Glossary
share:

Biometric providers with presentation attack detection that works across mobile and web onboarding flows

Fraudsters don’t need to steal physical identity documents to bypass digital onboarding anymore. 

With AI-generated faces, face swap apps, and other sophisticated spoofing techniques becoming more common, attackers now attempt to fool biometric systems using synthetic or manipulated images and videos. 

As businesses move more customer onboarding online, biometric verification is an important part of defense, of course. But not all biometric solutions offer the same level of protection. 

Ideally, you’re looking for a provider with presentation attack detection (PAD) that can detect spoofing attempts across every digital touchpoint, from mobile apps to browser-based onboarding.

An example of such a provider is GBG. In this article, we will explain how presentation attack detection works and how GBG can help you protect your business against fraud.

What is presentation attack detection (PAD)?

Presentation attack detection (PAD) is technology that helps tell the difference between a real person and a fake biometric sample. 

It automatically detects and blocks attempts to fool biometric systems using things like photos, videos, masks, deepfakes, or other synthetic content.

How presentation attacks work

A presentation attack happens when a fraudster tries to trick a biometric system into thinking they're someone else by presenting a fake biometric sample. This could include:

  • A printed photo of a person's face
  • A video replay shown on a phone or tablet
  • A silicone or latex fingerprint
  • A 3D mask
  • An AI-generated deepfake or synthetic face

These attacks continue to grow because digital onboarding is becoming the standard for customer onboarding, and generative AI has made it easier to create convincing synthetic media.

Why PAD matters for identity verification

Presentation attack detection (PAD) helps ensure that the person completing a biometric verification check is a real, physically present individual; not a spoof or AI-generated imitation. 

By stopping these attacks before they're successful, PAD helps reduce account opening fraud, synthetic identity fraud, and account takeover attempts.

For organizations in regulated industries, PAD also plays an important role in meeting KYC and AML requirements.

What to look for in a biometric provider with presentation attack detection

The right provider must balance security with a low-friction experience to prevent customer drop-offs during onboarding.

Look for:

  • Cross-channel support for mobile and web onboarding. Customers expect to start and finish identity verification on whichever device is most convenient, whether that's a native iOS or Android app, a mobile browser, or a desktop computer. Look for a provider that delivers a consistent experience across all channels and offers API-driven integrations, so you can build flexible verification journeys that work wherever your users are.
  • Certified liveness detection and anti-spoofing capabilities. Choose a provider that offers passive liveness detection certified against recognised ISO/IEC standards. Unlike active liveness, which asks users to blink, smile, or turn their head, passive liveness works in the background using a single selfie. This creates a faster, more seamless experience while reducing user error and onboarding drop-offs.
  • Protection against emerging AI-powered attacks. Traditional spoofing methods such as printed photos and replay videos are no longer the only threat. Modern biometric solutions should also detect AI-generated attacks, including deepfakes, face swaps, and video injection attacks, where manipulated video is fed directly into the verification system instead of coming from a live camera.
  • A fast user experience that maximizes onboarding conversion. Strong security shouldn't come at the expense of customer experience. Look for solutions that complete verification in just a few seconds and include features such as real-time camera guidance and image quality checks. Helping users capture a high-quality selfie on the first attempt reduces failed verifications and improves overall KYC conversion.

Why organizations choose GBG for biometric verification and presentation attack detection

Our team has more than 30 years of experience in the identity space, helping businesses scale safely across 195 countries. 

Here are three reasons 20,000+ customers across the globe choose to work with us: 

Verify customers across every channel

Whether your customers onboard through a native mobile app, mobile browser, or desktop, GBG delivers a consistent identity verification experience through our end-to-end GBG Go platform.

Our mobile SDKs and APIs make it easy to build a single onboarding journey across channels, while access to more than 8,500 global identity documents and hundreds of trusted local data sources helps you verify users around the world.

Stop spoofing, deepfakes and AI-powered fraud

GBG combines multiple layers of biometric and identity protection to defend against both traditional presentation attacks and emerging AI-generated threats.

Our platform includes:

  • Passive liveness detection certified to the highest ISO/IEC presentation attack detection standards
  • Face matching that analyzes 68 unique biometric facial landmarks to confirm a user matches their identity document
  • 100% detection of deepfake injection attacks, with automatic blocking of face-swap applications
  • Document tamper detection that identifies common signs of manipulated or forged identity documents
  • Additional identity intelligence and fraud signals that strengthen verification decisions, such as GBG Trust

Improve verification success before checks even begin

The quality of an image has a significant impact on both fraud detection and customer pass rates. That's why GBG focuses on improving capture quality before verification takes place.

As David Thomas, Global Head of Product, Documents and Biometrics at GBG, explains:

"What often gets overlooked is how much can be done on the front end to ensure the best quality image reaches the backend. Capture SDKs are crucially important; they generate and quality-check images before anything is submitted for processing. That is a part of the conversation that doesn't come up enough."

To support this, our pre-built digital onboarding SDKs automatically classify documents, eliminate glare, and adapt capture flows based on specific camera capabilities. 

Final notes

Choosing a biometric provider with robust presentation attack detection is essential for protecting your business against AI-enabled fraud. 

GBG is an example of an all-in-one solution that works across mobile and web flows, combining certified passive liveness with advanced deepfake detection. 

 

FAQs: Biometric presentation attack detection

Does presentation attack detection work on web browsers?

Yes, modern biometric providers like GBG offer PAD that works across both mobile apps and web browsers. By using web-based capture tools and APIs, the system can perform liveness checks and detect spoofs even when a user is on a desktop or mobile browser.

What is the difference between active and passive liveness?

Active liveness requires the user to perform an action, like blinking or turning their head. Passive liveness is less intrusive; it uses a single static selfie to detect signs of spoofing or synthetic media. Passive liveness typically sees higher completion rates because it removes the risk of user error.

Can biometrics detect deepfakes?

Specialized biometric providers use injection attack detection to identify when a video or image has been manipulated by AI. By analyzing biometric facial landmarks and looking for pixel level inconsistencies, the system can block deepfakes and face swap attempts during onboarding.

Get in touch with GBG

Request a demo