Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Presentation attack detection and liveness: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19785
Topic starter  

TL;DR: Presentation attack detection is being measured against spoofing techniques such as printed photos, video replays, and masks, with passive liveness balancing fraud resistance and user experience, according to Incode’s DHS S&T RIVR Track 3 results. For IAM and identity verification teams, the lesson is that liveness quality, testing methodology, and point-in-time validation matter as much as headline accuracy numbers.

NHIMG editorial — based on content published by Incode: Incode Among Top Performers in DHS S&T RIVR Track 3 Presentation Attack Detection

Questions worth separating out

Q: Should organisations use active or passive liveness detection?

A: Choose based on risk and user friction.

Q: Why do APCER and BPCER both matter in identity verification?

A: APCER shows how often spoofing is accepted, while BPCER shows how often real users are rejected.

Q: What are the signs that liveness controls are failing in production?

A: Watch for unusual approval spikes, device-specific anomalies, repeated recovery events, and a growing gap between lab performance and live conversion data.

Practitioner guidance

  • Separate passive and active liveness policy decisions Treat passive selfie checks and active challenge flows as different controls with different failure modes.
  • Measure both spoof acceptance and legitimate-user rejection Track APCER and BPCER together in production and testing, then review them by device type, geography, and onboarding step to find where performance degrades.
  • Re-test after model or policy changes Require new validation whenever models are retrained, thresholds change, or major fraud patterns emerge, because point-in-time certification does not guarantee current operational resilience.

What's in the full article

Incode's full article covers the operational detail this post intentionally leaves for the source:

  • Track-by-track RIVR results, including the separate passive and active liveness measurements
  • Detailed explanation of APCER reporting and why worst-case subtype performance matters
  • The relationship between RIVR testing, iBeta Level 3 conformance, and post-test model iteration
  • Context on how the evaluation maps to workforce identity, digital onboarding, and high-risk authentication flows

👉 Read Incode's analysis of DHS RIVR Track 3 presentation attack detection →

Presentation attack detection and liveness: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19376
 

Presentation attack detection is now an identity governance issue, not just a biometric accuracy issue. Once spoofing becomes reliable enough to imitate legitimate users, the control is no longer only about computer vision performance. It becomes a trust decision about who or what may enter the identity lifecycle in the first place. For IAM and fraud teams, that means PAD belongs in governance conversations alongside onboarding risk, authentication assurance, and account recovery design.

A question worth separating out:

Q: How do organisations validate biometric controls beyond a single test result?

A: Combine independent evaluations, internal red-team testing, and ongoing fraud telemetry. Then re-run validation after model updates, policy changes, or shifts in attacker behaviour. The goal is to prove that the control still works in production conditions, not just in a benchmark environment.

👉 Read our full editorial: Remote identity verification needs stronger liveness against spoofing



   
ReplyQuote
Share: