Glossary
Presentation attack detection (PAD) is the technical discipline of detecting attempts to fool a biometric system with a spoof (a printed photo, a screen replay, a mask, or a deepfake) presented to the sensor. Liveness detection is the best-known form of PAD; the term PAD is the formal, standardized name used in biometrics (defined in ISO/IEC 30107).
If liveness answers "is this a real, live person?", PAD is the broader engineering field around defeating every category of spoof, with a shared vocabulary for measuring how well a system does it.
PAD organizes spoofs by "presentation attack instrument" (the thing shown to the sensor:
Because "we detect spoofs" is easy to claim, PAD uses standardized metrics: the attack presentation classification error rate (how often a spoof is wrongly accepted) and the bona fide presentation classification error rate (how often a real person is wrongly rejected). Independent testing against these standards is how serious IDV providers substantiate their anti-spoofing claims rather than just asserting them.
Presentation and injection attacks are the primary way modern fraudsters attack biometric verification. As generative AI industrializes deepfakes and tooling emerges to inject them into capture flows, PAD has become one of the most important (and fastest-evolving) parts of identity verification. Strong, independently validated PAD is what stands between a bank’s onboarding and a wave of AI-generated impersonation. It’s a core component of trustworthy IDV, working alongside document verification and biometric matching.
PAD is inherently an arms race, and that framing matters for how you evaluate it. Every advance in detection prompts a new evasion, and every new spoofing technique prompts new detection. Printed photos gave way to screen replays, then to 3D masks, and now to AI-generated deepfakes and injection attacks that skip the camera entirely. A PAD system that tested well two years ago may be weak against today’s attacks, so PAD is never "done". It requires continuous retraining and updating against emerging techniques.
The practical implication is that PAD should be judged on current, independent testing rather than a one-time certification or a vendor’s assurance. Standardized metrics (how often spoofs slip through, how often real users are wrongly rejected) make comparison possible, and regular evaluation against the latest attack types is what separates PAD that holds up from PAD that looked good once. For a business relying on face verification, the freshness of a provider’s anti-spoofing is as important as its headline accuracy.
What is presentation attack detection?
The discipline of detecting spoofs (photos, masks, deepfakes) presented to a biometric system; liveness detection is a form of it.
What standard defines PAD?
ISO/IEC 30107, which also defines the metrics for measuring it.
How is PAD different from liveness detection?
Liveness is a common form of PAD; PAD is the broader, standardized field covering all spoof types and their measurement.
Related: Liveness Detection · Deepfakes · Identity Verification (IDV) · Face Authentication · Document Verification