News/Resources/KYC/KYC Liveness Detection: How Active, Passive, and PAD Checks Work

KYC Liveness Detection: How Active, Passive, and PAD Checks Work

KYC Liveness Detection: How Active, Passive, and PAD Checks Work

Digital KYC systems often rely on a selfie match against an identity document, but a match alone does not confirm a real person is present. Fraudsters can use photos, replayed videos, masks and deepfakes to bypass basic checks, making KYC liveness detection a critical layer in modern identity verification.

Liveness detection in KYC determines whether the biometric sample comes from a live user at the moment of capture. This distinction is essential as online identity fraud continues to rise, driven by synthetic identities and spoofing attacks.

Presentation attack detection (PAD) extends this protection by identifying attempts to manipulate biometric systems using physical or digital artefacts. Active and passive liveness detection methods approach this challenge differently, but both aim to ensure the same outcome: a genuine user is physically present during verification. This guide breaks down how these methods work, the attacks they defend against, and how they fit into a complete KYC workflow.

Binderr KYC Liveness Detection Software 

The best KYC liveness detection software should go beyond classifying a selfie as live or suspicious by linking results with document checks, face matching, fraud signals and risk-based decisions.

Binderr includes liveness detection within a full KYC workflow, helping businesses confirm a customer is present, match their face to their ID, and detect fraud before onboarding.

  • Active, passive, and hybrid liveness options for risk-based security
  • Strong PAD to detect photos, replays, masks, and spoofing
  • Deepfake detection for AI-generated or altered faces
  • Biometric face matching between selfie and ID document
  • Real-time fraud signals to flag suspicious onboarding
  • Global ID verification across multiple documents and countries

What Is Liveness Detection in KYC?

Liveness detection in KYC is a biometric security process that checks whether a selfie or facial scan comes from a real, physically present person rather than a spoof such as a photo, video replay, mask, or deepfake. It works alongside identity document verification and facial matching to add an anti-spoofing layer that detects presentation attacks and confirms genuine user presence during onboarding. 

By combining active or passive liveness detection with PAD (presentation attack detection), KYC systems help reduce fraud and support secure remote onboarding across fintech, banking and crypto platforms.

Verify Identities With Confidence

How Liveness Detection Fits Into KYC Identity Verification

Liveness detection is a critical step in modern KYC workflows that ensures the person completing verification is physically present and not using spoofed or synthetic media.

It works alongside document verification and facial matching to strengthen identity assurance and reduce fraud during digital onboarding.

Key points to understand its role in the KYC process:

  • It acts as a separate security layer that confirms the user is a real, live person at the time of capture, not just a static image or recorded video.
  • It is performed during the selfie or facial capture stage, typically before or alongside face matching against the identity document.
  • It helps detect presentation attacks such as printed photos, screen replays, masks, or other attempts to impersonate a genuine user.
  • It complements document verification, which checks whether the ID is authentic, by ensuring the person presenting it is physically present.
  • It enhances facial matching accuracy by ensuring the biometric sample being compared is genuinely live and not artificially generated or replayed.
  • It contributes to a risk-based KYC decision, where liveness results are combined with other signals like document checks, device data, and AML screening to determine overall trustworthiness.

Streamline the KYC Liveness Detection Process with Binderr

Managing document checks, facial matching, liveness analysis and fraud detection across separate tools creates fragmented workflows, forcing compliance teams to switch systems and manually build a final customer risk profile.

Binderr connects these steps within one KYC process.

  • Identity document checks to confirm passports, IDs and licences are genuine
  • Biometric face matching between selfie and ID photo
  • Active and passive liveness detection to confirm real user presence
  • Presentation attack detection (PAD) to spot spoofing attempts
  • Automated fraud analysis across document, biometric and behaviour data
  • Centralised results and audit trails for compliance review and reporting

What Is Active Liveness Detection?

Active liveness detection asks the user to perform actions during facial capture, such as blinking, turning the head or following on-screen prompts. The system then checks whether the responses are real-time, correctly timed and consistent with the instructions. 

This helps prevent spoofing attempts like photo replay, video injection or mask attacks by introducing unpredictable challenges that only a live person can complete, making it an important layer in biometric identity verification and anti-spoofing technology within modern onboarding flows.

How Active Liveness Works

Active liveness detection uses a challenge-response flow to confirm a real person is physically present during KYC verification. Unlike passive methods, it requires the user to actively participate, making it common in high-security onboarding like banking, fintech, and crypto platforms.

