SpoofSense Logo

SpoofSense Face

Deepfake detection built for identity verification.

Face swaps, GenAI faces and reenactment attacks are now cheap enough for everyday fraud. SpoofSense screens every selfie with pixel-level artifact analysis — passively, in the same API call as liveness and injection checks — so an AI-generated face never becomes an approved identity.

The basics

What is deepfake detection?

Deepfake detection determines whether a face in an image or video was generated or manipulated by AI. Generative models — face swap tools, diffusion models, real-time reenactment — can now produce faces that pass human review and defeat challenge-based verification. Detection works by finding what generators can't hide: statistical fingerprints, frequency-domain artifacts and physical inconsistencies that AI-generated imagery leaves behind at the pixel level.

In identity flows, deepfake detection is not a standalone tool — it is one layer of a defense that also needs face liveness detection against physical spoofs and injection attack detection against the virtual cameras used to deliver deepfakes. SpoofSense runs all three on every frame, in one call.

Know your enemy

The four deepfake attacks hitting identity flows.

Face swaps

A target's face is transplanted onto another person's head in real time — the classic identity-fraud deepfake used against KYC selfie checks.

Synthetic faces

Fully AI-generated faces from GAN and diffusion models, used to create synthetic identities that match no real human.

Reenactment

A real photo is animated — puppeteered — to blink, smile and turn on command, defeating challenge-based active liveness.

Digital manipulation

Attribute edits, morphs and partial manipulations that blend real and generated content to evade both humans and naive detectors.

Why legacy checks fail

You can't out-challenge a deepfake.

Active liveness — blink, smile, turn your head — assumes an attacker can't make a fake face perform. Real-time reenactment broke that assumption: a deepfake can now follow any challenge as naturally as a live user. The face passes the test because the test measures behavior, not authenticity.

Effective deepfake defense inspects how the image itself was formed, and whether the capture pipeline was tampered with. That's why SpoofSense is passive: instead of asking the face to prove itself, we interrogate the pixels and the stream. Genuine users do nothing; synthetic faces have nowhere to hide.

Our research team publishes openly on the hardest problem in this field — detecting fakes from generators never seen in training. Read the latest: Detecting What You've Never Seen: OOD Robustness in Forgery Detection.

How it works

Deepfake screening in one API call.

01

Capture

A single face image arrives from your onboarding or authentication flow via our Web SDK, Mobile SDKs, or REST API.

02

Screen

Pixel-level artifact analysis checks for GenAI fingerprints while PAD and injection screening validate the capture itself.

03

Decide

You get one decision covering deepfakes, spoofs and injection — ready to gate approval or trigger step-up.

Trust

Certified foundations. Research-grade detection.

SpoofSense is iBeta Level 1 and Level 2 compliant per ISO/IEC 30107-3, and our deepfake models are stress-tested against out-of-distribution generators — the attacks that don't exist in any training set yet. Documents need the same defense: SpoofSense DocLive catches portrait tampering and forged IDs during document capture.

FAQ

Deepfake detection, answered.

What is deepfake detection?

Deepfake detection is the analysis of an image or video to determine whether the face in it was generated or manipulated by AI — including face swaps, reenactment (puppeteering), and fully synthetic faces from GAN or diffusion models. In identity verification, it decides whether a selfie shows a real person or an AI-generated imitation.

How does SpoofSense detect deepfakes?

SpoofSense screens each face image with pixel-level artifact analysis that looks for the generation fingerprints AI models leave behind, alongside presentation attack detection and injection attack screening. All checks run passively on a single frame through one REST API call.

Why do deepfakes bypass traditional liveness checks?

Traditional active liveness relies on challenges like blinking or head turns — actions modern deepfakes can perform convincingly in real time. Catching them requires analyzing how the image was made, not what the face does, and verifying the integrity of the capture pipeline against injection.

Can deepfakes be injected without a camera?

Yes. Attackers commonly pair deepfakes with digital injection — using virtual cameras or emulators to feed the synthetic video directly into the verification flow. That is why SpoofSense combines deepfake screening with injection attack detection in the same check.

Which industries need deepfake detection?

Any flow where a face establishes trust: fintech and banking onboarding, KYC and identity verification providers, account recovery, high-risk transaction approval, and marketplaces verifying real users.

How accurate is deepfake detection on new, unseen generators?

Generalizing to generators never seen in training — out-of-distribution robustness — is the core research problem in deepfake detection. SpoofSense Research publishes its OOD robustness testing methodology and results openly on our blog.

Screen your first selfie for deepfakes today.

Start free — 100 credits →