Liveness detection is the set of techniques a biometric system uses to decide whether the face, finger or voice it has just captured belongs to a living person physically present at the sensor, rather than to a photograph, a screen replay, a silicone mask or a synthetic video. A face-matching algorithm answers a narrower question: does this image resemble the stored reference. It has no opinion on whether the image came from a human being. Liveness detection supplies that missing judgement.

The gap matters because faces are public. A profile photograph or a few frames of a livestream give an attacker what is needed to hold something up to a camera. Any system granting access, confirming an age or awarding a trust badge on a face match is only as strong as its ability to reject artefacts. That question reaches advertising through two doors: age assurance, which decides whether a user sees personalised ads, and the identity checks applied to advertisers and account holders.

How a check runs

A liveness check sits between capture and matching. The camera produces frames, the subsystem scores them, and only frames clearing the threshold reach the matcher. Implementations split into two families.

Active liveness issues a challenge and measures the response. Prompts ask the subject to turn the head, follow a moving dot, blink on command or read a random string. Randomness is the point: a pre-recorded video cannot improvise. Google's selfie video enrolment is an active design: according to its Help Center, users complete guided head movements at capture, and later recordings must reproduce them to prove the video is live.

Passive liveness asks nothing of the subject and analyses the capture itself. Signals include the depth cue produced when a three-dimensional head moves against a flat background, the way real skin scatters light compared with paper or an LCD panel, moire patterns from a screen, sensor noise consistent with a physical camera, and pulse recoverable from colour variation. Passive checks are faster and reject fewer legitimate users, which is why high-volume consumer deployments favour them.

Neither family returns a binary internally. Both emit a score and the operator sets the threshold, which is why any performance claim is meaningless without the operating point attached.

The standards and the numbers they define

The vocabulary comes from ISO/IEC 30107, published by the International Organization for Standardization and the International Electrotechnical Commission. Part 1, issued in 2016, establishes the framework; Part 3, published in 2017, sets out testing and reporting.

The standard prefers presentation attack detection, or PAD, treating liveness detection as a subset. A liveness test asks whether the sample is alive; PAD asks whether an attack is under way. Those diverge in both directions: a coerced user is alive but under attack, while an altered fingerprint is live yet fraudulent.

Three metrics carry the weight. The attack presentation classification error rate, or APCER, is the share of attacks wrongly passed as genuine, reported for the most successful attack instrument rather than averaged. The bona fide presentation classification error rate, or BPCER, is the share of real users wrongly rejected. Because the two move against each other, results are quoted as one held at a fixed value of the other, written as BPCER20 for the rejection rate at a 5% APCER. Full-system tests report the imposter attack presentation accept rate, or IAPAR.

Conformance testing runs through a few accredited laboratories, of which iBeta Quality Assurance is most cited. Its published methodology defines levels the ISO text does not. Level 1 uses artefacts buildable in eight hours from readily available materials, typically photographs, paper masks and video replayed on a phone, presented as 150 attacks alternated with 50 genuine presentations. Level 2 allows 24 hours per attack instrument and admits silicone, latex and resin masks. The laboratory's comparison document sets the full-system pass mark at an IAPAR of 15% or lower for Level 1 and 7% or lower for Level 2. False rejection was initially uncapped, later limited to 20%, then to 15% for the first two levels and 10% for Level 3.

One detail is routinely lost in vendor marketing. iBeta states that its reports indicate conformance, not certification, and that the wording was corrected during a NIST/NVLAP audit in March 2019. A press release announcing a "certification" is describing a contracted laboratory finding.

Origin and evolution

The problem was posed for fingerprints first. Academic work on spoof resistance dates to the early 2000s, and the field gained a shared benchmark when the Fingerprint Liveness Detection competition, LivDet, ran its first edition in 2009. Face liveness followed as smartphone cameras made remote onboarding viable, with a Google patent family filed in 2011 covering blink, gaze and facial proportion.

Standardisation in 2016 and 2017 replaced a scattered literature of "anti-spoofing" and "vitality detection" with one vocabulary. Certification schemes layered on top: the FIDO Alliance opened its Face Verification Certification in 2024, requiring at least 10,000 test verifications, measuring spoof resistance through IAPAR and adding accuracy testing across skin tone, age and gender. CEN/TS 18099, published in 2025, covers injection attack detection, and an ISO/IEC work item numbered 25456 is under development.

Why the advertising industry ended up here

Age assurance is the connection. Regulators now require platforms to establish whether a user is a minor, and the answer determines what advertising that user may be shown. Google began machine learning age estimation for United States ad protections on July 30, 2025, disabling ad personalisation for suspected minors, and added verification prompts in Search from August 2025 accepting a government identity document or a facial selfie when the model produced a false positive. X deployed comparable assurance in 2025, Bluesky adopted Epic Games' Kids Web Services, and Reddit locked teen chat and ad personalisation across the European Union from June 24, 2026. A selfie check with liveness underneath moves an account between advertising eligibility classes.

Account integrity is the second door. Google has suspended advertiser accounts at scale over deepfake impersonation of public figures, the threat class a liveness-checked face match is meant to blunt. Meta introduced a free Facebook verification badge on July 24, 2026 built on a recorded video selfie matched against profile photographs, restricted to accounts aged 18 and over and unavailable to Pages. Google shipped selfie video sign-in a day earlier, its documentation naming bot detection among the purposes.

