Liveness (face & palm)
Liveness detection — also called presentation attack detection (PAD) — verifies that a captured face or palm comes from a live subject present at the sensor, not a spoof (printed photo, mask, or replayed video). It is the security gate of any biometric workflow — recognition and unattended enrollment alike.
The Innovatrics SDKs implement the passive approach to liveness: no user action (blink, smile, head turn) is required — a single capture is scored.
How it works
Liveness typically runs before template extraction and matching, so a spoofed input is never extracted or matched. Depending on the integration it can also run after matching — for example a screening scenario that first identifies a subject and only then spoof-checks the probe. See the security note in Identification (1:N).
Modalities
| Modality | SDK(s) | Notes |
|---|---|---|
| Face | SFE Toolkit (on-device) · Biometric Identification Service (server) | Operating point chosen for the capture framing (distant kiosk/turnstile vs close-range handheld). |
| Palm | SFE Toolkit (on-device) · Biometric Identification Service (server) | On-device palm liveness has narrower platform coverage than face. |
On the server, passive liveness is available for both face and palm as an add-on.
SFE Toolkit implementation
On the SFE Toolkit, passive liveness maps to a capability per modality:
| Modality | SFE Toolkit capability |
|---|---|
| Face | Face Liveness |
| Palm | Palm Liveness |
Iris has no passive liveness in the SFE Toolkit.
Enrollment SDK implementation
On the Enrollment SDK, passive liveness maps to a function for the face modality:
| Modality | Enrollment SDK function |
|---|---|
| Face | FaceExecutor::GetPassiveLivenessFast / GetPassiveLivenessAccurate |
Iris and fingerprint have no liveness in the Enrollment SDK — face only. Full signatures: API Reference.
What it covers
Passive liveness addresses presentation attacks — a fake presented to the sensor. Coverage and maturity differ between face and palm, so they are documented and tuned separately.
Face
The attack types covered by Innovatrics passive face liveness detection
- Screen replay — faces presented to the camera on a screen.
- Printed faces — faces printed on paper presented to the camera.
- 2D masks — faces printed on cardboard with cutouts, worn over a person's face.
- 3D masks — silicone masks, dolls, and mannequins.
Palm
The attack types covered by Innovatrics passive palm liveness detection:
- Screen replay — palms presented to the camera on a screen.
- Printed palms — palms printed on paper presented to the camera.
- Photographs — a photograph of a palm presented to the camera.
Not covered (face and palm)
Passive liveness does not cover attacks on the capture channel or synthetic imagery: video injection (man-in-the-middle) and deepfakes / synthetic faces.
Key considerations
- Run liveness before matching by default — abort on failure; never extract or match a spoofed probe. Some integrations deliberately run it after matching instead (e.g. screening against a watchlist first) — make this an explicit design decision, not an accident.
- Match the operating point to capture conditions — camera distance, attended vs unattended; the right threshold depends on how the subject presents.
- No single global threshold — liveness scoring is model-specific; tune to your target FMR/FNMR on representative data.
- Use IR capture where the threat model includes 2D presentation attacks. A phone or tablet screen, or a printed photo, under IR illumination reflects the IR light rather than returning a face-like response — so the detector finds no face and ends the pipeline before liveness or extraction even run. Genuine skin, by contrast, reflects IR characteristically and is detected normally.
Related pages
- Identification (1:N) and Verification (1:1) (liveness is their security check)
- Enrollment