Glossary
share:

Identity verification solutions that detect printed photo attacks, 3D mask spoofs, and screen replay during onboarding

As digital onboarding becomes the standard for industries like fintech and iGaming, fraudsters are moving beyond simple data theft. They increasingly use presentation attacks with physical artifacts designed to fool biometric sensors and, ultimately, bypass security. 

Effective identity verification solutions combine biometrics, liveness detection, document authentication, and fraud intelligence to catch these attempts in real time.

GBG is an example of an identity verification solution that helps detect printed photo attacks, 3D mask spoofs, and screen replay during onboarding. In this article, we’ll discuss how solutions such as this work in practice and what capabilities to look for in the right provider.

How identity verification solutions detect common presentation attacks

The challenge is that fraudsters rely on a variety of techniques to impersonate genuine customers. Each attack type targets a different vulnerability in the biometric capture process, requiring specialized detection logic to maintain security.

Detecting printed photo attacks

In a printed photo attack, a fraudster presents a high-resolution physical image of another person's face to the camera. It's quite a low-tech attempt to bypass basic facial recognition that only looks for simple feature matching.

Identity verification solutions detect these attacks by using liveness detection to determine if the input is a real, three-dimensional human. Systems analyze specific facial characteristics to spot discrepancies, such as:

  • Depth perception to ensure the subject isn't a flat surface
  • Texture patterns that reveal paper grain or ink artifacts
  • Lighting behavior, such as the way light reflects off skin versus a printed photo
  • The absence of micro movements and natural muscle contractions

Detecting 3D mask spoofs

A 3D mask spoof is a more advanced presentation attack where the fraudster wears a realistic physical replica, often made of silicone or latex, to mimic a target's facial geometry.

Modern biometric security systems look past the surface appearance to identify these physical artifacts. To detect a 3D mask, the solution might evaluate:

  • Skin texture and the way light interacts with synthetic materials
  • Depth information that identifies rigid edges or unnatural contours
  • Facial movement patterns, as masks often fail to replicate the range of motion of real human skin
  • Signs of physical artifacts, such as the edge of a mask near the eyes or neck

Detecting screen replay attacks

Screen replay attacks occur when an attacker displays a photo or recorded video of a genuine user on a smartphone or tablet screen. They hold this device in front of the verification camera to simulate a live person.

Liveness detection identifies these attempts by looking for environmental and digital signatures that are unique to screens. 

These detection methods look for:

  • Screen reflections and the distinct glare produced by a digital display
  • Image distortions and moire patterns caused by the camera capturing a pixel grid
  • Movement inconsistencies that don't align with the physics of a live environment

Detecting deepfake and injection attacks

Deepfake attacks use artificial intelligence to generate realistic identities or manipulate existing faces in real time. Injection attacks bypass the camera by feeding this synthetic media directly into the system's data stream.

Advanced biometric systems monitor the integrity of the entire capture session to stop these digital manipulations.

How we detect presentation attacks during identity verification

Our end-to-end identity verification platform, GBG Go, combines biometric security, passive liveness testing, and document authentication. This layered approach helps prevent identity fraud while maintaining a low-friction onboarding experience for genuine users.

Here’s how to detect presentation attacks using our solutions:

Stop biometric spoofing with certified passive liveness detection

Traditional liveness checks often require users to blink, smile or turn their head to prove they're physically present. While effective, these additional steps can create friction and increase user error.

Our passive liveness detection takes a different approach. Instead of asking customers to perform specific actions, the technology analyzes a single live selfie for signs of spoofing, impersonation, or presentation attacks. This helps genuine customers complete verification more easily while maintaining a high level of security.

For example, Australian mutual bank Bank First implemented our identity verification solution with passive anti-spoofing liveness detection and biometric selfie-to-ID matching to strengthen digital onboarding. 

After deployment, the organization increased successful digital verifications from 70% to 77% while helping protect against identity fraud and spoofing attempts during account opening.

Note: Certified to meet leading ISO/IEC presentation attack detection standards, our solution automatically identifies common spoofing techniques, including printed photographs, screen replay attacks and physical masks. 

What’s more…

The rise of AI-generated imagery, sophisticated face swap tools, and fraudulent identity documents has created new challenges for digital businesses. Fraudsters can now manipulate biometric data and documents in ways that appear convincing to human reviewers, making it harder to distinguish genuine customers from bad actors.

We’ve built our solutions to help customers implement:

  • 100% detection of deepfake injection attacks
  • Advanced analysis checks for signs of image manipulation biometric inputs that could appear authentic at first glance but have actually been digitally altered

As David Thomas, Global Head of Product, Documents & Biometrics at GBG, explains:

"When it comes to biometric matching, the algorithms we deploy are much better than human beings. A human reviewer looking at a small black and white passport photo can’t reliably tell two similarly-looking men apart. Human beings are far more easily fooled than the facial matching algorithms we use, and that matters because every document includes a portrait photo."

You can also combine biometric verification with advanced document analysis:

  • Get access to a continuously updated library of more than 8,500 government-issued ID types from 195 countries
  • Use our system that performs more than 50 forensic checks in seconds and is designed to identify signs of tampering and fraud, including photo substitution, altered text, font manipulation and other physical modification

Checklist: Capabilities to look for in an identity verification solution

When evaluating identity verification solutions, prioritize these capabilities to detect modern presentation attacks:

  • Passive liveness detection: Evaluates a selfie or video capture to determine if it comes from a live person. It detects signs of spoofing without requiring users to perform actions, which reduces friction while maintaining security.
  • Presentation attack detection (PAD): Identifies whether biometric input is from a genuine person or an artifact like a 3D mask. It analyzes signals like facial depth, texture, and light reflection to find digital or physical fakes.
  • Deepfake and injection attack detection: Detects AI-generated faces and face swap applications. This protects against attacks that occur before biometric data even reaches your verification system.
  • Document authentication and tamper detection: Examines identity documents for signs of alteration. This identifies modified photos, changed text fields and fraudulent document presentations.

Final thoughts

Presentation attacks are evolving beyond just fake photos. Fraudsters now use 3D masks, deepfakes and screen replays to bypass onboarding security. 

As such, effective solutions require layered identity verification defenses that combine passive liveness, biometric fraud detection, and document authentication to help protect your business.

FAQs

What is the difference between active and passive liveness detection?

Active liveness requires the user to perform a specific action, such as blinking or following a dot on the screen, which can sometimes add more friction for customers. Passive liveness works in the background by analyzing a single frame or capture for signs of spoofing, providing a faster customer experience.

Can 3D facial recognition detect 3D masks?

Yes, advanced 3D biometric systems analyze depth, skin texture and light absorption. Since physical masks have different thermal and light-reflecting properties than human skin, these systems can identify the presence of a physical artifact even if it closely resembles a human face.

How do identity verification solutions stop deepfakes?

Solutions stop deepfakes by looking for digital artifacts and inconsistencies in the video or image stream that are invisible to humans. They also use injection attack detection to ensure the video feed is a live capture from the camera rather than a pre-recorded or AI-manipulated file being fed into the system.

Why is document authentication important for biometric security?

Presentation attacks often involve a stolen or tampered document. If you only verify the face without authenticating the ID document, a fraudster could use a forged ID alongside a deepfake to successfully impersonate a genuine user. Therefore, layers are necessary to close all potential gaps.

Get in touch with GBG

Request a demo