Skip to content

Biometrics · · 2 min read

Active versus passive liveness

What challenge-response liveness checks, what passive and certified PAD add, and how to choose honestly for your risk.

Liveness detection answers one question: is the face in front of the camera a live person, or a photo, a screen, a mask or a synthetic video? There are two broad approaches, and they defend against different things.

Active liveness

Active liveness asks the person to do something a static image cannot: turn their head, smile, move closer. The server chooses the challenges at random, so a pre-recorded video is unlikely to show the right movements in the right order.

KYCVerify's liveness is active. For each attempt it issues 1 to 4 challenges from turn_left, turn_right, smile and move_closer, single-use and valid for 5 minutes, and checks:

  • Order: a centre frame, then each challenge in the issued order.
  • Movement: head yaw from five facial landmarks for turns, mouth-to-eye width ratio for a smile, face size for moving closer, each relative to the centre frame.
  • Identity: every frame's face embedding compared with the centre frame, so a face swap mid-sequence fails.
  • One face: a second significant face in any frame fails the attempt.
  • Timing: increasing timestamps over a plausible span, and no identical frames under different labels (a replayed still).
  1. frame 0 · center

    baseline pose, size, embedding

  2. frame 1 · turn_left

    yaw left of the baseline

  3. frame 2 · smile

    mouth wider relative to eyes

  4. frame 3 · move_closer

    face larger than baseline

  • Issued order, single-use challenge id, 5 minutes
  • Same face in every frame (embedding vs centre)
  • One significant face per frame
  • Increasing timestamps, no duplicated frames
One attempt with three challenges. Each frame is labelled and timestamped by the browser and checked on the server.

Passive liveness

Passive liveness analyses a single selfie or short clip for signs of a presentation attack (moiré from screens, paper texture, mask edges, depth cues) without asking the person to do anything. It is faster for the user, and the best passive models are trained on large sets of real attacks.

Certified PAD

ISO/IEC 30107-3 defines how presentation-attack detection is tested. Independent labs test vendors' products against attack instruments of increasing sophistication and publish conformance letters at levels such as 1, 2 and 3. A certification applies to the tested product, configuration and devices.

What each defends against

AttackActive challenge-responsePassive / certified PAD
Printed photoStrong: cannot turn or smileStrong
Photo on a screenStrongStrong
Pre-recorded videoGood: challenges are randomVaries
Silicone or 3D maskWeak: masks can turnHigher levels test for it
Real-time face swap or injectionWeakNeeds injection detection, a separate control

Choosing for your risk

  • For low and medium risk (marketplaces, age gates, HR), active liveness plus face match against the document is a reasonable bar.
  • Raise it with more challenges, duplicate detection, AML screening and human review of borderline scores.
  • Where a regulator or your risk model requires certified PAD or injection detection, use a certified provider for that step.

See it working on your own data.

Every guide describes code you can run in the sandbox today.