Zarv

Injection attack

Also known as: Injection attack · Video injection · Virtual camera attack · Deepfake injection · Camera bypass

Fraud that inserts a fake video or image directly into the verification stream — via a virtual camera or app interception — without going through any real camera.

Legal basis

ISO/IEC 30107-3 — Presentation Attack Detection (testing & reporting)

In a presentation attack, the artifact is shown to a camera; in an injection attack, there is no camera. The fraudster feeds the video — often a deepfake — straight into the flow, using a virtual camera, an emulator or interception of the app, so the system receives an image that was never actually captured. It is more dangerous because it slips past defenses that look for screen reflections, edges and depth.

Because the image arrives "clean", the defense shifts to channel integrity: proving the video came from the device's real camera and was not injected, detecting the emulation environment and the device signals that give away the manipulation. It is the current frontier of remote biometric verification, as generating a convincing deepfake gets cheaper.

Frequently asked questions

What is the difference between a presentation attack and an injection attack?

In a presentation attack, an artifact (photo, video, mask) is shown to a real camera. In an injection attack, the fake video is inserted directly into the flow — via a virtual camera or interception — without going through any camera, which makes it harder to detect.

Sources

Related terms

See it in practice

See risk before it costs you.

GDPR & CCPA Compliant · No commitment · Live in minutes