Seventh Sense
Glossary

SenseCrypt
Technical library

Biometrics

Liveness detection

Definition
Liveness detection checks whether the camera sees a live person or an artifact such as a photo, replay or mask.

Face recognition alone cannot make that judgment, which is why a face login without liveness is not a security control.

6 sectionsSeventh Sense / SenseCrypt
On this page

01

Why recognition needs a second check

Liveness detection establishes that a living person is present at the lens. Face recognition answers a narrower question: are these two faces the same face. A high-resolution photograph of the right person answers that question perfectly, because it is the right person's face, and the matcher was never asked whether it was attached to anybody.

That gap is what makes the attack cheap. A photograph lifted from a public profile and angled toward a laptop camera defeats recognition on its own, with no technical skill and no budget behind it. Telling a person apart from a reproduction of one is the job liveness exists to do.

In an identity system the placement matters as much as the technique. A liveness check that runs after a match, or as an advisory risk score somebody reviews later, is a report. A liveness check that gates the credential is a control.

02

Passive and active checks

Every technique hunts for the same evidence: signs that whatever the lens is pointed at behaves like living tissue rather than like paper, glass or silicone. What separates the two families is whether the person is asked to participate, and that difference is felt by the user far more than by the attacker.

On user experience the passive family has largely won, because a check that costs the user nothing gets deployed across every flow rather than reserved for high-risk ones. Active methods keep a place where a slower, more deliberate ceremony is acceptable, or where the flow needs a visible signal that something was verified.

Passive liveness reads the capture itself

Analysis runs over frames the camera is collecting anyway, reading surface texture, reflection and the particular way light scatters in skin. Sign-in time does not increase and the user is asked for nothing.

Active liveness requests a movement

A blink, a smile or a turn of the head shows that something is responding as the check runs. The cost is a few seconds of the user's time, and the return is that a plain video replay becomes harder to use.

The test result is the claim worth checking

Asserting liveness costs a vendor nothing. What actually separates implementations is an independent laboratory result measured against an enumerated artifact set, rather than the technique printed on a datasheet.

03

Liveness detection and presentation attack detection

One goal, two vocabularies. The standards call it presentation attack detection and abbreviate that to PAD. Everyone in a product meeting says liveness.

The formal vocabulary is worth knowing when reading a datasheet. ISO/IEC 30107-3:2023 fixes the way presentation attack detection has to be tested and the way results are written down: which artifact types are in scope, how attempts are counted, and what form the numbers take. Citing it points at a test methodology, and that is a materially firmer claim than naming a technique.

04

Where deepfakes actually fit

Deepfakes have changed the conversation about face verification, and the change is often described imprecisely. A synthetic face shown on a screen in front of a camera is a presentation attack, and it is within the scope of a laboratory-tested liveness system. A synthetic face injected directly into the video pipeline, through a virtual camera or a compromised application, never reaches the lens at all and is a different class of problem.

The distinction is not academic. In February 2024 an Arup finance employee authorized about 25 million US dollars after a video call with deepfaked colleagues. No biometric system was defeated in that incident, because none was in the path: the attack targeted a human approval workflow directly.

The practical response is layered. Liveness handles what is presented to the camera. Application and device integrity handle what is allowed to produce a capture in the first place. Approval design handles the decisions that a convincing video can still influence.

05

How SenseCrypt uses liveness

Because the face is the credential here, liveness cannot be an optional risk signal attached to a login. It executes inside the same ceremony as the comparison, and a capture that fails it produces neither a session nor a token.

The SenseCrypt liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Capture runs on an ordinary 2D RGB camera, so the method works on whatever handset a person already carries instead of on a single hardware tier. Recognition accuracy is a separate question with separate evidence: the algorithm is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021, and the public report card is at https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html

The check runs at the point of capture

In the two mobile-app methods the app performs both the liveness check and the comparison on the enrolled phone, and nothing is transmitted at all unless the ceremony succeeds.

Tested at both artifact tiers

An accredited laboratory ran it against cheap artifacts, printed photographs and replays on a display, then against purpose-built ones including a 3D mask fitted to the test subject.

No special sensor required

A standard 2D RGB camera is sufficient and no depth sensor is involved, so the handset a person happens to own does not decide whether they can enroll.

Only a genuine app can produce a token

Hardware integrity attestation, Play Integrity on Android and App Attest on iOS, is a deployment-wide floor with no per-client opt-out, which raises the cost of feeding frames from something that is not the real app.

06

Frequently asked questions

What is liveness detection?

It is the test that establishes a living person at the lens, telling a real face apart from a printed photo, a screen replay or a mask. Liveness answers presence; face recognition answers similarity.

Does liveness detection stop a photo attack?

Yes. Rejecting printed photographs and images replayed on a screen is the baseline case, and it is exactly what Level 1 testing in ISO/IEC 30107-3 measures.

Are liveness detection and presentation attack detection the same thing?

They target the same outcome. ISO/IEC 30107-3:2023 uses presentation attack detection as the formal term, while liveness detection is the name everyone actually says. A datasheet reaching for the formal term usually has laboratory evidence behind it.

Does liveness detection stop deepfakes?

It stops a deepfake presented to the camera on a screen, which is a presentation attack. It does not by itself address a synthetic stream injected into the pipeline behind the camera; that is handled by application and device integrity controls, which SenseCrypt enforces as a deployment-wide floor.

Has the SenseCrypt liveness detection been independently tested?

Yes. The liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. That covers the cheap end, printed photographs and replays on a display, and the commissioned end, including a mask fitted to the test subject.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.