ataque de presentación
Analysis

Presentation Attack vs. Injection Attack: Understanding the Difference

Presentation attacks show the camera something that is not a real, live face. An injection attack bypasses the camera entirely and inserts a video directly into the data stream that the system believes is coming from the device’s camera.

Both attack methods aim to pass off an identity impersonation as genuine, which is why they are often confused. Generic terms such as “spoofing” are frequently used to describe both, blurring the very distinction that determines which defense you actually need.

That distinction has an important implication for anyone evaluating biometric vendors: ISO/IEC 30107-3 certification validates protection against presentation attacks—not injection attacks.

This article clearly distinguishes between these two threats, explains why each requires a different security control, and shows why relying solely on presentation attack certification leaves a security gap that many security teams fail to recognize until it’s too late.

What Is a Presentation Attack?

A presentation attack takes place in front of the camera: someone presents an artifact to the camera in an attempt to make the system believe it is looking at a live person. The camera does capture something—but that something is not genuine.

The most common attack vectors have been known for years:

  • A photo, either printed or displayed on another device’s screen.
  • A mask, made of paper or silicone, with varying levels of realism.
  • A replayed video, where a legitimate recording is played back in front of the camera.

In all three cases, the sensor captures something real, but it is not the actual person.

This is the classic attack against facial capture, and it is the type of threat that most liveness detection systems are already designed to detect.

What Is an Injection Attack?

An injection attack does not try to deceive the camera—it bypasses it entirely. Instead of presenting a fake artifact in front of the camera, the attacker injects a video file directly into the data stream that the system believes is coming from the device’s camera, typically through a virtual camera, an emulator, or hooking techniques.

This is the key difference: an injection attack is not physical and does not attempt to fool the camera. Instead, it feeds the system a pre-generated video, which is treated as if it had just been captured by the device.

As a result, injection attacks bypass defenses designed to analyze what the camera “sees.” This is also why they are the primary delivery channel for the highest-risk deepfake attacks.

We cover the mechanics of injection attacks, their different variants, and their growing prevalence in detail in our dedicated article on injection attacks.

Presentation vs. Injection: The Difference

Presentation Attack Injection Attack
Attack Vector At the sensor: the camera captures an artifact In the data stream: bypasses the sensor
Example Photo, mask, screen, replayed video Virtual camera, emulator, injected video or deepfake
Attack Target The physical capture process, in front of the camera The data transmission stream, before anything is captured
Defense Liveness Detection IAD (Injection Attack Detection)
Standard ISO/IEC 30107-3 CEN/TS 18099

How to Defend Against Each: PAD vs. IAD

The table summarizes what each attack is. The more important question is why the distinction matters: the two threats target different layers, so they require different defenses.

  • PAD (Presentation Attack Detection) relies on liveness detection. It analyzes what the sensor captures and looks for the characteristics of a real, live person—such as skin texture, depth, reflections, natural micro-movements, and active challenge responses. The question it answers is: “Is there a live person in front of the camera?”
  • IAD (Injection Attack Detection) does not analyze the face itself. Instead, it verifies the source of the signal, determining whether the image originates from the device’s physical camera or from a virtual or manipulated source. Its question is different: “Did this capture actually come from the device’s camera?”

Are Injection Attacks and Deepfake Detection the Same Thing?

It’s worth clarifying one point about deepfakes, as this is where there is the most confusion in the market.

Deepfake vs. Synthetic Identity vs. Replay Attack

These terms are often used interchangeably, so it’s worth taking a moment to clarify what they are and how they differ:

  • Synthetic identity (deepfake): A video and its associated data generated entirely by generative AI. The resulting face does not belong to any real, living person. As a result, this attack method does not impersonate a specific victim.
  • Face morphing: An attack technique that replaces the face in a video with that of another person.
  • Replay attack: An attack that injects a genuine video of a real person, obtained through illegitimate means such as hacking or social engineering.