The process typically works as follows:

  1. The system generates a challenge - The user is given a random prompt such as blinking, smiling, turning their head, or following a moving dot. These unpredictable challenges help prevent spoofing with photos or pre-recorded videos.
  2. The user performs the action - The user responds in real time using facial movements, making it difficult for fraudsters to reuse static or recorded content.
  3. The camera captures the response - A short video or frame sequence is recorded, along with signals like lighting, depth, and facial landmarks.
  4. The system analyses the response - Algorithms check timing, motion, and facial consistency to detect signs of spoofing, replay attacks, or synthetic input.
  5. The result is classified - The outcome is marked as genuine, suspicious, or inconclusive. Suspicious or unclear cases may trigger retries or manual review.

Randomised prompts make it harder to bypass the system, as recommended in security guidance like NIST for stronger identity proofing.

Overall, active liveness adds a strong security layer in KYC by ensuring the user is physically present and responding in real time.

What Is Passive Liveness Detection?

Passive liveness detection is a biometric check in KYC that runs in the background while a user simply takes a selfie or short video, without any prompts or required actions. It uses AI and computer vision to analyse facial texture, depth, lighting, motion, and spoofing signals to confirm whether the image comes from a real, physically present person rather than a photo, screen replay, mask, or deepfake. 

Because it requires no user interaction, passive liveness enables faster, smoother identity verification and is widely used in modern KYC onboarding to reduce friction while maintaining strong anti-spoofing protection.

How Passive Liveness Detection Works

Passive liveness detection works by analysing a selfie or short facial capture in real time without requiring the user to perform any specific action or follow a challenge. Instead of asking for movements or responses, the system evaluates the biometric data as it is being captured to determine whether it originates from a live person physically present at the camera.

The process typically works as follows:

  1. The user takes a standard selfie or short video during onboarding, usually guided by on-screen instructions to ensure proper framing, lighting, and focus.
  2. The system then captures multiple facial frames and associated image data in real time, often selecting the highest-quality frames for analysis while discarding blurred or incomplete captures.
  3. AI models analyse subtle visual, spatial, and sometimes behavioural cues within the image stream, such as facial texture, depth information, micro-movements, and lighting consistency.
  4. The system also evaluates the capture for inconsistencies commonly associated with spoofing attempts, including signs of screen replays, printed photographs, masks, or digitally manipulated media.
  5. Based on this analysis, a liveness score or classification is generated, such as “live,” “suspicious,” or “inconclusive,” sometimes accompanied by a confidence level or risk indicator.
  6. Finally, the liveness result is combined with other KYC signals such as document verification, identity data checks, and face matching to produce a final verification decision or trigger further review if needed.

Unlike active methods, passive liveness does not interrupt the user experience with prompts or instructions. This makes it suitable for high-volume onboarding flows where speed and conversion rates are important.

However, passive liveness still relies on sophisticated pattern recognition to distinguish real human presence from spoofing attempts such as printed photos, screen replays, or digitally generated faces. Its effectiveness depends on the quality of the model, the diversity of training data, and the range of attack types it has been evaluated against.

Start Secure Identity Checks

Active vs Passive Liveness Detection

Not all liveness detection checks work the same, some challenge the user, while others quietly analyse the selfie in the background.

Understanding the difference between active vs passive liveness detection is key to balancing security, user experience, and fraud prevention in modern KYC flows, especially when combined with presentation attack detection systems that protect against spoofing attempts.

Factor

Active Liveness

Passive Liveness

Customer action

Requires a movement or response

Usually no deliberate action

Typical capture

Guided video or movement sequence

Selfie or short background capture

User experience

More visible and interactive

Faster and less disruptive

Onboarding friction

Generally higher

Generally lower

Replay resistance

Improved when prompts are random

Depends on media and artefact analysis

Accessibility

Challenges may exclude some users

Fewer physical actions required

Customer awareness

User knows a security test is occurring

Analysis may happen in the background

Main weakness

Predictable or poorly designed challenges

Dependence on algorithm and capture quality

Common use

Higher-risk or stepped-up verification

Routine, high-volume onboarding

Best approach

Risk-based or combined deployment

Risk-based or combined deployment

Faster KYC Starts Here

What Is Presentation Attack Detection?

