SpoofSense Logo

SpoofSense Face

Injection attack detection: defend the pipeline, not just the camera.

The most dangerous spoof never touches your camera. Virtual cameras, emulators and intercepted streams inject deepfakes directly into the verification flow — invisible to liveness checks that only watch the lens. SpoofSense flags injected media passively, on every frame, in the same API call as liveness and deepfake screening.

The basics

What is a biometric injection attack?

In a biometric injection attack, the fraudster never shows anything to a camera. Instead, they insert fake media — usually a deepfake — directly into the software capture pipeline, using a virtual camera, a device emulator, a tampered app, or by intercepting the network request itself. The verification system receives what looks like a normal camera feed showing a live, genuine face.

This is what makes injection the blind spot of traditional anti-spoofing. Presentation attack detection examines the face in the frame; injection attacks compromise how the frame got there. A verification stack that only runs PAD will confidently approve a deepfake delivered through a virtual camera.

Injection attack detection (IAD) closes that gap by verifying the integrity of the capture itself — and it now has its own standard, CEN/TS 18099, dedicated to biometric data injection attack detection.

Know the difference

Presentation attacks vs. injection attacks.

Presentation attackInjection attack
Where the fake entersIn front of a real cameraInside the software pipeline — no camera involved
Typical instrumentsPrinted photos, screens, 2D/3D masksVirtual cameras, emulators, intercepted APIs
Defended byPresentation attack detection (PAD)Injection attack detection (IAD)
Governing standardISO/IEC 30107-3CEN/TS 18099
Typical payloadPhysical artifact of a faceDeepfake or replayed digital video

Attack vectors

Four ways fake media gets injected.

Virtual cameras

Software cameras (OBS-style tools and browser plugins) that replay or stream synthetic video as if it came from real hardware.

Emulators & modified apps

Device emulators and tampered mobile apps that fabricate the entire capture environment, sensor data included.

API & network interception

Man-in-the-middle manipulation that swaps genuine capture payloads for fraudulent media after the camera, before the check.

Hardware injection

HDMI-to-USB capture devices that present an external video source to the operating system as a physical webcam.

How it works

Injected streams leave fingerprints.

A genuine capture carries the signature of physical hardware. Injection breaks that signature in ways software can detect.

01

Source integrity

Virtual camera drivers, emulators and tampered capture environments expose signatures real devices don't produce.

02

Stream forensics

Injected media carries image statistics and capture metadata inconsistent with a physical sensor's output.

03

Combined decision

Injection signals are fused with liveness and deepfake screening into one decision per frame — one API call, no user friction.

Defense in depth

Liveness defends the camera. IAD defends the pipeline.

No single check stops modern identity fraud. SpoofSense layers certified passive liveness (iBeta Level 1 & 2, ISO/IEC 30107-3), deepfake detection and injection screening on every frame — and DocLive extends the same protection to ID documents, where injection attacks target document capture.

FAQ

Injection attack detection, answered.

What is a digital injection attack?

A digital injection attack bypasses the camera entirely: instead of presenting a fake face to the lens, the attacker feeds pre-made or synthetic video directly into the software capture pipeline — using virtual cameras, emulators, modified apps or network interception — so the verification system receives media that no camera ever captured.

How is an injection attack different from a presentation attack?

A presentation attack shows something fake to a real camera — a printed photo, a screen replay, a mask. An injection attack skips the camera and inserts fake media into the data stream itself. Presentation attack detection (PAD) cannot see injection, because from the software's view a perfectly normal 'camera feed' arrived.

How does injection attack detection work?

Injection attack detection (IAD) verifies the integrity of the capture pipeline. Injected streams leave traces genuine captures don't: virtual camera and driver signatures, emulator fingerprints, inconsistent capture metadata, and image statistics that don't match a physical sensor. SpoofSense screens for these signals passively on every frame.

Why are injection attacks growing?

Because deepfakes made them worthwhile. A convincing synthetic face is easy to generate but hard to physically present to a camera — so fraudsters inject it instead. Virtual camera software is free, and off-the-shelf tools now bundle deepfake generation with injection delivery.

Is there a standard for injection attack detection?

Yes — CEN/TS 18099, 'Biometric data injection attack detection,' is the first standard dedicated to IAD, covering injection attack instruments, detection systems and test methodology. It complements ISO/IEC 30107-3, which governs presentation attack detection.

Do I need both liveness detection and injection attack detection?

Yes. Liveness defends the camera, deepfake detection defends the image, and injection attack detection defends the pipeline. An attacker only needs one unguarded layer. SpoofSense runs all three checks together on every frame, in a single API call.

Close the injection blind spot today.

Start free — 100 credits →