Seventh Sense
Glossary

SenseCrypt
Technical library

Biometrics

Presentation attack detection (PAD)

Definition
Presentation attack detection (PAD) identifies fake biometric samples presented to a sensor.

ISO/IEC 30107-3:2023 is the standard that defines how PAD is tested and reported, which is why the phrase appears on datasheets far more often than the testing behind it does.

6 sectionsSeventh Sense / SenseCrypt
On this page

01

What counts as a presentation attack

A presentation attack is an attempt to deceive a biometric sensor by showing it something other than the genuine trait. The standard's vocabulary calls the fake object a presentation attack instrument, and it covers anything raised in front of the lens as a substitute for a living face.

The cost range is the interesting part of the taxonomy. At one end sits a public photograph and an office printer. At the other sits a mold, a laboratory and a subject who is either cooperating or unaware. A system that reliably defeats the first class and not the second is still worth deploying, provided the organization knows which class it bought.

  • A printed photograph of the target's face, flat or curved.
  • A photograph or video of the face replayed on a screen.
  • A paper cutout mask or a fitted three-dimensional mask.
  • A synthetic or deepfake face displayed to the camera.

02

What ISO/IEC 30107-3 specifies

ISO/IEC 30107-3:2023 governs the testing and reporting of presentation attack detection. It prescribes no detector design and it issues no certificate. What it fixes is the experiment: the artifact species in scope, the number of attempts, the conduct of the operator and the subject, and the form the result has to take.

That is precisely why a result from an accredited laboratory carries weight while a self-assessment does not. Two products can both claim conformance to the same standard and have been tested against very different artifact sets, so the scope of the test is the number worth reading.

Note the phrasing when a vendor cites this. A laboratory tests a specific product version against a specific artifact set at a specific time. Anything stated more broadly than that has left the evidence behind.

03

What Level 1 and Level 2 mean

Level 1 and Level 2 belong to the iBeta testing program. The standard itself defines no such tiers, which catches out readers who meet the standard number and the level quoted together in a single sentence.

What a tier fixes is the budget and sophistication ceiling for artifacts the laboratory may construct. A higher tier records a larger permitted spend per attack. It does not record a change in the specification, or a product measured against a different one.

Level 1 covers what a printer can produce

Printed photographs, stills and video shown on a display, and paper masks. Anyone holding a printer, a phone and a public photo of the target can attempt these today for almost nothing.

Level 2 covers artifacts made to order

Commissioned items, principally a three-dimensional mask built by the laboratory around one named test subject. At this tier the expense of mounting an attack starts working as a deterrent in itself.

04

PAD and liveness detection

Product teams say liveness; the standards say presentation attack detection. A datasheet that chooses the formal term is usually signalling a laboratory result rather than describing a technique, which makes it a useful tell when reading vendor material.

The liveness detection entry approaches the same subject from the operational side: how passive and active checks differ in daily use, and where deepfakes sit in relation to the sensor.

05

How SenseCrypt uses presentation attack detection

With the face acting as the credential, presentation attack detection is on the critical path of every authentication rather than sitting at its edge. In the two mobile-app methods the enrolled phone performs the capture, the liveness check and the comparison, and a capture that fails never becomes a face token.

The SenseCrypt liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition accuracy is a separate question with separate evidence: the algorithm is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021. The program was known as FRVT when that participation began and now runs as FRTE and FATE. We describe this as NIST-evaluated rather than NIST certified, because NIST evaluates algorithms and certifies nothing. The report card is public: https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html

The check gates the token

A failure terminates the ceremony on the handset itself. Since no token is minted, nothing arrives at the identity provider to be scored after the event or triaged in a review queue.

Testing covered iBeta Levels 1 and 2

Level 1 in the iBeta result covers printed photographs and replays on a display. Level 2 covers commissioned artifacts, including a three-dimensional mask built for the subject.

Only the genuine app can submit

Hardware integrity attestation, Play Integrity on Android and App Attest on iOS, is enforced deployment-wide with no per-client opt-out. That is the layer that addresses what a PAD report explicitly does not cover.

Review what an attacker could obtain

There is no face image and no biometric template on the server, so there is no gallery to poison, no template to steal, and the sealed enrollment record still requires access controls.

06

Frequently asked questions

What is presentation attack detection?

It is the detection of a fake biometric sample presented to a sensor, such as a printed photo, a screen replay or a mask. ISO/IEC 30107-3:2023 defines how the capability is tested and how results are reported.

How do PAD and liveness detection differ?

Only in register. Presentation attack detection is the vocabulary of the standard, and liveness detection is the vocabulary of product conversations. They point at the same capability.

What do Level 1 and Level 2 mean?

They are iBeta program tiers that cap what the laboratory may spend on an artifact, not levels defined by ISO/IEC 30107-3. At Level 1 the artifacts are cheap: a printed photograph, or a video replayed on a display. At Level 2 they are commissioned, a mask molded for the named test subject among them.

Has SenseCrypt been tested for PAD?

Yes. The SenseCrypt liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. That covers artifacts presented to the camera; injection attacks behind the camera are addressed separately through hardware integrity attestation on the app.

Is a PAD test the same as an accuracy evaluation?

No, and they are often confused. A PAD test measures resistance to fake samples. Recognition accuracy is measured separately, and for SenseCrypt that evidence comes from the NIST Face Recognition Technology Evaluation, in which the algorithm has been evaluated under Seventh Sense's own name since 2021.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.