be detected at this security checkpoint. The first step in this security procedure is to enroll facial data. This data is then cross-checked against official government data sources to ensure 3-D facial liveness. If the biometric facial recognition requirements are not met, the user in question is either eliminated or restricted from proceeding further.
What is Liveness Detection?
Liveness detection is essential to biometric facial recognition, as it helps prevent advanced threats. Biometric facial recognition can be bypassed because it is not active verification, and any criminal can create a fake identity. Using editing software, a fake biometric identity can be created. Liveness detection makes biometric facial recognition even more robust. Businesses can utilize it to verify their users in real-time.
Once a user reaches a specific security checkpoint, the software requires them to verify their identity using the facial biometric verification method. Biometric solutions paired with liveness detection accurately verify the user with their flawless verification technology. These solutions integrate 3-D liveness detection that makes sure a user is accurate, and it is not an edited picture or a fake simulation. Afterward, a liveness detection exercise is also carried out. Users must perform specific actions that determine whether the user being onboarded is an actual entity or a simulation.
The most commonly used liveness detection methods are:
- Texture Analysis
This method is used to detect natural and artificial variations in skin textures. Every person’s skin has a specific texture that can not be replicated. A 3D liveness check helps companies distinguish between a natural person’s skin texture and a printed or digital representation. This way, a deepfake can be identified and eliminated.
- Motion Analysis
This aspect of liveness detection tracks the movements of the user. Full-body movements and micromovements are both tracked. These include acts such as blinking, moving eyes, head tilting, and facial expressions. These acts have no specific pattern and cannot be anticipated. On the other hand, a deepfake has repeating movements and motion, which is repetitive because it is pre-programmed.
- 3D Depth Sensing
Modern security systems employ advanced technologies such as structured light or time-of-flight cameras to create a highly detailed three-dimensional map of an individual’s face. This enables the system to effectively differentiate between a natural, live person and a two-dimensional image or a pre-recorded video, ensuring strict measures are in place to prevent unauthorized access or fraudulent activities.
- Infrared Imaging
Infrared imaging uses lenses to detect light wavelengths that are specific to the human skin and are not visible to the human eye in regular cases. An actual entity will produce these wavelengths, while a deepfake will not produce them. This helps businesses with face anti-spoofing and differentiating deepfakes.
What are the Different Types of Liveness Detection?
Liveness detection sorts into two families, separated by whether the system asks the user to do anything. Active liveness issues a prompt and grades the response. Passive liveness reads the capture itself and asks for nothing. Most production stacks now run both, and the risk policy decides how much friction a given session sees.
Regulators recognise the split. The European Banking Authority’s Guidelines on the use of remote customer onboarding solutions (EBA/GL/2022/15, November 2022) require unattended onboarding flows to perform liveness detection verifications, “which may include procedures where a specific action from the customer is required to verify that he/she is present in the communication session or which can be based on the analysis of the received data and does not require a specific action by the customer.” The first description is active liveness, the second is passive, and the EBA’s accompanying analysis names both directly.
| Type | How the check runs | What the user does | Where it strains |
| Active liveness | Issues an unpredictable prompt and grades the response in real time | Blinks, smiles, turns the head, or follows an on-screen cue | Adds steps, which raises abandonment on mobile and slow connections |
| Passive liveness | Analyses a single capture for depth, texture, and micro-motion | Nothing beyond holding still for the selfie | Places the entire burden on model quality, so independent lab evidence matters more |
| Hybrid, risk-based | Runs passive by default and escalates to an active challenge when risk signals fire | Nothing, unless the session is flagged | Needs a risk engine behind it, otherwise the escalation rule is arbitrary |
| Document liveness | Confirms the ID itself is physically present rather than a screen grab or a reprint | Captures the document on camera | Sits outside face liveness entirely, so a face-only stack leaves the gap open |
Face liveness and document liveness answer different questions, and neither substitutes for the other. A genuine live person can hold up a photograph of a stolen passport, and a genuine passport can be held by someone replaying a video of its owner. The full picture needs both checks bound to the same session.
For a deeper comparison of the two main approaches, including what independent lab testing has changed about the old security-versus-friction trade-off, see active vs passive liveness.
The Benefits of Liveness Detection
3-D facial liveness detection is a process that can help businesses significantly elevate their security with accurate verification processes.
- Prevention of Anti-Spoofing Attacks
Liveness detection is a security feature that helps prevent unauthorized access by detecting and mitigating attempts at impersonation through the use of liveness detection in authorizing photos, videos, or other non-living representations of a person’s face. This technology ensures that the presented facial features belong to a live person, providing an additional layer of security against fraudsters.
- Enhanced Security
Entities such as scammers, fraudsters, money launderers, and illegal financiers are always looking for companies they can use as a middle gateway to wash their black money. These entities try their best to infiltrate business systems, and using deepfake technology is one of the primary methods. Liveness detection keeps these entities off of a business’s radar and allows firms to proceed with their functions safely.
- Compliance with Regulations
Two frameworks put liveness inside the compliance perimeter rather than beside it. The FATF Guidance on Digital Identity (March 2020) lists liveness detection within the verification step of identity proofing, which links the individual to the identity evidence they provided. The European Banking Authority went further in EBA/GL/2022/15, which requires credit and financial institutions running unattended remote onboarding to perform liveness detection verifications. A firm that onboards a customer who was never actually present has not completed customer due diligence, whatever its file says, and that is the exposure supervisors price into enforcement.
