Table of contents
Liveness detection is the check that confirms a real, present person is in front of the camera during identity verification, rather than a photograph, a screen, a video replay, a mask or a synthetic image injected into the capture stream. It is what makes a selfie-to-document face match worth anything, and it is tested against presentation attacks under ISO/IEC 30107-3.
The full product detail, active versus passive liveness, presentation and injection-attack detection, testing and accuracy, is on the liveness detection page. This entry covers the definition and the terms around it.
Active versus passive liveness
Active liveness asks the user to do something, turn the head, follow a moving dot, blink, so the system can confirm a live response. Passive liveness analyses a single capture for the signals of a real face, such as texture, depth cues and reflections, without instructions. Active checks are harder to defeat with a static image but add friction and have become an attack surface for pre-recorded video; passive checks are smoother and rely on the quality of the model. Many systems combine the two.
Presentation attacks versus injection attacks
A presentation attack shows the camera something that is not a live face: a printed photograph, a phone screen, a replayed video or a mask. An injection attack bypasses the camera and feeds a synthetic or replayed image, often a deepfake, directly into the capture stream through a virtual camera, an emulator or a modified app. Liveness detection addresses the first; detecting the second requires attesting the capture channel and the device, which is why the two are separate controls.
How liveness is tested
ISO/IEC 30107-3 defines how presentation-attack detection is evaluated, and independent laboratories such as iBeta test systems against it at defined levels of attack sophistication. A vendor claim should state the level, the laboratory and the date; a claim without those three is not a certification.
Liveness at Zyphe
Zyphe runs active liveness with anti-spoof checks against photographs, screens, videos and masks, a face match to the document portrait at a configurable threshold (75 percent by default), and injection-attack detection for imagery fed directly into the capture stream. The models run in-house and are updated monthly. Liveness is one stage of the KYC software flow, between document fraud detection and screening.
Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 18, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.