Anti-Spoofing

Techniques used to detect and reject fraudulent biometric samples — printed photos, silicone masks, replay videos — before they can deceive a biometric authentication system.

Direct answer: Anti-spoofing is the set of controls that helps a biometric system distinguish a live subject from a fraudulent sample presented to the sensor. It covers attacks such as printed photos, replayed video, masks, and synthetic or manipulated media, while testing must reflect the sensor, workflow, and threat model in use.

What Anti-Spoofing Covers

A presentation attack is made at the point of capture: for example, a printed photo, a screen replay, a silicone mask, or another artifact is shown to a camera. An injection attack is different: altered or synthetic data is inserted into the software or transport path after capture. A product may address one, both, or neither, so buyers should ask which attack surface was evaluated.

Passive liveness evaluates signals without asking the user to perform a specific gesture. Active liveness asks for an action, such as turning the head or following an instruction. Both approaches can be useful, and both can fail under changes in lighting, camera quality, accessibility needs, fraud pressure, or unfamiliar attack patterns. Liveness detection and presentation attack detection are related, but neither label alone proves suitability for a buyer’s environment.

How Buyers Should Evaluate It

Ask which biometric modality, device types, attack instruments, and operating conditions were tested. Look for a test report or standard-based evaluation rather than an unsupported certification claim, and separate presentation-attack results from injection-attack coverage. Review user friction, fallback paths, latency, privacy, accessibility, monitoring, and how the provider handles new attack material. ISO/IEC 30107-3 describes testing and reporting for biometric presentation attack detection; NIST’s FATE PAD work provides a useful independent evaluation reference.

Limitations and Counter-Read

Published test results are evidence, not a guarantee of performance in every deployment. Attack tools, capture devices, user populations, and thresholds change the result. A strong review should therefore compare the vendor’s evidence with the threat model and run an independent pilot where the decision is consequential. See related terms: PAD, liveness detection, and PAI.

Last reviewed: 2026-05-11

Sources

Category: biometrics. Part of the Identity Technologist Glossary — 158+ practitioner-grade definitions covering identity verification, KYC/AML, biometrics, fraud prevention, and compliance. See all terms at https://identitytechnologist.com/glossary.