PAD testing varies widely. Here is what to look for
PAD evaluation is not a single, uniform thing. The quality of a test depends on the breadth of attack species covered, the sophistication level they represent, the independence of the laboratory conducting them, and whether the methodology is grounded in current threat intelligence. Understanding those variables is how you distinguish an evaluation that builds real confidence from one that simply provides a certificate.
Challenging the system
The number of test transactions matters. A larger sample size increases statistical confidence and reduces the likelihood that results are influenced by one-off anomalies. But transaction volume alone does not determine the quality of a Presentation Attack Detection (PAD) evaluation.
What distinguishes a rigorous evaluation is the challenge it presents to the system. This depends on the breadth and sophistication of the presentation attack instruments (PAIs) used, the independence of the testing laboratory, and whether the methodology reflects the techniques being used by real-world attackers.
Effective PAD testing also relies on continual research and innovation. Attack methods are constantly evolving, and even seemingly minor changes—such as introducing a subtle curve to a printed mask or altering the fit of a wig—can be enough to bypass an otherwise robust system. High-quality laboratories continuously refine and develop new attack instruments to expose vulnerabilities before adversaries do.
A test based on large volumes of low-sophistication attacks can demonstrate resilience against well-known techniques, but it provides only part of the picture. A more meaningful evaluation challenges the system across the full range of attack sophistication, using diverse presentation attack instruments on multiple devices and platforms. When those attacks are informed by current threat intelligence and developed to reflect emerging techniques, the results provide a much higher level of assurance.
For organisations operating in high-risk sectors such as financial services, digital identity, government and border security, this depth of testing is not optional. Confidence comes not from the number of transactions alone, but from knowing the system has been challenged with the attacks that matter most.
What to examine when comparing PAD testing providers
Breadth and sophistication of presentation attack instruments
Not all PAD evaluations challenge systems in the same way. A meaningful evaluation should include a diverse range of presentation attack instruments (PAIs), spanning low-, medium- and high-sophistication attack species.
The appropriate level of testing depends on your risk profile. A consumer application may only require assurance against common attacks, whereas financial services, digital identity, government and border security applications are increasingly expected to demonstrate resilience against highly sophisticated attacks.
Three-dimensional masks, advanced silicone artefacts and AI-enabled presentation attacks such as deepfakes presented on devices are no longer theoretical. As attack techniques become more accessible and industrialised, organisations need confidence that their systems have been evaluated against the threats they are most likely to face. Ingenium provides testing across all recognised sophistication levels, including Level C attack species where appropriate.
Attack species evolution
Presentation attacks evolve rapidly. Techniques that once required specialist knowledge can quickly become accessible through commercially available materials, open-source tools or advances in artificial intelligence. A static attack catalogue quickly loses relevance.
Ingenium continually develops and refines its library of presentation attack instruments using insights from operational research, national security partners, academic collaboration and international standards development. This ensures our evaluations remain aligned with the evolving threat landscape rather than yesterday’s attacks.
The appropriate level of testing depends on your risk profile. A consumer application may only require assurance against common attacks, whereas financial services, digital identity, government and border security applications are increasingly expected to demonstrate resilience against highly sophisticated attacks.
Three-dimensional masks, advanced silicone artefacts and AI-enabled presentation attacks such as deepfakes presented on devices are no longer theoretical. As attack techniques become more accessible and industrialised, organisations need confidence that their systems have been evaluated against the threats they are most likely to face. Ingenium provides testing across all recognised sophistication levels, including Level C attack species where appropriate.
Attack species evolution
Presentation attacks evolve rapidly. Techniques that once required specialist knowledge can quickly become accessible through commercially available materials, open-source tools or advances in artificial intelligence. A static attack catalogue quickly loses relevance.
Ingenium continually develops and refines its library of presentation attack instruments using insights from operational research, national security partners, academic collaboration and international standards development. This ensures our evaluations remain aligned with the evolving threat landscape rather than yesterday’s attacks.
The appropriate level of testing depends on your risk profile. A consumer application may only require assurance against common attacks, whereas financial services, digital identity, government and border security applications are increasingly expected to demonstrate resilience against highly sophisticated attacks.
Three-dimensional masks, advanced silicone artefacts and AI-enabled presentation attacks such as deepfakes presented on devices are no longer theoretical. As attack techniques become more accessible and industrialised, organisations need confidence that their systems have been evaluated against the threats they are most likely to face. Ingenium provides testing across all recognised sophistication levels, including Level C attack species where appropriate.
Device and platform coverage
PAD performance is not always consistent across deployment environments. Differences in camera hardware, operating systems, browsers and application implementations can all influence performance. Results obtained on one device should not be assumed to apply universally.
