Presentation attack (spoofing)
Also known as: Presentation attack · PAD · Spoofing · Spoof attack · Biometric spoofing
An attempt to fool a biometric check by presenting an artifact to the camera — a photo, a video, a mask or a deepfake — in place of the live person.
Legal basis
ISO/IEC 30107-1 — Presentation Attack Detection (framework)
The presentation attack is the classic attempt against biometrics: instead of the real face, a printed photo, a video on a screen, a 3D mask or a deepfake is held up to the camera. The defense is liveness detection, whose effectiveness against these attacks is measured by the ISO/IEC 30107 standard (*presentation attack detection*, PAD), the reference that NIST's own testing also uses.
It is why face comparison is never the only signal: without liveness, the holder's photo pulled from a social network passes verification. A presentation attack shows the artifact *through the camera*; when the fake video is fed straight into the flow, with no camera, it is a different type — the injection attack.
Frequently asked questions
What is a presentation attack in biometrics?
It is showing an artifact to the camera — a photo, video, mask or deepfake — in place of the live person, to fool facial verification. The defense is liveness detection, whose resistance to these attacks is measured by the ISO/IEC 30107 standard.