Skip to content
Wednesday, August 26, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Digital
Digital

Presentation-Attack Detection Standards for Video KYC: ISO 30107 Against the Injection Threat

The face at the onboarding camera cleared liveness testing for years — until attackers stopped presenting to the lens and started injecting into the stream.

Naomi Bergman, · June 15, 2026 · 7 min read
ShareXFacebookLinkedInTelegramEmail
Infographic of layered capture defenses around a face silhouette

ISO/IEC 30107 is the standards family for presentation-attack detection — Part 3 defining how PAD mechanisms are evaluated against attack types from printed photos and masks to replayed video — and it anchors the liveness claims in most remote-onboarding RFPs; the threat that now drives procurement is the one the camera cannot see: injection attacks, where the fraudster bypasses the physical camera entirely and feeds synthetic or swapped video into the capture path, so the "live" face the system verifies never existed in front of any lens. PAD standards measured the front door; the attack moved to the plumbing.

3G Times publishes information, not legal advice. Onboarding-control design belongs with each institution's CDD program and fraud risk assessment.

What does the ISO 30107 evaluation measure?

Part 3 testing grades a biometric system's error rates against a defined attack instrument spectrum — photographs, screens, masks, cosmetics, replay — reporting attack-presentation classification error rates alongside the genuine-presentation rates. Accredited labs run the batteries, vendors publish certificates, and procurement teams quote the numbers. Three honest readings keep the quotes useful. The certificates measure the attack families the standard enumerates, weighted by the lab's corpus; they measure the biometric algorithm, not the whole capture pipeline; and they measure a point in time in an arms race that moves quarterly. A Part 3 certificate is evidence of rigor, not an expiration-proof guarantee — which is why mature programs re-evaluate on cadence and read the certificate's scope page before the headline number.

Why did injection change the threat model?

Classic PAD asks "is there a real person presenting to the sensor?" and answers with light, depth, motion, and texture analysis. Injection asks a different question — "is this signal coming from a sensor at all?" — because the attacker hooks the virtual camera, the device's media stack, or the app's capture interface and streams a fabricated feed. Deepfake tooling made the fabricated feeds convincing; emulators and instrumentation frameworks made the plumbing accessible. Against that, liveness analysis alone is arguing with a recording. The control families that answer injection sit around the biometric: device integrity attestation (has the environment been instrumented?), secure capture paths (hardened camera frameworks that resist stream substitution), session binding (the challenge-response tied to the device and moment, verified server-side), and signal forensics on the stream itself. The NIST-lineage testing programs extended their evaluations toward these digital-injection vectors as the industry's measurement caught up with the attack.

Attack classWhat it defeatsControl family
Printed photo / screen replayFace matching alonePassive/active liveness (30107 scope)
Masks, cosmetics, prosthetics2D texture liveness3D/depth-aware PAD
Deepfake on physical replayWeaker livenessChallenge-response dynamics
Virtual-camera injectionAll camera-facing PADDevice attestation, secure capture
Full session emulationSingle-point checksSession binding, behavioral signals

How should a fraud-control file read all this?

As a layered defense with evidence per layer. The biometric layer's 30107 certificates — scoped, dated, from accredited labs — evidence the face-to-sensor threat. The device layer's attestation and integrity telemetry evidence the capture-path threat, with the vendor's documentation naming the instrumentation frameworks it detects. The session layer's binding artifacts — challenge-response logs, timing, server-side verification — evidence that the verified event and the recorded event are the same event. And the operations layer ties it to the CDD file: the retained session, the PAD scores, the attestation flags, and the human-review queue for flagged cases. GLBA-lineage safeguards expectations read the whole file, and the fraud-risk assessment grades each layer's residual risk honestly — the file that claims a single control defeats all attack classes has already misgraded the top row.

The vendor-diligence corollary: onboarding-fraud platforms consolidate like every other critical dependency, and the injection-defense layer runs deepest in capture stacks shipping device-level engineering. The separating question is blunt — which layers do you own, which do you rent, where does responsibility sit — because the incident post-mortem will find that boundary whether or not anyone drew it.

How do deepfake economics change the review queue?

As synthesis got cheap, the human-review queue became a target: a reviewer approving borderline sessions is now adjudicating against machine-generated faces. The operational answers are the unglamorous ones — reviewer tooling that surfaces the forensic signals rather than the pretty face, time-boxed review with escalation paths, sampling audits of approvals, and metrics that treat "approved but later flagged" as a control signal rather than a reviewer's failing. The onboarding funnel's conversion pressure is real; the program that measures the trade it is making — approvals per reviewer, error rates against ground truth, attack-class mix over time — is the one that can defend its thresholds to a partner bank's diligence team with numbers instead of confidence.

What does this mean in practice?

The standards taught the industry to ask whether the person was real; the arms race now asks whether the camera was. Programs that kept their evidence layered — biometric certificates, attestation telemetry, session binding, reviewed queues — answer both questions from the same onboarding file.

Metrics close the loop: PAD false-rejection rates watch the conversion cost, flagged-session outcomes watch the fraud cost, and the ratio between them is the threshold-tuning dial the program actually manages. The attack-class mix chart is the one that earns escalations — when injection attempts triple quarter over quarter, the budget conversation writes itself from the telemetry.

How should vendors be re-evaluated over time?

On a fixed re-test cadence — annually at minimum — and on event triggers: a new injection technique reported in the wild, a material capture-stack change, or drift in the funnel's own fraud telemetry. The re-evaluation reads the new certificate's scope against the attack-class mix production data shows, the comparison the original RFP could only assume.

What does a partner bank's diligence ask first?

For the layered evidence with dates: certificates with scope pages, injection-coverage documentation, session-binding design, and the production attack-mix telemetry. The onboarding file that opens with the fraud-risk assessment — each layer graded, each residual acknowledged — answers the diligence in one meeting; the file that opens with a vendor badge answers it in several.

Frequently asked questions

Do 30107 certificates cover injection attacks?

The core enumerations grew from physical presentation attacks; digital-injection coverage appears in extended evaluations and complementary testing rather than the classic Part 3 batteries. The honest procurement question is which injection vectors the vendor's pipeline testing covers, evidenced how — beyond the certificate's letterhead.

Active challenges add friction and defeat simple static attacks; passive liveness preserves conversion and improves continuously. Mature programs pair them with device-layer controls rather than choosing a winner — the attack classes differ, and so do the controls.

Who validates the validators?

Accredited labs under recognized schemes, re-evaluation cadences, and the customer's own red-team exercises. The strongest signal in an RFP remains the vendor's willingness to be tested on the buyer's scenarios, not just the lab's corpus.

Frequently Asked Questions

Do 30107 certificates cover injection attacks?
The classic Part 3 batteries grew from physical presentation attacks; digital-injection coverage appears in extended evaluations and complementary testing. The procurement question is which injection vectors the vendor's pipeline testing covers, evidenced how.
Is active liveness better than passive?
Active challenges defeat simple static attacks at friction cost; passive preserves conversion and improves continuously. Mature programs pair both with device-layer controls — the attack classes differ, and so do the controls.
Who validates the validators?
Accredited labs under recognized schemes, re-evaluation cadences, and the customer's own red-team exercises. The strongest RFP signal remains the vendor's willingness to be tested on the buyer's scenarios, not just the lab's corpus.