Understanding presentation attacks – and whether your system can stop them
A presentation attack is a direct attempt to fool a biometric system at its point of capture. Understanding how these attacks work, how they are classified, and what it actually takes to detect them is the starting point for any meaningful assessment of a biometric system’s security.
The threat at the sensor
A presentation attack occurs when an attacker deliberately presents a fabricated artefact to a biometric sensor, with the aim of being accepted as a legitimate user.
It’s different in nature to Injection attacks
In facial biometric systems, this typically involves presenting something in place of a live face. That might be a printed photograph held up to a camera, a video played from a screen, or a sophisticated three-dimensional mask designed to pass as a real person. The attack is physical and direct.
What separates a capable PAD system from a basic one is its ability to distinguish between a genuine biometric characteristic and an artefact, consistently, across a wide range of attack types and conditions.
This distinction is what PAD testing measures.
Not all attacks are the same
Presentation attacks are not uniform in their sophistication or the resources required to execute them. Ingenium characterises attack species in alignment with the NIST Strength of Function for Authenticators for Biometrics (SOFA-B) framework, which provides a consistent basis for classifying how much expertise, resource, and prior knowledge a given attack demands. Attacks are grouped into three levels of sophistication:
Level A
Level A attacks require minimal expertise and materials that are widely available. A printed photograph or an image displayed on a tablet screen. They can be produced quickly, replicated at scale, and represent the baseline threat that any PAD system must address.
Level B
Level B attacks involve more refined techniques and a degree of specialist knowledge. Higher-quality image capture, materials with more realistic properties, or modifications designed to defeat common detection approaches.
Level C
Level C attacks are the most sophisticated. They require significant expertise and access to specialist tooling, including three-dimensional face masks and deepfake video sequences. These attacks represent a smaller share of the overall threat volume today, but that is changing.
One of the most important things to understand about these classifications is that they are not fixed. Techniques that sit at Level C today may be reclassified as a Level A attack within a few years as tooling becomes more accessible and knowledge widely known. PAD evaluations that only consider yesterday’s threat model provide temporary assurance.
Two metrics. One clear picture
The effectiveness of a PAD subsystem is measured using two interdependent metrics, defined in ISO/IEC 30107, the internationally recognised standard for biometric presentation attack detection.
Attack Presentation Classification Error Rate (APCER)
measures how often the system incorrectly classifies a presentation attack as a genuine user. A high APCER means attacks are getting through.
Bona Fide Presentation Classification Error Rate (BPCER)
measures how often the system incorrectly classifies a genuine user as an attack. A high BPCER means legitimate users are being rejected.
Neither metric can be read in isolation. A system tuned to catch every attack will typically reject more genuine users. The balance between the two is a meaningful indicator of how a PAD system will behave under real world conditions.
Testing what the vendor hasn't
A PAD system may perform well during internal development and testing. That is not the same as performing well under adversarial conditions set by an independent evaluator.
Vendor testing plays an important role in product development, validation, and quality assurance. Independent evaluation provides complementary assurance by applying an impartial methodology, independently selected presentation attack instruments (PAIs), and objective performance measurement. This enables organisations to understand how a PAD subsystem performs beyond its internal test environment.
Ingenium evaluates systems under laboratory and real-world conditions, across a structured range of attack species, on the devices, platforms and configurations representative of the intended deployment environment.. The result is objective insight into how a system actually performs, rather than how it has been optimised to perform.
That distinction matters whether you are a technology vendor preparing for procurement, or an organisation deciding how much confidence to place in a system you are about to deploy.
For many organisations, understanding their PAD performance is only part of the picture. Ingenium also provides performance and bias-focused evaluations to assess how consistently a system performs across different demographic groups, a factor that carries commercial, regulatory, and reputational implications.
What's at stake when attack detection fails
When a PAD subsystem fails to detect presentation attacks, the biometric check can become a point of exposure rather than protection. The impact depends on the use case, but the risks are consistent.
Fraudulent access and account takeover.
If an attacker can defeat PAD with a printed photograph or a deepfake video, the biometric system may grant access to an unauthorised user
Identity fraud at onboarding.
Remote identity verification is a common target for presentation attacks. A PAD failure during onboarding can allow a fraudulent identity to enter the system, creating downstream risks that may be difficult to detect, investigate, and reverse
Regulatory and compliance exposure.
Standards and regulatory frameworks increasingly require demonstrable PAD capability. Understanding what your system can detect, under which conditions, and against which attack types is essential to any defensible assurance or compliance position.
Reputational risk.
Trust in biometric identity systems depends on consistent, reliable performance. A high-profile PAD failure can undermine user confidence, customer trust, and market credibility.
Understanding your PAD performance under rigorous, independent evaluation is therefore more than a technical security measure. It is a commercial, regulatory and organisational necessity.
Know what your system can actually detect. Then decide if that's enough
Whether you are assessing a system before deployment, preparing for regulatory review, or looking to build independent validation into your product, Ingenium provides rigorous, impartial PAD evaluations and reporting to give you a clear picture of where you stand.
