Biometric Spoofing Attack Types
Biometric spoofing, also called a presentation attack, is any attempt to fool a biometric system by presenting a fake or manipulated version of a person's trait rather than the genuine live sample. Understanding the range of attack types — from simple printed photos to AI-generated deepfakes — is essential context for why liveness detection has become a critical part of modern biometric security.
Presentation attacks vary widely in sophistication and cost, generally rising in effectiveness as they rise in complexity:
- Print attacks: a printed photograph or high-resolution image held up to a facial recognition camera
- Replay attacks: a photo or video displayed on a screen (phone or tablet) shown to the sensor instead of a physical print
- Fake fingerprints: molds or casts made from gelatin, silicone, or other materials that replicate ridge patterns lifted from a surface or a stolen print image
- Masks: 2D or 3D printed masks, sometimes highly detailed, designed to fool facial recognition cameras including some depth-sensing systems
- Voice cloning and synthesis: AI-generated speech that mimics a target's voice characteristics closely enough to fool voice recognition systems
- Deepfakes: AI-generated video or images that convincingly simulate a real person's face and expressions, increasingly used to attempt remote identity verification fraud
Presentation attacks target the point where a biometric sensor captures data from the physical world, meaning the attacker needs physical or virtual proximity to the capture device. Common scenarios include unlocking a stolen phone, attempting to bypass a facial recognition access gate, or defeating remote identity verification during account opening by presenting a fake or synthetic selfie video instead of a live person. This is distinct from attacks on stored templates or matching databases, which are data-security problems rather than presentation attacks.
Liveness detection exists specifically to counter presentation attacks by verifying the sample comes from a live, present person rather than a static or synthetic reproduction. Active liveness checks — asking a user to blink, turn their head, or speak a random phrase — can defeat basic print and replay attacks, while more advanced passive techniques analyzing depth, texture, and micro-movements are needed to catch sophisticated 3D masks and increasingly convincing deepfakes. As attack techniques evolve, particularly with generative AI improving deepfake and voice-cloning quality, liveness detection must correspondingly advance to keep pace.
Different modalities face different dominant attack types: facial recognition and voice recognition covered elsewhere on this site are increasingly targeted by AI-generated deepfakes and cloned voices, while fingerprint recognition remains more commonly targeted by physical mold-based fakes. Modalities that are harder to observe or replicate externally, such as vein pattern recognition, are inherently more resistant to presentation attacks simply because the underlying trait is not visible or capturable from a distance.
As synthetic media generation becomes cheaper and more accessible, the arms race between spoofing techniques and liveness detection is intensifying, pushing the industry toward multi-modal verification and continuous monitoring rather than relying on any single, static anti-spoofing check.