Presentation Attack Detection (PAD) is a biometric security layer that identifies attempts to fool a system using fake inputs such as printed photos, screen replays, masks, or deepfakes. In KYC liveness detection workflows, PAD acts as the broader anti-spoofing layer that detects presentation attack instruments interfering with biometric capture, making it a core part of modern identity verification security.

While liveness detection confirms a real, live person is present, PAD goes further by analysing artefacts, injection attempts, and abnormal signals across the capture process. According to NIST, PAD is the automated detection of a presentation attack, making it the umbrella framework that includes liveness detection within biometric security and strengthening overall presentation attack detection capabilities in KYC systems.

Detect More Than Basic Photo Spoofing

Common Spoofing and Presentation Attacks

Fraudsters don’t always need advanced tools to bypass identity checks, they often rely on simple visual tricks that mimic a real user during onboarding.

Understanding these spoofing and presentation attack methods is essential for building stronger KYC liveness detection and biometric fraud prevention systems, especially when comparing active vs passive liveness approaches in real-world onboarding environments.

Printed Photo Attacks - Printed photo attacks occur when a fraudster holds a physical image of a legitimate user in front of the camera to bypass KYC liveness checks. These spoofing attempts often use high-quality prints, but biometric liveness detection can flag them through flat facial depth, visible paper edges, unnatural texture, glare, and the lack of natural micro-movements.

Screen and Digital Photo Attacks - Screen-based spoofing uses a phone, tablet, or monitor to display a victim’s face during verification. Liveness detection systems can detect these attacks by identifying screen edges, pixel patterns, reflection artefacts, flicker effects, and moiré distortions that indicate a digital display rather than a live person.

Video Replay Attacks - Video replay attacks use pre-recorded footage of a real user to simulate live interaction. Anti-spoofing systems counter this using random challenge prompts, timing checks, replay pattern detection, and media integrity analysis to spot mismatches between expected live responses and recorded content.

Mask and 3D Artefact Attacks - Mask attacks involve physical objects like paper masks, printed overlays, silicone replicas, or 3D face models used to impersonate someone. PAD systems detect these by analysing depth inconsistencies, rigid materials, edge flaws, and the absence of natural skin movement and micro-expressions.

Deepfake Presentation Attacks - Deepfake attacks use AI-generated or manipulated facial videos shown to a camera during onboarding. Liveness and deepfake detection models identify them through irregular facial motion, blending artefacts, lighting inconsistencies, and unstable frame-to-frame behaviour.

Digital Injection Attacks - Digital injection attacks bypass the camera by feeding fake biometric data directly into the system using virtual cameras, emulators, or compromised devices. NIST defines them as untrusted media injected into the biometric pipeline, requiring controls like device attestation, virtual camera detection, and secure channels alongside PAD. ENISA also classifies them as a major identity fraud threat.

Detect More Than Basic Photo Spoofing with Binderr

Modern identity fraud goes beyond printed photos and includes screen replays, prerecorded videos, masks, synthetic faces, deepfakes, and other capture manipulation attempts.

Binderr combines liveness detection with additional identity and fraud signals to strengthen customer verification.

  • Detects advanced spoofing attempts beyond basic photo-based fraud
  • Identifies screen replays, video injections and prerecorded facial captures
  • Flags synthetic identities and deepfake-generated facial inputs
  • Combines liveness detection with biometric face matching for stronger assurance
  • Uses multi-signal fraud analysis instead of relying on a single check
  • Helps compliance teams reduce false approvals and improve onboarding accuracy

ISO/IEC 30107 and PAD Testing Standards

ISO/IEC 30107 standards help buyers objectively evaluate presentation attack detection (PAD) claims by defining how biometric systems should be tested, measured, and reported against spoofing threats like photos, videos, masks, and deepfakes. 

These standards are essential for comparing KYC liveness detection solutions in a consistent, audit-ready way.

ISO/IEC 30107-1

ISO/IEC 30107-1 establishes the foundational framework, terminology, and concepts for biometric presentation attack detection (PAD), clearly defining what constitutes a presentation attack, a bona fide sample, and a presentation attack instrument. 

It ensures that terms like liveness detection, anti-spoofing, and biometric authentication are used consistently across vendors, regulators, and KYC systems, making it easier for buyers to understand what level of protection a solution actually provides.