Ingenium evaluates biometric systems across client-selected devices representative of the intended deployment, including mobile applications, browser-based solutions and dedicated hardware. This provides a more accurate picture of real-world performance.
Independence and methodology
Independent testing provides a level of assurance that vendor-led testing cannot. While internal testing is an essential part of product development, it is typically performed with detailed knowledge of the system and under conditions controlled by the developer.
An independent laboratory approaches the evaluation differently. Test methods, attack selection and execution are designed to challenge the system objectively, without favouring known strengths or expected behaviour. This provides organisations with greater confidence that the reported performance reflects genuine resilience rather than performance under optimised conditions.
Attack species evolution
Presentation attacks evolve rapidly. Techniques that once required specialist knowledge can quickly become accessible through commercially available materials, open-source tools or advances in artificial intelligence. A static attack catalogue quickly loses relevance.
Ingenium continually develops and refines its library of presentation attack instruments using insights from operational research, national security partners, academic collaboration and international standards development. This ensures our evaluations remain aligned with the evolving threat landscape rather than yesterday’s attacks.
The appropriate level of testing depends on your risk profile. A consumer application may only require assurance against common attacks, whereas financial services, digital identity, government and border security applications are increasingly expected to demonstrate resilience against highly sophisticated attacks.
Three-dimensional masks, advanced silicone artefacts and AI-enabled presentation attacks such as deepfakes presented on devices are no longer theoretical. As attack techniques become more accessible and industrialised, organisations need confidence that their systems have been evaluated against the threats they are most likely to face. Ingenium provides testing across all recognised sophistication levels, including Level C attack species where appropriate.
Reporting depth
A simple pass or fail provides limited insight into the security of a biometric system. Effective evaluation should explain why a system performed as it did and identify where vulnerabilities exist.
Ingenium’s reports include detailed results for individual presentation attack species, performance across different devices and platforms, and analysis of observed weaknesses and their practical implications. This enables vendors to improve their technology and helps buyers make informed, risk-based decisions about deployment.
Testing that reflects the real threat, not a simplified version of it
A high-quality PAD evaluation should do more than produce performance metrics. It should demonstrate how a biometric system performs against the attacks it is likely to encounter in the real world, using a methodology that is objective, repeatable and independently verified.
Ingenium’s PAD evaluation programme is accredited to ISO/IEC 17025 and conducted in accordance with ISO/IEC 30107, the internationally recognised framework for Presentation Attack Detection (PAD) testing. Every evaluation measures both Attack Presentation Classification Error Rate (APCER) and Bona Fide Presentation Classification Error Rate (BPCER), because security and usability must always be considered together. A system that blocks every attack but rejects legitimate users is no more effective than one that accepts every user but cannot detect a spoof.
The quality of a PAD evaluation depends on how convincingly it challenges the system. Ingenium develops and characterises presentation attack instruments across the recognised range of attack sophistication, informed by the NIST Strength of Function for Authenticators for Biometrics (SOFA-B) framework. This enables organisations to understand not only whether their system can resist common attacks, but how it performs against increasingly capable and determined adversaries.
Representative testing is equally important. Presentation attack instruments are created using source imagery from a diverse population, encompassing a broad range of ages, ethnicities and genders. This helps ensure evaluations reflect the diversity of real users and reduces the risk of performance conclusions being biased towards a narrow demographic.
All testing is performed within a controlled laboratory environment to ensure results are repeatable, traceable and scientifically defensible. While the test conditions are tightly controlled, the attack scenarios are not artificially simplified. Ingenium continually updates its threat models and attack instruments using operational research, threat intelligence, academic collaboration and international standards development, ensuring evaluations remain aligned with the techniques used by today’s attackers rather than those of the past.
The result is independent, evidence-based assurance that reflects how a biometric system performs against the attacks that matter most, providing organisations with the confidence to make informed deployment and risk-management decisions.
Evidence that holds up where it needs to
The value of a rigorous evaluation depends on what it produces. Ingenium’s PAD evaluations deliver:
Ingenium’s PAD evaluation programme is led by independent experts with no commercial interest in the outcome. The reports it produces are structured to be transparent, reproducible, and usable.
A detailed test report with methodology, species-level results by device, conclusions, and recommendations
Performance data across APCER, BPCER, and FTA for each device tested
Analysis that identifies where a PAD subsystem is underperforming, not just whether it passed
A results presentation and Q&A session to support interpretation and communication of findings
Evidence suitable for use in regulatory conversations, procurement applications, and market-facing contexts
For technology vendors, independently produced results can be referenced and published. They provide a credible, third-party foundation that vendor claims alone cannot match.
Not all PAD testing is created equal. Find out what rigorous looks like.
If you’d like to understand how the quality and coverage of your current testing compares to what your risk profile requires, or how independent testing can strengthen your market position, our team is here to help.
