Glossary

Presentation attack

Also known as: Spoofing

A presentation attack, often called spoofing, is an attempt to fool an identity-verification system by presenting a fake or altered biometric trait, such as a face image, voice recording, fingerprint or mask, as if it belonged to a real user.

Presentation attacks target the point where a person provides a biometric sample to a camera, microphone, fingerprint reader or similar sensor. The attacker may use a printed photo, replayed video, synthetic voice, realistic mask or artificial fingerprint.

They are especially relevant to remote identity verification, where a service must determine whether a live person is present and whether the submitted biometric evidence is genuine. A presentation attack is not the same as stealing an account password or compromising a database.

Common examples

  • Holding a photograph or screen displaying a face in front of a selfie-verification camera.
  • Playing a recorded or AI-generated voice to pass voice authentication.
  • Using a fake fingerprint, such as a molded replica, against a fingerprint sensor.
  • Presenting a mask, prosthetic or other physical imitation of a face.

How systems address it

Identity-verification providers use presentation attack detection, often called PAD or liveness detection, to identify signs that the sample comes from a real, present person. Techniques can assess depth, motion, texture, reflections, challenge responses or sensor signals, depending on the biometric modality and device.

No control eliminates all spoofing risk. Organizations typically combine liveness checks with document verification, fraud monitoring, device and network signals, and review processes appropriate to the transaction's risk level.