Injection attack detection testing that goes beyond the standard
Injection attack detection (IAD) testing evaluates how well a biometric and identity system identifies and resists attempts to inject data directly into its data stream, bypassing the sensor entirely. Ingenium provides a tiered programme of IAD testing from foundational compliance-level evaluations through to advanced assessments designed to reflect the capabilities of organised threat actors.
A threat that bypasses what most testing looks for
A presentation attack requires physical access to a sensor. An injection attack does not.
Instead of presenting a fake face or document to a camera, an attacker manipulates the data stream between the sensor and the system, inserting biometric data that the system accepts as genuine. The attack is invisible to traditional presentation attack defences and operates at a level most standard audits are not designed to examine.
The instruments used range from replayed video streams to AI-generated deepfakes. The methods of delivery include virtual cameras, function hooking, OS-level exploits, and network interception. What unites them is their ability to operate silently, at scale, and without triggering standard security alerts.
The testing framework
Five levels of coverage. From compliance baseline to advanced assurance.
Ingenium’s IAD testing programme comprises five distinct levels, structured around the CEN/TS 18099 standard and extending beyond it.
Each level represents a specific combination of Injection Attack Methods (IAMs) and Injection Attack Instruments (IAIs), with increasing breadth and depth as levels progress.
Standard compliance
Beyond standard compliance
Level 1 – CEN/TS 18099 Substantial
The foundational compliance tier. Aligned with the CEN/TS 18099 ‘Substantial’ evaluation level, Level 1 tests against 2 or more IAMs and 10 or more IAI species. A well-structured starting point for organisations at the beginning of their IAD testing programme, or where CEN/TS 18099 Substantial compliance is the primary requirement.
Level 2 – CEN/TS 18099 High
Aligned with the CEN/TS 18099 ‘High’ evaluation level. Expands IAM coverage to 3 or more methods and increases the attack weighting, providing a more rigorous evaluation of system resilience against a broader range of delivery mechanisms.
Level 3 – Beyond the standard
Exceeds the CEN/TS 18099 requirements, with greater emphasis on sophisticated IAMs and a more diverse set of IAI species. Designed for organisations that require testing to go beyond the compliance threshold and reflect a more realistic threat picture.
Level 4 – Extended IAI focus
A 40 FTE-day programme that maintains high attack weighting while specifically targeting a system’s IAI detection capabilities. This level also provides valuable insight into PAD subsystem resilience as a secondary output – not a formal PAD assessment, but a meaningful supplementary perspective on system behaviour.
Level 5 – Maximum coverage
Ingenium’s most comprehensive IAD evaluation. Level 5 includes the highest volume of IAI species – including instruments specifically created by Ingenium’s team to target the unique functionality of the system under test. Designed for systems that operate in high-risk environments or where the highest available level of assurance is required.
What Ingenium brings to IAD testing
Staying ahead of the threat requires more than a standard methodology
Injection attack methods do not stand still. Hackers innovate when they fail: refining instruments, automating delivery, and adopting new generative AI capabilities as they become accessible. A testing programme that reflects last year’s threat landscape may not detect next year’s attacks.
Ingenium invests in partnerships with public sector bodies, academic institutions, and international standards working groups. These relationships give us access to emerging threat intelligence, including attack methods not yet reflected in published standards, and enable us to develop testing that mirrors the capabilities of organised threat actors.
Our testing is conducted in laboratory conditions against measurable, reproducible metrics. Findings are produced in structured reports designed to support regulatory conversations, procurement processes, and internal risk management alike.
Testing outcomes that serve your specific context
Regulatory compliance
Achieve and evidence compliance with CEN/TS 18099 and other applicable standards, with structured reporting that supports regulatory submissions and audit requirements.
Vendor differentiation
Independent IAD testing results give vendors credible, third-party evidence of their system's resilience, strengthening procurement applications and building buyer confidence beyond vendor-provided assurance.
Ongoing system assurance
For organisations with deployed systems, periodic IAD testing provides a current picture of resilience as the threat landscape evolves. Not a one-time certification, but a programme of assurance.
The question isn't whether to test. It's how thoroughly.
Whether you’re seeking a compliance baseline, preparing for procurement, or building an ongoing testing programme, Ingenium provides the rigour, independence, and reporting to give you a clear picture of where your systems stand.
