Presentation attack testing that reflects the real threat

Presentation attacks and the systems designed to stop them vary widely in their attack detection capabilities. Ingenium provides independent, scientifically grounded PAD evaluations which reflect today’s threats giving organisations and technology vendors the objective data they need to make confident decisions.

When the threat is right in front of you

A presentation attack occurs when an attacker attempts to deceive a biometric system at the point of capture, presenting an artefact  (an instrument), such as a photo or face mask, to the sensor in place of a genuine biometric characteristic. The objective is to be accepted as a legitimate user.

These attacks range from basic printed photographs to highly sophisticated three-dimensional masks and deepfake video sequences. The level of resource and expertise required to create these attacks varies significantly, and what constitutes a sophisticated attack today may be accessible and widely replicated tomorrow.

Biometric systems are expected to detect and reject these attacks through a PAD subsystem. How reliably they do so, across a full spectrum of attack types, on the devices and platforms your users actually use, is what a PAD evaluation measures.

Two metrics. One clear picture.

Ingenium’s PAD evaluation process is grounded in ISO/IEC 30107, the foundational, internationally recognised standard for biometric presentation attack detection. Every evaluation is structured around two core performance metrics.

Attack Presentation Classification Error Rate (APCER) measures how often a system incorrectly classifies a presentation attack as a genuine user. A high APCER indicates a security issue.

Bona Fide Presentation Classification Error Rate (BPCER) measures how often a system incorrectly classifies a genuine user as an attack. A high BPCER indicates a usability issue.

Both metrics are interdependent. Improving attack detection sensitivity can increase false rejections. The goal is to minimise both, and the balance between them is a meaningful indicator of a system’s real-world performance. Ingenium’s evaluations also captures Failure to Acquire (FTA) errors, which affect operational usability and are considered alongside APCER and BPCER in assessing overall performance. 

Testing against the full range of real-world attacker tactics

Ingenium evaluates systems against a structured range of attack species, characterised in alignment with the NIST Strength of Function for Authenticators for Biometrics (SOFA-B) framework. This classification provides a consistent basis for assessing how much resource, expertise, and prior knowledge is required to produce and execute each attack.

Presentation attack species can be developed using a range of biometric sourcing; from images and videos to sophisticated 3D scans. Ingenium ensures the biometric sourcing used to create these instruments are derived from a diverse population representing a broad range of ethnicities, ages, and genders. For each evaluation, demographic composition is aligned to the client’s user profile, ensuring results are representative of the system’s user base. 

An evaluation tier aligned with your threat model

Ingenium’s PAD evaluation framework is structured into five progressive test tiers. Each tier tests across two client-selected devices, which may include mobile platforms (iOS, Android), web browsers (Chrome, Firefox), or dedicated hardware such as webcams. 

Tiers are designed to align with your security requirements, risk profile, and any applicable regulatory or industry standards.

Standard compliance
Beyond standard compliance 

Level 1

An entry-level evaluation covering Level A and Level B attack species. Level 1 provides an initial assessment of baseline PAD performance, suitable for organisations beginning the process of understanding their system’s resilience.

Transactions

APCER: 1,000

BPCER: 100

Total: 1,100

Level 2

Building on Level 1, this tier expands the volume of Level B attack instruments. It does not include Level C attack species. Level 2 provides a more rigorous assessment of performance against medium-sophistication attacks.

Transactions

APCER: 1,500

BPCER: 100

Total: 1,600

Level 3

Level 3 introduces Level C attack species for the first time, including advanced techniques such as three-dimensional face masks and deepfake videos. This tier evaluates resilience across the full spectrum of low, medium, and high-sophistication attacks. It represents a significant step up in the depth and rigour of evaluation.

Transactions

APCER: 1,650

BPCER: 250

Total: 1,900

Level 4

Level 4 broadens both the range and volume of Level B and C attack species. The number of PAIs per species increases, and the cohort from which artefacts are derived is more diverse. This tier is designed for systems where a high standard of security assurance is required.

Transactions

APCER: 2,050

BPCER: 250

Total: 2,300

Level 5

Our most comprehensive evaluation. Level 5 incorporates the widest range of attack species and the largest volume of presentations across all sophistication levels. The bona fide subject cohort is expanded to maximise statistical confidence. This tier is designed for systems that require the highest available level of independent assurance.

Transactions

APCER: 2,150

BPCER: 350

Total: 2,500

Pass criteria that mean something

Each evaluation tier is assessed against defined APCER and BPCER thresholds. A system must meet all requirements to pass at the chosen level.

Evidence you can trust. Insight you can use.

Ingenium’s PAD evaluation delivers more than a pass or fail result. Every engagement delivers independent, evidence-based insights that help you understand how your PAD performs, where vulnerabilities exist, and what to do next. The results are suitable for internal decision-making, product development, procurement, regulatory engagement, and customer assurance.

A comprehensive evaluation report

detailing the test methodology, attack instruments used, results by presentation attack instrument (PAI) species, conclusions, and practical recommendations.

Performance metrics for APCER, BPCER, and FTA

for each device, configuration or deployment scenario

Species-level analysis

exactly which presentation attacks your PAD detects reliably, where performance falls short, and the associated security implications

Expert results review

including a presentation and Q&A session to help your technical and commercial teams interpret the findings and communicate them confidently

Independent evidence

to support procurement processes, regulatory submissions, customer due diligence, and other assurance activities.

For technology vendors, an independent PAD evaluation provides credible third-party evidence of performance. Published results demonstrate validated capability that customers, partners, and regulators can assess with confidence.

Ingenium can also incorporate performance and demographic bias evaluation into broader testing programmes. Where fairness and equitable performance across user populations are business or regulatory priorities, bias assessments can be included alongside PAD evaluation to provide a more complete view of system performance.

Not all PAD testing is created equal. Find out where yours stands.

Whether you are evaluating a PAD subsystem for the first time, preparing for regulatory scrutiny, or looking to build independent validation into your product offering, Ingenium provides  rigorous, impartial testing and reporting to give you a clear picture of where your solution stands.