Limitations and disputes

The sharpest criticism is that liveness detection defends the wrong end of the pipe. A presentation attack holds an artefact up to a lens; an injection attack bypasses the lens entirely, feeding synthetic frames into the application through a virtual camera driver, an emulator or a manipulated API call. The liveness model receives what appears to be a camera stream and has no native way to know otherwise. Entrust's 2026 Identity Fraud Report, drawing on more than one billion verifications, reported injection attacks up 40% year on year and deepfakes in one in five biometric fraud attempts. Those are supplier figures from a company selling detection, and no independent audited baseline exists.

Laboratory conformance travels poorly. A Level 1 or Level 2 result describes performance against a fixed catalogue of artefacts under contracted conditions, with cooperative subjects supplying high-quality reference images, and says nothing about generative models released after the test date.

Accuracy varies by demographic. The UK Parliamentary Office of Science and Technology, briefing on facial age estimation, notes that no method establishes an exact age, that services compensate by setting a challenge age above the legal threshold, commonly 25 for an 18 check, and that accuracy depends on image quality and on age, sex and ethnicity. Ofcom has acknowledged that estimation performs less well at younger ages, a limit set out in the UK consultation on children's online experience.

The legal dispute is unresolved. Spain's data protection authority fined Yoti 950,000 euros in March 2026 across three findings, the largest 500,000 euros for processing biometric special category data without a valid Article 9 basis. Yoti argued its facial scan authenticates rather than identifies; the regulator held that a retained template matched one to one falls inside Article 9. The same authority rejected a structurally identical argument from an iris-scanning operator in February 2026, applying a least-intrusive-alternative test. The UK Information Commissioner's Office has accepted that facial age estimation used only for categorisation is not Article 9 processing. Two authorities, one regulation, opposite readings.

Adjacent terms

Presentation attack detection is the standardised superset; liveness detection is one method within it. Facial age estimation predicts an age range and identifies nobody, which is why regulators treat it differently from facial recognition, which converts a face to a template and matches it against a stored reference. Brazil's data protection authority drew that distinction in a draft age verification guide in May 2026. Injection attack detection validates the capture channel rather than the image. And invalid traffic detection, the bot filtering an Adalytics investigation found missing declared bots, shares the humanness question but uses network signals rather than biometrics.

Recent developments

Yoti said today that it will remove its Digital ID app from Spanish app stores from September 10, 2026 rather than offer a non-biometric route into it, while appealing the AEPD resolution before the Audiencia Nacional. Its position is that no PIN, password or passcode matches a face scan at the moments its app requires one. Its published list of alternatives omits passkeys. The public-sector substitute is incomplete: the European Commission recommended on April 29, 2026 that member states deploy a privacy-preserving age verification application by December 31, 2026, an instrument carrying no penalty for missing the date.

Timeline

  • 2009 - The first Fingerprint Liveness Detection competition, LivDet, establishes a shared benchmark for spoof resistance research
  • July 2011 - A European patent application filed by Google covers combined facial liveness indicators including blink rate, gaze and eye distance
  • 2016 - ISO/IEC 30107-1 publishes the presentation attack detection framework and vocabulary
  • 2017 - ISO/IEC 30107-2 and 30107-3 publish data formats and the testing and reporting methodology defining APCER, BPCER and IAPAR
  • March 2019 - A NIST/NVLAP audit prompts iBeta to describe its PAD results as conformance rather than certification
  • May 2024 - The FIDO Alliance launches Face Verification Certification, requiring at least 10,000 test verifications and demographic accuracy testing
  • February 11, 2025 - The European Data Protection Board adopts Statement 1/2025 setting ten principles for GDPR-compliant age assurance
  • July 30, 2025 - Google begins machine learning age estimation to restrict ad personalisation for suspected minors in the United States
  • 2025 - CEN/TS 18099 publishes injection attack detection requirements; ISO/IEC 25456 enters development
  • March 10, 2026 - Spain's AEPD publishes its resolution fining Yoti 950,000 euros across three GDPR breaches
  • June 24, 2026 - Reddit begins European Union age checks, restricting teen accounts and ad personalisation
  • July 23, 2026 - Google introduces selfie video sign-in for consumer accounts, citing liveness movement prompts and bot detection
  • July 24, 2026 - Meta launches Facebook Verified, a free badge built on a recorded video selfie
  • September 10, 2026 - Yoti's Digital ID app is due to leave Spanish app stores

Summary

Who: Standards bodies ISO and IEC, which define presentation attack detection in the 30107 series; accredited laboratories such as iBeta; the FIDO Alliance, which certifies face verification; identity vendors including Yoti, Persona, Au10tix and Entrust; platforms deploying face checks, among them Google, Meta, X, Bluesky and Reddit; and data protection authorities in Spain, the UK and Brazil.

What: A set of techniques determining whether a captured biometric sample originates from a living person present at the sensor rather than from an artefact or a synthetic stream. Implementations divide into active designs that issue challenges and passive designs that analyse capture signals, and are measured through APCER, BPCER and IAPAR at declared operating points.

When: Rooted in fingerprint anti-spoofing research of the early 2000s, benchmarked from the 2009 LivDet competition, standardised by ISO/IEC 30107 in 2016 and 2017, extended by FIDO face verification certification in 2024 and by CEN/TS 18099 injection attack requirements in 2025.

Where: Inside remote identity verification, account recovery and age assurance flows on consumer platforms, and in the compliance layers built for the UK Online Safety Act, the EU Digital Services Act and equivalent regimes.

Why: Face images are trivially obtainable, so a match alone proves nothing about presence. For advertising specifically, the output of these checks determines whether an account is treated as adult and therefore eligible for personalised targeting, and whether an advertiser or creator account carries a verified identity.