ISO/IEC 30107-3

ISO/IEC 30107-3:2023 defines how PAD systems are scientifically evaluated, including test methodologies, performance benchmarking, reporting standards, and classification of attack types such as printed photos, replayed videos, masks, and digital injection attempts. It ensures that liveness detection in KYC is not just marketing-driven but validated through repeatable testing frameworks that measure real-world resistance to spoofing and biometric fraud.

PAD Performance Metrics

PAD performance is measured using key biometric security metrics that balance fraud prevention and user experience. APCER (Attack Presentation Classification Error Rate) shows how often spoof attempts are wrongly accepted as real users, while BPCER (Bona Fide Presentation Classification Error Rate) measures how often genuine users are incorrectly flagged as fraud, impacting onboarding friction. 

IAPAR (Impostor Attack Presentation Accept Rate) evaluates system-level vulnerability to successful spoof acceptance, while FMR/FAR (False Match/Acceptance Rate) tracks incorrect identity matches, and FNMR/FRR (False Non-Match/Reject Rate) measures legitimate user rejections, together defining the real-world reliability of biometric liveness detection systems.

Relevant NIST Guidance

NIST SP 800-63-4 strengthens the importance of PAD compliance in facial recognition KYC systems, requiring presentation attack resistance as part of digital identity proofing. It recommends maintaining an IAPAR below 0.07 and mandates that PAD systems be evaluated using ISO/IEC 30107-3 testing standards, ensuring that biometric onboarding solutions can reliably resist spoofing, deepfakes, and injection-based attacks while maintaining secure and user-friendly identity verification workflows.

Build Trust With Standardised KYC Checks

How to Choose the Right Liveness Detection Approach (Active, Passive or Hybrid)

Choosing the right liveness detection approach is a balance between security strength, user experience and fraud risk tolerance.

Understanding when to use active vs passive liveness or a hybrid model can significantly improve onboarding success and fraud prevention within modern KYC workflows that rely on presentation attack detection to stop spoofing attempts.

Assess the Onboarding Risk

Risk-based KYC liveness detection starts with understanding what is at stake during onboarding. High-value accounts, regulated industries, and cross-border users demand stronger biometric identity verification because fraud impact scales with exposure. A fintech onboarding a low-risk wallet user does not need the same active liveness detection depth as a bank opening credit lines or issuing lending products.

Evaluate Customer Friction

Every extra step in active or passive liveness detection affects completion rates. Long capture times, repeated selfie attempts, or unclear instructions increase abandonment and reduce successful KYC conversion. Studies show that nearly 40 percent of users drop off during complex identity verification flows, making friction a direct business risk in biometric onboarding.

Review Attack Coverage

Modern presentation attack detection must go beyond simple photo spoofing. Fraudsters now use deepfake videos, virtual cameras, injected media streams, and 3D masks to bypass facial liveness detection systems. A strong KYC liveness detection setup should be tested across printed photos, replay attacks, emulated devices, and compromised environments to ensure real-world resilience.

Use Step-Up Verification

A layered identity verification strategy improves both security and user experience. Passive liveness detection can handle low-risk onboarding, while active liveness or hybrid checks add stronger assurance when risk signals increase. High-risk or inconclusive cases should escalate to manual review or attended verification, ensuring biometric identity verification adapts to context rather than applying a single rigid flow.

Do Not Ignore Injection Attacks

Presentation attack detection alone is not enough in modern KYC systems. Attackers can bypass camera-based checks entirely through virtual cameras, SDK manipulation, or direct media injection into the verification pipeline. NIST guidance highlights the need to combine liveness detection with device integrity checks, emulator detection, secure transmission, and server-side fraud analysis to defend against both physical and digital injection threats.

A complete presentation attack detection strategy must therefore extend beyond visible spoofing and include system-level protections that support both active and passive liveness models.

Best Practices for Implementing KYC Liveness Detection

Strong identity verification starts with ensuring the person behind the screen is real, present, and not a spoof.

By combining smart liveness strategies with layered fraud controls, businesses can significantly reduce onboarding risk while keeping user experience smooth.

Combine liveness with document and face matching

Liveness detection should always be used alongside identity document verification and biometric face matching to create a complete KYC identity verification flow. While liveness confirms that a real person is physically present during capture, document checks validate authenticity and face matching confirms identity consistency. Together, these controls reduce the risk of spoofing, identity fraud and presentation attack detection failures in biometric onboarding.

Use risk-based step-up checks instead of a fixed flow

A risk-based approach to KYC liveness detection applies stronger verification steps only when needed, rather than forcing every user through the same process. 

