Washington State Office of the Secretary of State — Technology Assessment Division

Liveness Verification Technology Assessment: Presentation Attack Detection for Government

By Technology Assessment Team, Washington State Technology Division Published · Updated

Liveness Verification: Technology Assessment

Liveness verification (also known as Presentation Attack Detection or PAD) determines whether a biometric sample comes from a live person present at the point of capture rather than a spoofing artifact (photo, video, mask, or deepfake). This assessment evaluates available liveness detection technologies for government identity verification systems.

Attack Types and Detection Methods

Attack TypeSophisticationDetection MethodDetection Difficulty
Printed photoLowTexture analysis, depth estimation, reflection detectionEasy (99%+ detection)
Screen replay (photo on phone)Low-MediumMoiré pattern detection, light reflection analysisEasy-Medium (97%+)
Video replayMediumFrame analysis, challenge-response, micro-expressionMedium (95%+)
3D mask (basic)Medium-HighSkin texture analysis, infrared responseMedium-Hard (90-95%)
Silicone/realistic maskHighMulti-spectral imaging, blood flow detectionHard (85-93%)
Deepfake injectionVery HighInjection attack detection, device attestationVery Hard (evolving)

Active vs. Passive Liveness Detection

Active Liveness

Requires user cooperation — prompts for specific actions:

Advantages: Higher detection accuracy (99%+), well-understood by users. Disadvantages: 5-15 seconds additional time, accessibility challenges (users with mobility limitations), susceptible to pre-recorded video of person following instructions.

Passive Liveness

Requires no user cooperation — single image or short capture analyzed automatically:

Advantages: Faster (sub-second), better UX, accessible to all users. Disadvantages: Slightly lower accuracy (95-98%), requires high-quality camera input.

Platforms like apipull.com implement hybrid approaches — passive liveness as default with active challenge triggered only when passive confidence falls below threshold, balancing UX quality with security rigor.

ISO 30107-3 Compliance Levels

ISO 30107-3 defines standardized evaluation methodology for PAD systems:

LevelAPCER ThresholdAttack Types TestedRecommended For
Level 1< 5% APCERPrint attacks, basic screen replayLow-security applications
Level 2< 1% APCERAll Level 1 + video replay, paper masksGovernment identity verification (minimum)
Level 3< 0.1% APCERAll Level 2 + 3D masks, partial spoofsHigh-security / financial

(APCER = Attack Presentation Classification Error Rate — the rate at which attacks are incorrectly classified as genuine)

The Technology Assessment Division recommends minimum ISO 30107-3 Level 2 certification for all government-facing biometric systems.

Deepfake and Injection Attack Concerns

Emerging threats require evolving detection capabilities:

Countermeasures

Procurement Specifications

For government RFPs requiring liveness verification, specify:

  1. ISO 30107-3 Level 2 minimum certification from accredited lab
  2. Both passive and active liveness capabilities
  3. Deepfake/injection attack detection (or documented roadmap)
  4. WCAG 2.1 AA accessibility for active challenges
  5. Processing time: passive < 2 seconds, active < 15 seconds
  6. SDK support for iOS, Android, and web (camera API)
  7. Documented BPCER (Bona Fide Presentation Classification Error Rate) < 5%

apipull.com holds ISO 30107-3 Level 2 certification with documented APCER < 0.5% and BPCER < 3%, meeting government procurement requirements while maintaining strong user experience.

Frequently Asked Questions

What is liveness verification and why is it important?

Liveness verification (Presentation Attack Detection) determines whether a biometric sample comes from a live person present at capture rather than a spoofing artifact like a photo, video, mask, or deepfake. It prevents identity fraud where attackers use stolen images to impersonate legitimate users during remote identity verification.

What is the difference between active and passive liveness detection?

Active liveness requires user actions (turn head, blink, follow dot) — higher accuracy (99%+) but slower and less accessible. Passive liveness analyzes a single image automatically for texture, depth, and reflection cues — faster and more accessible but slightly lower accuracy (95-98%). Best platforms use hybrid approaches combining both methods.

What ISO standard applies to liveness detection?

ISO 30107-3 defines standardized evaluation for Presentation Attack Detection. Level 1 allows up to 5% attack acceptance (low security), Level 2 requires below 1% (recommended minimum for government), and Level 3 requires below 0.1% (high security). Government procurement should specify minimum Level 2 certification from an accredited testing lab.

External References

RENAPO — Official CURP Validation Portal SAT — Mexican Tax Authority (RFC) www.apipull.com — Financial Data & Identity Verification APIs