SardineCon SF/2026

Learn More

What is Injection attack?

SUBSCRIBE

An injection attack skips the real camera and feeds pre-recorded, edited, or AI-generated media straight into the verification pipeline, often through a virtual camera, an emulator, or an intercepted API call. It is one of the fastest-growing ways to beat remote identity checks because it leaves no physical artifact for liveness to catch.

What is an injection attack, in plain English?

An injection attack bypasses the camera entirely. Instead of holding something up to the lens, the fraudster feeds media directly into the verification pipeline: a pre-recorded video, an edited image, or an AI-generated face pushed in through a virtual camera, an emulator, or an intercepted API call. As far as the check can tell, a perfect capture just arrived; in reality no real camera ever saw a real person.

This is why it is so dangerous. A classic spoof, a photo or mask held to the lens, leaves a physical artifact that liveness is built to detect. Injection leaves none, because the image is synthetic and inserted below the camera layer, so liveness alone rarely catches it. It has become one of the fastest-growing ways to beat remote identity checks, riding the rise of deepfake tools.

In fraud and AML, defending against injection shifts the question from what is in the image to where the image came from. The controls are device integrity, capture provenance, virtual-camera and emulator detection, and tamper checks on the capture software, not just analyzing the picture.

Presentation attack versus injection

What changes

Presentation attack

Injection attack

Where it happens

In front of the real camera.

Below the camera, fed into the pipeline.

The artifact

A photo, mask, or screen with physical tells.

No physical artifact at all.

What catches it

Liveness detection.

Device integrity and capture provenance.

Typical tooling

Printed photo, mask, replay screen.

Virtual camera, emulator, intercepted API.

Who is involved?

Who

Their role

The attacker

Builds or buys synthetic media and injects it through a virtual camera or emulator.

The IDV vendor

Adds device-integrity and provenance checks to catch what liveness cannot.

The fraud team

Watches for emulator and virtual-camera signals and tightens the capture channel.

The deepfake toolmaker

Supplies the AI models that make convincing injected faces cheap and fast.

What it looks like in practice

In practice

A wave of new signups all pass the selfie and liveness checks with clean, well-lit faces. The biometric scores look great. But the device signals show each session ran inside an emulator, with the front camera served by a virtual camera driver rather than real hardware.

The faces were deepfakes injected straight into the flow, so liveness saw a smooth, moving face and approved it. Nothing was ever held to a lens, so there was no artifact to catch. The tell was not in the image at all; it was in the channel. Once the team added emulator and virtual-camera detection, the whole batch failed at capture.

Why it matters to operators

Injection breaks the assumption most remote checks quietly rely on: that the image reaching the model actually came from the device's camera. Once that assumption fails, a strong liveness score means little, because the attacker never presented anything physical to defeat it. As deepfake tooling gets cheaper, this moves from a niche threat to a volume one.

The practical shift is to stop judging only the picture and start judging the channel. Device integrity, capture provenance, virtual-camera and emulator detection, and tamper checks on the capture software are what actually catch injection. A flow that leans on liveness alone will keep passing injected media no matter how good its image analysis is.

What to watch in the data

  • Virtual camera drivers. A capture served by a virtual camera instead of real hardware is a direct injection signal.
  • Emulated environment. Sessions running inside an emulator or virtual machine during identity capture warrant a hard look.
  • Too-perfect captures. A run of flawless, evenly lit selfies with no natural motion or artifacts can mean synthetic media.
  • Provenance gaps. Missing or tampered capture-provenance signals suggest the image did not come from the genuine camera.
  • API anomalies. Requests that arrive without the expected client integrity signals may be intercepted or replayed.

Quick questions

How is injection different from a presentation attack?

A presentation attack holds a spoof in front of the real camera and leaves physical tells. Injection bypasses the camera and feeds synthetic media straight into the pipeline, leaving no artifact for liveness to catch.

Why does liveness alone miss it?

Liveness is designed to detect a fake presented to a lens. Injection never presents anything physical; the media is inserted below the camera, so the liveness model may see a convincing moving face and approve it.

What actually stops injection?

Controls that judge the channel, not just the image: device integrity, capture provenance, virtual-camera and emulator detection, and tamper checks on the capture software. These confirm the media truly came from a genuine camera.

Is injection the same as a deepfake?

Not quite. A deepfake is the synthetic media; injection is the delivery method that inserts it into the pipeline. Deepfakes are a common payload, but injection can also carry pre-recorded or edited real footage.

Why is it growing so fast?

Because deepfake and virtual-camera tools are cheap, easy, and improving quickly. That lowers the skill needed to run injection at volume, turning it from a rare, expert attack into a mass-market one.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

What to know alongside Injection attack