← Back to blog March 20, 2026

Liveness Detection: How It Works and Why It Matters

What is liveness detection?

Liveness detection determines whether a face presented to a camera belongs to a real person physically present, rather than a printed photo, a screen replay, a mask or a deepfake. Active liveness asks the user to perform an action; passive liveness analyses a single capture. ISO/IEC 30107-3 is the presentation attack detection standard.

Liveness detection is the technology that determines whether a biometric sample — usually a face — comes from a real, physically present person or from an attack. It's the difference between a verified identity and a fraudster holding up a printed photo, playing a video on a screen, or using an AI-generated deepfake to impersonate someone else.

As identity verification moves online, liveness detection has become the critical layer that prevents the most common and most dangerous forms of biometric fraud. Without it, face matching alone is trivially easy to defeat.

The Problem Liveness Detection Solves

Face matching works by comparing a selfie against a photo on a government ID. The underlying models are excellent — modern face comparison algorithms achieve accuracy rates above 99%. But accuracy only matters if the selfie is genuine.

Without liveness detection, an attacker can bypass face matching by presenting:

These are called presentation attacks — the attacker presents a fake biometric to the sensor. Liveness detection exists specifically to catch them.

How Liveness Detection Works

There are two fundamental approaches: active and passive. Most modern systems use passive liveness or a hybrid of both.

Active liveness

Active liveness asks the user to perform an action: blink, turn their head, smile, or follow a moving dot with their eyes. The system checks whether the response matches what a live person would produce.

Advantages:

Disadvantages:

Passive liveness

Passive liveness analyzes the biometric sample without asking the user to do anything extra. The user takes a selfie — or records a short video — and the system determines liveness from the data itself.

Passive liveness models analyze signals that are invisible to humans but detectable by machine learning:

Advantages:

Disadvantages:

Video-based liveness

A third approach captures a short video clip (typically 2-4 seconds) rather than a single frame. This gives the system temporal information — it can analyze micro-movements, blinking patterns, blood flow-related color changes, and consistency across frames.

Video-based liveness is particularly effective against deepfakes because generating temporally consistent fake video is significantly harder than generating a single convincing frame. Artifacts that are invisible in a still image — flickering at face boundaries, inconsistent lighting across frames, unnatural micro-expressions — become detectable in video.

This is the approach that platforms like Verifa use: a short video capture that feels as simple as taking a selfie but provides the temporal depth needed to catch sophisticated attacks.

The Deepfake Problem

Deepfakes have fundamentally changed the threat landscape for identity verification. In 2024 and 2025, the tooling became accessible enough that non-technical attackers can run real-time face swaps on consumer hardware.

The attack works like this:

  1. The attacker obtains photos of the victim (social media is usually enough)
  2. They train or load a face-swap model using those photos
  3. During the verification session, the model maps the victim's face onto the attacker's in real time
  4. The modified video feed is injected into the camera stream using virtual camera software

The result is a live video feed that shows the victim's face, responds to prompts in real time, and passes basic face matching because the face geometry matches the ID photo.

Stopping deepfakes requires multiple detection layers:

No single technique catches every deepfake. The defense is layered: injection detection stops the simplest attacks, temporal analysis catches mid-tier tools, and artifact detection handles the most sophisticated attempts.

Liveness Detection Standards

The industry standard for evaluating liveness detection is ISO 30107-3, which defines testing methodology for presentation attack detection (PAD). Testing under this standard uses a metric called the Attack Presentation Classification Error Rate (APCER) — the percentage of attacks that are incorrectly classified as genuine.

ISO 30107-3 testing is performed by accredited labs (like iBeta) using standardized attack instruments: printed photos at various resolutions, screen replays on different devices, 2D and 3D masks, and video replays.

Two levels of conformance are commonly referenced:

When evaluating liveness detection vendors, ask for their ISO 30107-3 test results and pay attention to the APCER across different attack types. A system that blocks 100% of printed photos but fails against screen replays has a serious gap.

Where Liveness Fits in the Verification Flow

Liveness detection doesn't operate in isolation. It's one step in a verification pipeline that typically looks like this:

  1. Document capture — The user photographs their government ID
  2. Document verification — AI extracts data, checks for tampering, and validates the document
  3. Selfie/video capture — The user takes a selfie or records a short video
  4. Liveness detection — The system confirms the capture is from a live person
  5. Face matching — The live selfie is compared against the photo on the document
  6. Risk scoring — All signals (document, biometric, device, behavioral) are aggregated into a risk assessment

Liveness runs before face matching for a reason: there's no point comparing a face if it isn't real. Running liveness first also saves compute — you avoid running expensive face comparison on fraudulent inputs.

What to Look for in a Liveness Solution

If you're building identity verification into your product, here's what matters when evaluating liveness detection:

The Arms Race Continues

Liveness detection is not a solved problem. It's an ongoing arms race between attack tools and detection systems. Deepfake generators get better every few months. New attack vectors emerge — audio deepfakes for voice biometrics, fully synthetic identities that never existed, adversarial patches that fool computer vision models.

The companies that stay ahead are the ones that continuously retrain their models against new attack types, maintain diverse training datasets, and layer multiple detection signals rather than relying on any single technique.

For product teams implementing identity verification, the takeaway is straightforward: liveness detection is not optional, and not all liveness detection is equal. A checkbox that says "liveness: yes" tells you nothing. Ask about the attack types tested, the standards met, and how the system handles the threats that didn't exist when it was built.

Ready to get started?

Start verifying identities in minutes with Verifa's free plan. No credit card required.

Create Free Account