SardineCon SF/2026

Learn More
Identity verification4 min de lectura

¿Qué es Presentation attack detection (PAD)?

SUBSCRIBE

Presentation attack detection is the technology that catches spoofs during a biometric capture, deciding whether the subject is a live, genuine person or a fake artifact like a mask, photo, or screen replay. It is the measurable defense that turns a bare face or fingerprint check into one you can actually trust.

What is PAD, in plain English?

Presentation attack detection is the part of a biometric check that answers one question: is this a live person or a fake? When a face or fingerprint is captured, PAD inspects the signal for the tells of a spoof, such as flat texture, screen moire, unnatural depth, or missing sensor artifacts, and returns a decision on whether it trusts the subject as genuine.

PAD is the engine behind liveness. People often use liveness and PAD interchangeably, but PAD is the broader, more formal term: it is the defense against presentation attacks specifically, the spoofs held up to a real sensor. It is measured, benchmarked, and certified against defined attack levels, which is why buyers ask for PAD results rather than a vague liveness claim.

In the fraud stack it sits inside identity verification, guarding face match and fingerprint checks. One important boundary: PAD covers artifacts presented to the lens, but it does not stop injection attacks that bypass the camera. Those need device and provenance defenses, so PAD is necessary but not sufficient on its own.

How PAD is measured

Metric or level

What it means

APCER

How often a spoof is wrongly accepted as genuine; the miss rate you most want low.

BPCER

How often a real person is wrongly rejected as a spoof; the friction cost to genuine users.

Level 1

Resistance to easy attacks like printed photos and basic screen replays.

Level 2

Resistance to harder attacks like high-resolution replays, masks, and 3D models.

Certification

Independent lab testing against a standard, so a claim is verified rather than self-reported.

What it looks like in practice

In practice

A lender evaluates two vendors for its onboarding face check. Both claim liveness, but only one reports certified PAD results: a low spoof-acceptance rate at Level 2 alongside a modest rejection rate for real users. The team runs a bake-off with printed photos, phone replays, and a silicone mask.

The certified vendor catches every spoof but rejects a handful of genuine users in poor lighting, a tradeoff the team tunes. The other passes the mask twice. The lender picks the certified option, then adds device-integrity checks on top, knowing PAD does not cover a fraudster who injects a synthetic feed and never shows anything to the lens.

Why it matters to operators

PAD is what makes a biometric check auditable. A vendor can say it has liveness, but PAD gives you numbers: how often spoofs get through, how often real users get bounced, and against which attack levels. That lets you set a risk-appropriate threshold instead of trusting a marketing line, and it gives compliance and audit something concrete to point at.

The two failure modes pull against each other. Turn PAD up and you reject more real customers; turn it down and you let more spoofs through. Tune it by the value at stake, revalidate against fresh attack methods, and remember the blind spot: PAD stops artifacts at the lens, so pair it with injection and device defenses to close the whole gap.

What to watch for

  • Uncertified claims. Liveness without lab-tested PAD numbers is a marketing claim, not a measured control.
  • Only Level 1 coverage. Passing printed photos but not masks or high-res replays leaves higher-value flows exposed.
  • Rising false rejects. A spike in genuine users bounced can mean the threshold is too tight or capture quality dropped.
  • Injection blind spot. A strong PAD score means nothing if the feed was injected; watch for virtual cameras and emulators.
  • Stale benchmarks. Attack methods evolve, so PAD tested a year ago may miss today's spoofs; retest regularly.

Quick questions

Is PAD the same as liveness detection?

They overlap heavily. Liveness is the general idea of proving a real person is present; PAD is the formal, measured defense against presentation attacks specifically. In practice PAD is the term you use when you want certified numbers rather than a general claim.

What does PAD not cover?

Injection attacks. PAD judges what is presented to the sensor, so if a fraudster bypasses the camera and feeds a synthetic image directly into the app, PAD never sees the bypass. You need device-integrity and capture-provenance checks for that.

What are APCER and BPCER?

APCER is the rate at which spoofs are wrongly accepted, the miss rate. BPCER is the rate at which genuine users are wrongly rejected, the friction cost. Good PAD keeps APCER low without pushing BPCER so high that real customers abandon.

What do the attack levels mean?

They grade the difficulty of spoofs a detector resists. Level 1 covers easy attacks like printed photos; Level 2 covers harder ones like high-resolution replays and 3D masks. Higher-value flows should require higher levels.

Why ask for certification?

Because self-reported numbers are easy to inflate. Independent lab certification against a standard confirms the spoof-detection and rejection rates are real, which matters when you are defending the choice to auditors or a risk committee.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Qué saber junto con Presentation attack detection (PAD)