Low-risk users may complete passive liveness checks, while higher-risk cases can trigger active liveness detection or additional PAD checks. This improves onboarding efficiency while maintaining strong fraud prevention and compliance coverage, especially when managing active vs passive liveness decisions at scale.

Randomise prompts to prevent replay attacks

Randomised challenges in active liveness detection help prevent replay attacks where fraudsters use pre-recorded videos or scripted responses. By changing instructions such as head movements or facial actions each time, the system makes it harder to predict or reuse captured content. This strengthens presentation attack detection and improves resistance to spoofing attempts across both active and passive liveness flows.

Test both user experience and attack resistance

Effective biometric liveness detection must balance security with usability by evaluating both user experience and fraud resistance. Testing should measure completion rates, false rejections and onboarding friction alongside performance against spoofing techniques like photo, video replay and deepfake attacks. 

This ensures the KYC process remains secure without negatively impacting legitimate users, regardless of whether active vs passive liveness is used.

Evaluate across devices, lighting and user groups

Liveness detection performance should be assessed across a wide range of real-world conditions, including different devices, camera qualities, lighting environments and demographic groups. 

Variations in these factors can affect biometric capture quality and liveness accuracy. Comprehensive testing helps ensure consistent KYC verification performance and reduces bias or failure rates in production, strengthening overall presentation attack detection reliability.

Separate presentation and injection attack controls

Presentation attack detection focuses on identifying physical spoofing attempts such as printed photos, masks or screen replays, while injection attack controls address manipulation within the digital capture pipeline. 

These include virtual cameras, emulators and media injection techniques. Treating them separately ensures stronger biometric security and more complete protection in liveness detection systems, whether using active or passive methods.

Give clear capture instructions without exposing detection logic 

Users should receive simple and clear guidance during selfie or video capture to improve success rates in liveness verification. Instructions like proper lighting, face positioning and camera stability help reduce failed attempts. 

However, the system should not reveal how liveness detection or PAD checks work internally, as this could help attackers bypass biometric security controls and weaken presentation attack detection effectiveness.

Build a Complete Compliance Workflow With Binderr

Liveness detection is one part of identity verification, but businesses still need to verify identity documents, screen for financial crime risk, assign a risk score, and complete due diligence.

Binderr brings these compliance capabilities together in one platform.

  • Unified onboarding workflow: Manage KYC, KYB, AML and risk in one connected process.
  • Automated identity verification: Verify users with document checks, OCR, face matching and liveness detection.
  • Integrated AML screening: Screen against sanctions, PEPs, watchlists and adverse media.
  • Dynamic risk scoring engine: Automatically update customer risk based on multiple signals.
  • Built-in due diligence workflows (CDD & EDD): Trigger standard or enhanced checks based on risk level.
  • Ongoing monitoring and audit readiness: Continuously monitor customers and maintain full audit trails.

Bottom Line

Liveness detection plays a critical role in modern KYC by ensuring a real, physically present user is completing biometric verification, helping prevent spoofing attempts such as photos, videos, masks, and deepfakes. Active methods use user challenges, while passive methods run in the background, and organisations often evaluate active vs passive liveness depending on risk, friction and fraud exposure.

For effective KYC and AML compliance, liveness detection should be combined with presentation attack detection, identity document verification, face matching, device checks, and risk-based screening.

Binderr Services connects liveness detection with AI-powered document verification, biometric face matching, AML screening and dynamic risk scoring. Businesses can create a free account, access free credits and test a complete KYC workflow without a credit card or mandatory sales call.

Start free. Upgrade when ready.

FAQs - Liveness Detection in KYC

Is liveness detection the same as PAD?

Is liveness detection the same as face matching?

Can liveness detection detect deepfakes?

Can passive liveness detect a photograph?

Is active liveness more secure than passive liveness?

What do APCER and BPCER mean?

Is liveness detection required for KYC?

Can liveness detection replace identity document verification?

What happens when a customer fails a liveness check?

Mohammad Humaid

Article written byMohammad Humaid

Mo leads marketing and growth at Binderr, where he’s building a global marketplace that connects businesses with trusted partners and corporate service providers. Previously, Mo contributed to the growth of leading brands such as Wise (formerly TransferWise), Revolut and Binance, driving their expansion across Europe and APAC region. With a background spanning Fintech, Blockchain, Web3 and SaaS, Mo focuses on building brands that scale globally with compliance, trust and transparency.