A presentation attack is when a fraudster holds a spoof up to a camera or sensor, such as a printed photo, a cutout, a silicone mask, or a screen replay, to beat a biometric check and impersonate someone. It is the most direct way to fool a face or fingerprint capture, and it is the exact threat liveness and PAD are built to stop.
What is a presentation attack, in plain English?
A presentation attack is any attempt to fool a biometric sensor by presenting a fake artifact to it. Instead of being the person, the attacker shows the camera something that looks like the person: a photo on paper, a video playing on a phone, a high-resolution mask, or a lifted fingerprint on a gummy mold. The industry also calls the fake object a presentation attack instrument.
The defining trait is that the attack happens at the lens. The fraudster is physically in front of the real sensor, using a prop to impersonate a genuine subject. That makes it the physical-world counterpart to an injection attack, where the camera is bypassed entirely and a synthetic feed is pushed straight into the app.
In the fraud stack, presentation attacks are the main reason liveness detection and presentation attack detection exist. If a face or fingerprint check had no liveness layer, a printout would sail through. The whole job of PAD is to tell a live, genuine person from an artifact held to the camera.
The spoof ladder, crude to sophisticated
- Print — Photo or paper. A printed face or a cutout held to the camera; the cheapest and easiest to catch.
- Replay — Screen replay. A photo or video of the victim played on a phone or tablet, often carrying moire and bezel tells.
- Mask — 3D mask or model. A silicone or resin mask that mimics real depth and can defeat weaker depth checks.
- Hybrid — Deepfake on a screen. A synthetic, animated face played to the lens, blending presentation and deepfake techniques.
What it looks like in practice
In practice
A fraudster buys a stolen ID and a matching social photo scraped from social media. During onboarding they print the victim's face at high resolution, cut out the eye area, and hold it in front of the phone to pass a face match against the document.
The liveness model flags the capture: the skin has no natural micro-texture, the lighting on the paper is flat, and the depth reading is uniform where a real face would curve. The session is blocked and the device is tagged. Weeks later the same device signature reappears with a screen-replay attempt on a different victim, confirming an operator working through a list.
Why it matters to operators
Presentation attacks are the baseline threat to any biometric check, and they scale cheaply. A printout costs pennies, so if your face check has no liveness layer, you are effectively accepting photos of your customers as proof of presence. That is the difference between a control and a formality.
The practical takeaway is to match your defense to the value at stake. A low-value action might tolerate lighter liveness, but account opening, high-value transfers, and recovery flows warrant strong PAD tested against defined attack levels. And because presentation is only half the picture, cover injection attacks too, or fraudsters will simply skip the lens.
What to watch for
- Flat texture. Paper and screens lack the micro-detail and pore structure of live skin under a good capture.
- Screen artifacts. Moire patterns, glare, and a visible bezel edge point to a replay rather than a live face.
- Uniform depth. A face with no natural curvature usually means a flat artifact, though good masks can defeat this.
- Repeat device or environment. The same background, lighting, or device across many identities suggests a spoof workstation.
- Escalating sophistication. If crude spoofs stop working, expect masks and deepfake replays next; keep testing new attack types.
Quick questions
How is a presentation attack different from an injection attack?
A presentation attack shows a fake artifact to the real camera; an injection attack bypasses the camera and feeds a synthetic image or video straight into the app. Presentation happens at the lens, injection happens in the pipe, and you need defenses for both.
What stops presentation attacks?
Liveness detection and presentation attack detection, which read texture, depth, and replay artifacts to separate a live person from an artifact. Strong programs benchmark PAD against defined attack levels and revalidate as new spoofs appear.
Are masks really a threat?
Yes for higher-value targets. High-quality silicone or resin masks reproduce depth and can defeat weaker liveness checks, which is why serious programs test against 3D attack instruments, not just photos and screens.
Is a screen replay a presentation attack?
Yes. Playing a photo or video of the victim on a phone or tablet held to the camera is one of the most common presentation attacks, and it often carries moire and bezel tells a good detector can catch.
Do I need liveness on every biometric check?
Match the strength to the value. Low-value actions may tolerate lighter checks, but onboarding, high-value payments, and recovery flows should carry strong liveness because a bare face match accepts a printout as proof.
Go deeper
- NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
- FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

