Presentation Attack vs. Injection Attack: Understanding the Difference
Presentation attacks show the camera something that is not a real, live face. An injection attack bypasses the camera entirely and inserts a video directly into the data stream that the system believes is coming from the device’s camera.
Both attack methods aim to pass off an identity impersonation as genuine, which is why they are often confused. Generic terms such as “spoofing” are frequently used to describe both, blurring the very distinction that determines which defense you actually need.
That distinction has an important implication for anyone evaluating biometric vendors: ISO/IEC 30107-3 certification validates protection against presentation attacks—not injection attacks.
This article clearly distinguishes between these two threats, explains why each requires a different security control, and shows why relying solely on presentation attack certification leaves a security gap that many security teams fail to recognize until it’s too late.
What Is a Presentation Attack?
A presentation attack takes place in front of the camera: someone presents an artifact to the camera in an attempt to make the system believe it is looking at a live person. The camera does capture something—but that something is not genuine.
The most common attack vectors have been known for years:
- A photo, either printed or displayed on another device’s screen.
- A mask, made of paper or silicone, with varying levels of realism.
- A replayed video, where a legitimate recording is played back in front of the camera.
In all three cases, the sensor captures something real, but it is not the actual person.
This is the classic attack against facial capture, and it is the type of threat that most liveness detection systems are already designed to detect.
What Is an Injection Attack?
An injection attack does not try to deceive the camera—it bypasses it entirely. Instead of presenting a fake artifact in front of the camera, the attacker injects a video file directly into the data stream that the system believes is coming from the device’s camera, typically through a virtual camera, an emulator, or hooking techniques.
This is the key difference: an injection attack is not physical and does not attempt to fool the camera. Instead, it feeds the system a pre-generated video, which is treated as if it had just been captured by the device.
As a result, injection attacks bypass defenses designed to analyze what the camera “sees.” This is also why they are the primary delivery channel for the highest-risk deepfake attacks.
We cover the mechanics of injection attacks, their different variants, and their growing prevalence in detail in our dedicated article on injection attacks.
Presentation vs. Injection: The Difference
| Presentation Attack | Injection Attack | |
|---|---|---|
| Attack Vector | At the sensor: the camera captures an artifact | In the data stream: bypasses the sensor |
| Example | Photo, mask, screen, replayed video | Virtual camera, emulator, injected video or deepfake |
| Attack Target | The physical capture process, in front of the camera | The data transmission stream, before anything is captured |
| Defense | Liveness Detection | IAD (Injection Attack Detection) |
| Standard | ISO/IEC 30107-3 | CEN/TS 18099 |
How to Defend Against Each: PAD vs. IAD
The table summarizes what each attack is. The more important question is why the distinction matters: the two threats target different layers, so they require different defenses.
- PAD (Presentation Attack Detection) relies on liveness detection. It analyzes what the sensor captures and looks for the characteristics of a real, live person—such as skin texture, depth, reflections, natural micro-movements, and active challenge responses. The question it answers is: “Is there a live person in front of the camera?”
- IAD (Injection Attack Detection) does not analyze the face itself. Instead, it verifies the source of the signal, determining whether the image originates from the device’s physical camera or from a virtual or manipulated source. Its question is different: “Did this capture actually come from the device’s camera?”
Are Injection Attacks and Deepfake Detection the Same Thing?
It’s worth clarifying one point about deepfakes, as this is where there is the most confusion in the market.
Deepfake vs. Synthetic Identity vs. Replay Attack
These terms are often used interchangeably, so it’s worth taking a moment to clarify what they are and how they differ:
- Synthetic identity (deepfake): A video and its associated data generated entirely by generative AI. The resulting face does not belong to any real, living person. As a result, this attack method does not impersonate a specific victim.
- Face morphing: An attack technique that replaces the face in a video with that of another person.
- Replay attack: An attack that injects a genuine video of a real person, obtained through illegitimate means such as hacking or social engineering.
Injection Attack Detection (IAD) focuses on the input channel, not on identifying each individual deepfake. If a video cannot be injected into the system in the first place, it doesn’t matter how convincing it looks.
For that reason, organizations should be cautious of broad claims about “deepfake detection“ and instead ask vendors to provide evidence that they can detect the actual attack methods—presentation attacks and injection attacks—because those capabilities can be independently tested and verified.
The key takeaway is this: strong protection against presentation attacks provides no protection against injection attacks—and vice versa.
An excellent liveness detection system cannot determine how an injected video entered the system, while a robust Injection Attack Detection (IAD) solution does not assess whether the face itself is real or a mask. Each addresses a different attack surface of the same problem.
When evaluating a biometric vendor, the question that really matters is how they integrate PAD and IAD—not which one they offer.
Why ISO/IEC 30107-3 Certification Does Not Cover Injection Attacks
ISO/IEC 30107-3 is the standard for evaluating presentation attack detection. It defines how a system’s resistance to photos, masks, screens, and other artifacts presented to a sensor is measured. It is a rigorous and widely recognized standard, and requiring compliance with it is entirely reasonable. However, its scope is limited to presentation attacks.
A vendor certified under ISO/IEC 30107-3 may provide very strong protection against fake photos, masks, and replayed videos shown to the camera, while still being completely vulnerable to injection attacks.
The CEN/TS 18099 Standard
Injection attacks also have their own international standard: CEN/TS 18099. Introduced in 2025, the standard defines three assurance levels for evaluating protection against injection attacks: Basic, Substantial, and High.
At present, only a limited number of accredited laboratories offer certification against CEN/TS 18099, so adoption is still in its early stages. As a result, the absence of this certification should not, by itself, be considered a decisive factor when evaluating a biometric vendor.
Before Signing with a Vendor
An ISO/IEC 30107-3 certificate tells you that a vendor’s solution can resist photos, masks, and replay attacks presented to the camera. It tells you nothing about whether that same platform can detect virtual cameras or videos injected directly into the data stream.
Before signing with a vendor, ask them directly what Injection Attack Detection (IAD) controls they have in place, what evidence supports those claims, and whether they have validated them against CEN/TS 18099 in addition to PAD testing. If the answer is simply, “We’re certified under ISO/IEC 30107-3,” then you already know which half of the problem remains unaddressed.
Learn how Injection Attack Detection complements liveness detection within a unified identity verification stack.
It is a type of injection attack in which the attacker uses a virtual camera (or an emulator) to impersonate the device’s physical camera, feeding the system a fabricated video instead of a genuine live capture.
No. ISO/IEC 30107-3 evaluates presentation attack detection only. An injected deepfake delivered through a virtual camera enters the system via a channel that falls outside the scope of the standard.
Neither. They are different security controls designed to answer different questions, and they work as complementary layers of protection. The real question is not which one to choose, but how to integrate them effectively.