Injection Attack Detection (IAD) focuses on the input channel, not on identifying each individual deepfake. If a video cannot be injected into the system in the first place, it doesn’t matter how convincing it looks.

For that reason, organizations should be cautious of broad claims about deepfake detection and instead ask vendors to provide evidence that they can detect the actual attack methods—presentation attacks and injection attacks—because those capabilities can be independently tested and verified.

The key takeaway is this: strong protection against presentation attacks provides no protection against injection attacks—and vice versa.

An excellent liveness detection system cannot determine how an injected video entered the system, while a robust Injection Attack Detection (IAD) solution does not assess whether the face itself is real or a mask. Each addresses a different attack surface of the same problem.

When evaluating a biometric vendor, the question that really matters is how they integrate PAD and IAD—not which one they offer.

Why ISO/IEC 30107-3 Certification Does Not Cover Injection Attacks

ISO/IEC 30107-3 is the standard for evaluating presentation attack detection. It defines how a system’s resistance to photos, masks, screens, and other artifacts presented to a sensor is measured. It is a rigorous and widely recognized standard, and requiring compliance with it is entirely reasonable. However, its scope is limited to presentation attacks.

A vendor certified under ISO/IEC 30107-3 may provide very strong protection against fake photos, masks, and replayed videos shown to the camera, while still being completely vulnerable to injection attacks.

The CEN/TS 18099 Standard

Injection attacks also have their own international standard: CEN/TS 18099. Introduced in 2025, the standard defines three assurance levels for evaluating protection against injection attacks: Basic, Substantial, and High.

At present, only a limited number of accredited laboratories offer certification against CEN/TS 18099, so adoption is still in its early stages. As a result, the absence of this certification should not, by itself, be considered a decisive factor when evaluating a biometric vendor.

Before Signing with a Vendor

An ISO/IEC 30107-3 certificate tells you that a vendor’s solution can resist photos, masks, and replay attacks presented to the camera. It tells you nothing about whether that same platform can detect virtual cameras or videos injected directly into the data stream.

Before signing with a vendor, ask them directly what Injection Attack Detection (IAD) controls they have in place, what evidence supports those claims, and whether they have validated them against CEN/TS 18099 in addition to PAD testing. If the answer is simply, “We’re certified under ISO/IEC 30107-3,” then you already know which half of the problem remains unaddressed.

Learn how Injection Attack Detection complements liveness detection within a unified identity verification stack. 

No. Biometric spoofing is an umbrella term that encompasses both presentation attacks and injection attacks. Using it as a synonym for either one obscures an important distinction: presentation attacks deceive the sensor, while injection attacks bypass it altogether.

No—not on its own. Liveness detection (the foundation of Presentation Attack Detection, or PAD) determines whether the face is real and physically present, not where the video came from. An injected video can bypass liveness detection because liveness does not verify the origin of the signal.

It is a type of injection attack in which the attacker uses a virtual camera (or an emulator) to impersonate the device’s physical camera, feeding the system a fabricated video instead of a genuine live capture.

No. ISO/IEC 30107-3 evaluates presentation attack detection only. An injected deepfake delivered through a virtual camera enters the system via a channel that falls outside the scope of the standard.

Neither. They are different security controls designed to answer different questions, and they work as complementary layers of protection. The real question is not which one to choose, but how to integrate them effectively.

No. That’s not how it works. Injection Attack Detection (IAD) protects by closing off the channel through which a deepfake must enter—by verifying the origin of the capture—rather than trying to identify each individual piece of synthetic content.

Not yet. There is currently no widely established standard equivalent to ISO/IEC 30107-3 for injection attacks. That is why it’s important to ask vendors directly what Injection Attack Detection (IAD) controls they have in place and what evidence they can provide to support their effectiveness.

Beyond PAD certification, ask how the solution verifies that every capture originates from the physical camera of a legitimate device, how it detects and handles virtual cameras and emulators, and where the vendor’s responsibility ends and your integration’s responsibility begins.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link