- Convenient User-Experience
Modern liveness detection is an alternative to biometric facial recognition, allowing companies to deploy a more seamless verification solution. This is convenient because it will enable companies to conduct facial verification in seconds, giving them instant results. User convenience is also a significant factor because users have an automated facial recognition process that requires no physical presence or extra documents.
Overall, biometric facial recognition with liveness detection offers a powerful and convenient solution for identity verification (IDV) in various industries. By effectively complementing your liveness verification processes, this technology can significantly build trust and security in the digital world.
What Types of Biometric Spoofing Attacks Can Liveness Detection Detect?
Liveness detection is built to catch presentation attacks, meaning fakes shown to the camera. ISO/IEC 30107-3:2023, the international standard for biometric presentation attack detection, draws that boundary in its own scope statement, “The attacks considered in this document take place at the biometric capture device during presentation. Any other attacks are considered outside the scope of this document.”
Within that boundary, a liveness layer is tested against four attack families.
- Printed photographs and paper masks: Flat 2D reproductions, including cut-outs with the eye area removed. Texture and depth analysis reject these first.
- Screen and video replay: A phone or monitor held up to the camera, replaying a stolen selfie or a recorded session. Reflection, moiré, and refresh-rate artefacts give these away.
- 3D masks: Silicone, urethane, and resin casts, which are the hardest presentation attack to defeat and the reason the highest testing tier exists.
- Deepfake video played to a lens: A synthetic face rendered on a screen and shown to the camera, which still fails depth analysis because the screen is flat.
The gap most buyers miss. Injection attacks never touch the camera. A virtual camera driver or a modified app feeds a synthetic video stream straight into the verification pipeline, so no fake is ever presented to a lens and presentation attack detection has nothing to look at. That distinction matters commercially, because a vendor can hold top-tier presentation attack conformance and still have no defence against an injected stream. Independent PAD conformance and injection resistance are assessed separately, so ask any provider to evidence both rather than assuming one covers the other. Shufti covers this ground in more depth in deepfake presentation and injection attacks and injection attacks in biometric systems.
A single selfie check stops being a control at the volumes now in play, because attackers only need one of these attack families to go unguarded.
Liveness Detection with Shufti
Shufti advanced machine learning mechanisms perform 3D depth analysis to the highest level by using appropriate reference data. Our full-scale verification solution provides businesses with a suite of verification solutions paired with liveness detection. Our solutions establish the real persona of an entity, which also guards against facial spoof attacks.
In April 2026 Shufti became the first European company to achieve iBeta Level 3 Presentation Attack Detection conformance under ISO/IEC 30107-3 for passive single-selfie liveness on both iOS and Android. The evaluation recorded 0% Attack Presentation Classification Error Rate and 0% Bona Fide Presentation Classification Error Rate across 900 mask attacks and 100 genuine presentations, tested between 27 March and 24 April 2026 by iBeta Quality Assurance, an NVLAP-accredited laboratory. Every spoof was rejected, and every legitimate user was accepted, without asking anyone to blink or turn their head. Shufti takes every measure to handle deepfakes, and our IDV experts are always there for assistance.
Still unsure about your biometric verification needs? Talk to an expert now and achieve your verification goals with Shufti biometric facial recognition and liveness detection.
Frequently Asked Questions
Q: What is liveness detection in identity verification?
Liveness detection confirms that the face in front of the camera belongs to a real person present at that moment, not a photo, a screen replay, a mask, or a deepfake. It runs alongside the face match, which only confirms that two images show the same person.
Q: How does liveness detection prevent deepfake and spoofing attacks?
Liveness detection reads signals a synthetic face struggles to reproduce, including skin texture under light, involuntary micro-movement, and three-dimensional depth. A deepfake rendered onto a flat screen has no true depth, so depth and texture analysis reject it before the face match ever runs.
Q: What are the different types of liveness detection methods?
Two main types exist, active and passive. Active liveness prompts an unpredictable action such as a blink or a head turn and grades the response. Passive liveness analyses a single capture without asking for anything. Document liveness is a third class, confirming the ID itself is physically present.
Q: What types of biometric spoofing attacks can liveness detection detect?
Presentation attacks, meaning fakes shown to the camera. That covers printed photographs, screen and video replays, paper masks, and silicone or resin 3D masks. Injection attacks, which feed a synthetic stream past the camera entirely, fall outside presentation attack detection and need a separate control.
Q: Why is liveness detection important for AML/CFT compliance?
Regulators treat liveness as a condition of remote onboarding. EBA Guidelines EBA/GL/2022/15 require unattended onboarding flows to perform liveness checks, and the FATF Guidance on Digital Identity (March 2020) names liveness detection within the verification step of identity proofing. Onboarding someone who was never present breaks customer due diligence.
Q: Why is liveness detection an important security layer in facial biometrics?
Face matching alone cannot separate a live person from a high-quality image of one. A stolen selfie matches the reference photo perfectly, so without a liveness layer, the biometric check confirms only that an attacker holds a picture of the real customer.















