Presentation Attack Detection on Identity Documents: Why Research Is Becoming a Business Imperative
In recent years, the gap between how identity fraud attacks and how models trained on historical data detect it has become a business variable, not just a technical one. Banks, fintechs, travel platforms, and digital identity providers feel it first on the balance sheet: fraud that goes undetected translates into direct loss, added friction in the onboarding of legitimate customers translates into abandonment, and regulatory exposure translates into penalties.
Choosing an identity partner today means asking about more than a system’s current detection rate. It means asking what work is happening behind the scenes to keep detecting what doesn’t exist yet. Facephi takes part in leading international competitions precisely to answer that question with evidence, not promises.
Digital fraud is moving faster than technology
Digital identity fraud is no longer limited to visibly altered documents or low-quality counterfeit cards. Attackers increasingly combine forged identity documents, high-quality reproductions, manipulated images, replay attacks, and synthetic content to impersonate legitimate users during remote onboarding.
This type of manipulation of the document presented to the camera is known as Presentation Attack Detection (PAD). A second front is just as active, targeting the channel rather than the document: Injection Attack Detection (IAD), which introduces data or video directly into the capture stream without going through a real camera. While PAD addresses what is presented to the camera, IAD addresses whether that camera is real.
The challenge is that fraud evolves continuously, while detection systems are often trained on historical data. A model that performs well on the countries, document types, cameras, and attack methods represented in its training set may perform substantially worse when confronted with an unfamiliar identity document or a new form of manipulation.
Presentation Attack Detection (PAD) for identity documents must therefore be evaluated not only against known attacks, but also against unseen countries, unseen documents, real bona fide images, and changing capture conditions. The objective is not simply to recognize yesterday’s fraud. It is to build systems capable of responding to tomorrow’s attacks.
Research investment is a business strategy
For an identity technology provider, investment in applied research is not an academic luxury. It is a way to anticipate threats before they reach production and to ensure that the technology offered to customers continues to evolve with the risk environment.
Research in PAD addresses questions that directly affect business performance: Can a system detect attacks that were not present in its training data? Can it generalize across countries and document designs? Does it remain reliable when images are captured with different smartphones, lighting conditions, or compression levels? Can it maintain adequate accuracy without introducing unacceptable friction into the onboarding process?
These questions are especially important because there is no universal PAD system capable of detecting every possible attack. Performance depends on the available data, the number and diversity of bona fide images, the attack types represented, and the countries used during training.
Privacy protection makes the problem more difficult. Organizations cannot freely collect and distribute large databases of genuine identity documents. As a result, bona fide images are scarce, while many publicly available datasets do not fully follow ICAO-9303-related document requirements[1] or provide sufficient geographic and document diversity. Academic researchers face an even greater challenge because open-access databases are limited and often lack the scale needed to train and evaluate robust systems.
For companies, this means that research capability is part of product resilience. A partner that actively investigates these limitations is better positioned to identify weaknesses, improve generalization, and adapt its systems as fraud changes.
Attacks and detection are evolving together
he evolution of identity fraud is a race between attack creation and attack detection. Traditional presentation attacks included printed copies, screen displays, and physically altered documents. Today, attackers can produce more convincing reproductions, manipulate document images digitally, combine genuine and forged elements, and use increasingly sophisticated synthetic content.
The detection side has evolved accordingly. Modern PAD research explores models that learn both global document characteristics and localized security features. It also focuses on cross-dataset evaluation, robustness to previously unseen attacks, and improved generalization across countries and document formats.
However, a central lesson has emerged: strong performance within a single dataset does not necessarily translate into reliable performance in the real world. When the countries used for training are changed, performance can decline because document layouts, security features, materials, fonts, and capture conditions vary considerably. This is a practical limitation for both industry and academia: not every company has access to identity documents from every country, and researchers often cannot obtain the datasets required to test broad geographic generalization.
The goal, therefore, is not to claim that one model solves every fraud scenario. It is to measure limitations honestly, improve performance against unseen conditions, and establish evaluation practices that reflect the complexity of remote identity verification.
Tangible evidence: the PAD-ID Card Challenge and DAS 2026
A meaningful response to this challenge requires independent and neutral evaluation. This is the purpose of the international PAD-ID Card Challenge organized within the IEEE International Joint Conference on Biometrics (IJCB).
The competition has been held in 2024[2], 2025[3], and 2026[4] with the participation of Hochschule Darmstadt, Fraunhofer IGD, and Facephi. Its objective is to assess the state of the art in presentation attack detection for identity documents through cross-dataset evaluation, while also helping establish protocols that the research and industrial communities can reuse.
The initiative is particularly important because it addresses the lack of common benchmarks. Teams can be evaluated under comparable conditions rather than relying solely on private datasets or results obtained within a single organization’s data environment. The 2025 competition demonstrated that foundation-model approaches could improve generalization to unseen countries and bona fide samples, while also showing that large and diverse datasets remain one of the field’s central requirements.
The 2026 edition expanded the scope to passports in addition to identity cards, bringing the evaluation closer to the diversity of real-world machine-readable travel documents. It also involved more than 100 models submitted by 63 teams from universities and companies worldwide.
The broader research community is also meeting at events such as DAS 2026 in Vienna[5], where document analysis, document security, and identity technologies can be discussed across academic and industrial boundaries[6]. These forums help transform isolated research results into shared knowledge and more demanding evaluation practices.
From research to better products
The value of this work is ultimately measured by its impact on real onboarding journeys. A research program should help identify attacks that would otherwise remain undetected, reveal when a model is overfitted to a limited set of countries, and guide improvements that maintain security without unnecessarily rejecting legitimate users.
The PAD-ID Card Challenge provides a direct mechanism for this improvement. By testing systems against unseen documents, new bona fide images, and heterogeneous attack scenarios, it exposes weaknesses that may remain invisible in intra-data validation. The resulting insights can inform training strategies, model design, data collection, and the selection of complementary controls within a broader identity-verification architecture.
This does not mean that a competition result alone guarantees production security. It means that product development is informed by independent evidence and by conditions that are closer to the variability encountered in the real world. Research becomes a continuous feedback loop: benchmark, identify weaknesses, improve, and test again.
Choosing a partner for the future of identity
For organizations evaluating an identity technology partner, investment in research should be considered a strategic criterion, not a secondary technical detail.
A credible partner must recognize that PAD is an evolving security capability, not a finished feature. It should understand the limits created by privacy restrictions, insufficient bona fide data, geographic imbalance, and previously unseen attacks. It should also be willing to expose its technology to neutral evaluation alongside universities, research institutes, and other companies.
As scientists and citizens who depend on digital onboarding, we have a shared interest in ensuring that identity systems are genuinely competitive and continuously improved. The objective is not only to prevent financial fraud. It is to protect individuals from impersonation, misuse of their personal data, and the social consequences of someone else taking control of their identity.
The strongest identity partners are therefore not those that promise that every attack can be detected. They are those that invest in R&D, measure the problem honestly, improve their algorithms continuously, and contribute to the independent research needed to make digital identity safer.
[1] https://www.icao.int/publications/doc-series/doc-9303
[2] https://ieeexplore.ieee.org/document/10744475
[3] https://ieeexplore.ieee.org/document/11411073
[4] https://arxiv.org/abs/2607.15734
[5] https://das2026.seecs.edu.pk/
[6] https://link.springer.com/content/pdf/10.1007/978-3-032-36207-0_10.pdf