The liveness check most teams bought was built to catch someone holding up a printed photo. Today’s attacks inject synthetic video straight into the camera feed and wear a generated face. Microblink’s biometric authentication confirms a live human is present and matches them to their verified identity document.
We publish what independent testing found, rather than asking you to take an accuracy claim on trust.
The Gap in Most Deployments
Most liveness checks were designed to catch a printed photo or a face on a screen. Generative models now produce faces that satisfy those same checks, so a control that still passes its own tests stops catching what actually arrives.
Injection attacks feed synthetic video directly into the application through a virtual camera or the API, never presenting anything to a lens. A check that only evaluates what the camera sees has nothing to evaluate.
Every vendor claims high accuracy. Very few publish false accept and false reject rates from testing they did not run themselves, which leaves buyers comparing marketing numbers that were never independently checked.
Active checks that ask users to blink, turn, or repeat a phrase add friction exactly where abandonment is highest—and they are the checks generative video now defeats most easily.
Attack Coverage
Biometric authentication is only as strong as the attack classes it was trained against. Microblink pairs passive liveness with face-to-document cross-matching, so a session has to satisfy both that a live human is present and that the human matches the identity on a verified document. The Fraud Lab generates over 100,000 attack images a month, which means new techniques are modelled before they arrive in production traffic.
A printed photo, a mask, or a face replayed on another screen, held up to the camera.
Synthetic video fed through a virtual camera or the API itself, bypassing the physical lens entirely.
Generated or swapped faces built to pass as the document holder. Microblink scored 100% detection on the DHS-backed IDNet benchmark.
A real, unaltered ID presented by someone who is not its holder—caught by cross-matching the live face to the document portrait.
Where Biometric Authentication Belongs
Bind a new account to a real person at the moment it is created, not afterwards.
Add a face check to payouts, limit increases, and payment changes—only where risk warrants it.
Re-establish identity without routing users to a call centre or repeating full biometric KYC.
Confirm the same verified person when an account moves to unfamiliar hardware.
Re-confirm dormant or elevated-risk accounts against the identity originally enrolled.
Bind a new account to a real person at the moment it is created, not afterwards.
Add a face check to payouts, limit increases, and payment changes—only where risk warrants it.
Re-establish identity without routing users to a call centre or repeating full biometric KYC.
Confirm the same verified person when an account moves to unfamiliar hardware.
Re-confirm dormant or elevated-risk accounts against the identity originally enrolled.
Independently Tested
The Department of Homeland Security ran the most rigorous public evaluation of identity verification systems to date, measuring wrongful acceptances and wrongful rejections together. Microblink was the only system to meet every performance threshold, including a 0.00% system error rate. Every other system tested failed at least one.
IDNet is a DHS-backed benchmark built specifically to test whether a system can distinguish generated faces from real ones. Microblink detected 100% of deepfakes in that testing—the metric that matters most for biometric authentication, because a deepfake that clears liveness defeats everything downstream of it.
Models are only as current as the attacks they have seen. Microblink's in-house Fraud Lab generates more than 100,000 attack images a month—synthetic faces, swaps, injected video, and physical spoofs. New techniques are modelled and tested against before they show up in customer traffic, rather than after.
A World AI Cannes Festival Excellence Award for deepfake detection, and 2.9 billion identities processed across 195+ countries in 2025. Microblink builds its own models rather than reselling white-labelled technology, and powers verification for half the top providers in the Gartner 2024 IDV Magic Quadrant.
Vendor Evaluation
False accept and false reject rates from a vendor’s own lab are marketing. Ask which independent evaluation they entered and how they scored. Microblink met every threshold in the U.S. DHS RIVR evaluation.
“Liveness detection” describes a category, not a capability. Ask specifically about injection attacks and generated faces—not only printed photos and masks, which almost everything catches. See how the field compares on deepfake detection.
Biometric data carries the strictest handling rules of anything you collect. Ask whether processing can run on-device, what is retained, and which regional endpoints exist for markets with residency requirements.
False accept and false reject rates from a vendor’s own lab are marketing. Ask which independent evaluation they entered and how they scored. Microblink met every threshold in the U.S. DHS RIVR evaluation.
“Liveness detection” describes a category, not a capability. Ask specifically about injection attacks and generated faces—not only printed photos and masks, which almost everything catches. See how the field compares on deepfake detection.
Biometric data carries the strictest handling rules of anything you collect. Ask whether processing can run on-device, what is retained, and which regional endpoints exist for markets with residency requirements.
Quick and accurate ID verification, ensuring a seamless and secure registration process
Meet regulatory requirements with ID document verification and non-documentary signals
Verify identity and prevent unauthorized transactions through secure document scanning
Detect stolen or synthetic identities with precision and verify IDs to prevent fraudulent account creation and transactions
Ensure compliance and prevent underage access by instantly verifying customer ages through secure ID scanning
With 12 years of expertise in computer vision R&D, Microblink has been at the forefront of AI-driven identity verification, continuously innovating to deliver fast and accurate solutions.
We pioneered AI-driven identity verification, setting the standard for fast, secure, and accurate ID scanning solutions.
We develop our AI in-house, using proprietary data and a dedicated team of machine learning specialists to ensure unmatched accuracy and performance in identity verification.
Latest
Biometric authentication software confirms a person’s identity using a physical characteristic—most commonly their face—rather than something they know or carry. For remote identity verification it pairs a liveness check, which establishes that a real human is present, with a match against the portrait on a verified identity document.
Facial recognition with liveness detection is the practical choice for remote onboarding, because every smartphone and laptop already has a front-facing camera and users are familiar with the interaction. Fingerprint, iris, and voice are less suited to remote flows because they depend on hardware you cannot assume users have, or are easier to spoof at a distance.
A presentation attack shows something fake to the camera—a printed photo, a mask, a face replayed on a screen. An injection attack never reaches the camera at all, feeding synthetic video into the application through a virtual camera driver or the API. Many biometric systems handle the first and are blind to the second, so it is worth asking about each separately.
Ask for false accept and false reject rates from an evaluation the vendor did not run. Independent testing matters because the two error types trade against each other—any system can look accurate on one by sacrificing the other. Microblink was the only vendor to meet every threshold in the U.S. Department of Homeland Security’s RIVR evaluation, staying within limits on both simultaneously.
It depends on whether the liveness check is passive or active. Active checks ask users to blink, turn their head, or read a prompt, which adds time and drop-off. Passive liveness runs on a single capture with no instructions, so the user experience is unchanged from taking a selfie.
Handling varies significantly between vendors, and biometric data carries the strictest requirements of any personal data you collect. Microblink can process biometric checks entirely on-device, so face data never leaves the user’s handset, with regional cloud endpoints available where local residency rules apply.
AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.
See the Data