How Injection Attacks Broke Liveness Detection, and What Replaced It

How Injection Attacks Broke Liveness Detection, and What Replaced It
Written By:
IndustryTrends
Published on
Updated on

Remote identity verification rested for years on a single assumption that nobody wrote down because it seemed too obvious to state: the image being analysed came from the camera.       

Everything else followed from it. If the frames arrived from a physical sensor pointed at a physical scene, then the job was to work out whether that scene contained a living person or a representation of one. That is a computer vision problem, and the industry got good at solving it.

Attackers solved a different problem instead. They stopped using the camera.

What liveness detection actually measured

Presentation attack detection, the formal name for liveness checking, splits into two approaches.

Passive methods analyse properties of the image that differ between a face and a reproduction of a face. Human skin scatters light beneath its surface, producing a reflectance profile that paper and glass do not reproduce cleanly.

A photographed screen frequently generates moiré interference, invisible to the eye but detectable algorithmically. A flat surface has no depth, so when the head shifts slightly, the parallax between near and far facial features is absent. Some systems go further and look for periodic micro-variations in skin colour caused by blood flow, a technique known as remote photoplethysmography.

Active methods ask the user to do something: blink, turn, read a number from the screen, or hold still while the display projects a sequence of coloured light and the system measures how it reflects off a three dimensional surface.

Both families are effective against what they were designed for. Both assume a scene exists.

What injection attacks do instead

An injection attack delivers a fabricated video stream directly into the verification application, through a virtual camera driver, a compromised device input, or a manipulated browser media pipeline. The physical camera is never involved. There is no printed photograph, no screen held up, no mask.

This does not defeat presentation attack detection so much as bypass the question it answers. The system is still asking whether the scene in front of the lens is real, while the attacker has removed the lens from the chain entirely.

The measured growth is steep. The Entrust 2026 Identity Fraud Report, drawn from more than a billion identity verification events across 195 countries, found that injection attacks rose 40 percent year over year, and that AI generated material now accounts for roughly one in five biometric fraud attempts. Separate threat intelligence from iProov has tracked native virtual camera attacks growing by several orders of magnitude, with a sharp concentration in attacks targeting mobile verification platforms.

The generative side compounds it. A synthetic face rendered in real time can blink, turn, and follow on screen instructions, which means the active challenge, for years the strongest single control, is now something a sufficiently good model simply performs.

What replaced it

The response reframes the question from perception to provenance. Not "is this a real person?" but "did this signal originate where it claims to have originated?"

That is a different engineering problem and it draws on different evidence: cryptographic attestation of the application and device, detection of virtual camera drivers and hooked media pipelines, analysis of stream timing and compression artefacts that differ between sensor output and synthesised output, and integrity checks that are considerably harder to implement in a browser than in a native SDK.

This class of control is what the industry now calls injection attack detection, and it has moved from a differentiator to a procurement requirement in about two years.

"The era of treating biometric verification as a solved problem is over. Generative AI has fundamentally shifted the threat model from presentation attacks to injection attacks, and any organization that hasn't adapted its defenses is operating on borrowed time," said Teodor Rogojina, CEO of Qoobiss, the Romanian identity verification provider, announcing in June 2026 that it was submitting its platform for Extended Level PAD and IAD evaluation.

Synthetic identities: the fraud category AI made cheap

The economics matter more than the technology, and they explain where the pressure lands.

Synthetic identity fraud combines real data elements, most often a valid national identification number, with fabricated ones: a name that does not belong to that number, an invented address, and increasingly a generated face. The result is a person who does not exist but who passes automated checks, because each element is individually plausible and no real individual will ever file a complaint.

Generative tools removed the last expensive component of that construction, which was a convincing face that could satisfy a liveness check. What used to require a cooperating human accomplice now requires a model and a virtual camera.

Because there is no victim to report it, this category tends to be understated in fraud statistics and overrepresented in eventual losses, which surface at bust out rather than at onboarding.

The standards caught up, slowly

Evaluation frameworks have adjusted. Extended Level assessment under ISO/IEC 30107-3 tests biometric systems against a substantially broader set of attack instruments than Basic Level, including high quality masks, synthetic face presentation, and deepfake injection. In Europe, ETSI TS 119 461 and CEN/TS 18099 provide the conformity framework for remote identity proofing.

The regulatory pull is specific. The architecture reference framework for the EU Digital Identity Wallet cites ISO 30107-3 within its security requirements for remote identity proofing, and several member states are expected to require Extended Level conformance from verification services participating in the wallet ecosystem. Member states must make wallets available by December 6, 2026, and organisations legally required to use strong user authentication, banks foremost among them, must accept them from December 6, 2027.

For vendors, that converts independent evaluation from a marketing asset into a condition of market access, on a timeline that does not accommodate a late start.

The uncomfortable asymmetry

Document verification has a clean answer. A chip signed by an issuing state either validates against that state's certificate or it does not, and there is no middle ground.

Verifying the human has no equivalent. There is no cryptographic proof that the person in front of the camera is the document holder and is present right now. There is only a probability, assembled from physical signals and, increasingly, from evidence about where the signal came from.

The document problem is solved. The person problem is the one the next several years will be spent on.

logo
Analytics Insight: Top Tech & Crypto Publication | Latest AI, Tech, Crypto News
www.analyticsinsight.net