Biometrics · · 2 min read
Active versus passive liveness
What challenge-response liveness checks, what passive and certified PAD add, and how to choose honestly for your risk.
Liveness detection answers one question: is the face in front of the camera a live person, or a photo, a screen, a mask or a synthetic video? There are two broad approaches, and they defend against different things.
Active liveness
Active liveness asks the person to do something a static image cannot: turn their head, smile, move closer. The server chooses the challenges at random, so a pre-recorded video is unlikely to show the right movements in the right order.
KYCVerify's liveness is active. For each attempt it issues 1 to 4 challenges from turn_left, turn_right, smile and move_closer, single-use and valid for 5 minutes, and checks:
- Order: a centre frame, then each challenge in the issued order.
- Movement: head yaw from five facial landmarks for turns, mouth-to-eye width ratio for a smile, face size for moving closer, each relative to the centre frame.
- Identity: every frame's face embedding compared with the centre frame, so a face swap mid-sequence fails.
- One face: a second significant face in any frame fails the attempt.
- Timing: increasing timestamps over a plausible span, and no identical frames under different labels (a replayed still).
frame 0 · center
baseline pose, size, embedding
frame 1 · turn_left
yaw left of the baseline
frame 2 · smile
mouth wider relative to eyes
frame 3 · move_closer
face larger than baseline
- Issued order, single-use challenge id, 5 minutes
- Same face in every frame (embedding vs centre)
- One significant face per frame
- Increasing timestamps, no duplicated frames
Passive liveness
Passive liveness analyses a single selfie or short clip for signs of a presentation attack (moiré from screens, paper texture, mask edges, depth cues) without asking the person to do anything. It is faster for the user, and the best passive models are trained on large sets of real attacks.
Certified PAD
ISO/IEC 30107-3 defines how presentation-attack detection is tested. Independent labs test vendors' products against attack instruments of increasing sophistication and publish conformance letters at levels such as 1, 2 and 3. A certification applies to the tested product, configuration and devices.
What each defends against
| Attack | Active challenge-response | Passive / certified PAD |
|---|---|---|
| Printed photo | Strong: cannot turn or smile | Strong |
| Photo on a screen | Strong | Strong |
| Pre-recorded video | Good: challenges are random | Varies |
| Silicone or 3D mask | Weak: masks can turn | Higher levels test for it |
| Real-time face swap or injection | Weak | Needs injection detection, a separate control |
Choosing for your risk
- For low and medium risk (marketplaces, age gates, HR), active liveness plus face match against the document is a reasonable bar.
- Raise it with more challenges, duplicate detection, AML screening and human review of borderline scores.
- Where a regulator or your risk model requires certified PAD or injection detection, use a certified provider for that step.