ZealiD Blog

Injection Attacks vs Liveness Checks: What Remote Identity Proofing Must Prove

Written by Tomas Zuoza | Jun 19, 2023

Last updated: 16 September 2026

 

If you are evaluating a remote identity verification provider, the question "do you have liveness detection?" no longer separates one vendor from another. Injection attacks bypass the camera entirely, so a liveness check that analyses the captured image cannot see them. Since February 2025 there has been a written specification for what a remote identity proofing service must actually do, and it is the standard your provider should be answering against.

Key Takeaways

  • A presentation attack shows a fake to a real camera. An injection attack feeds synthetic video directly into the verification pipeline, so no physical scene is ever captured.
  • Injection attacks overtook presentation attacks as the leading vector in 2024 and rose a further 40% year on year in 2025.
  • ETSI TS 119 461 V2.1.1 (February 2025) sets policy and security requirements for identity proofing and adds Extended LoIP alongside Baseline.
  • The useful procurement question is not whether a provider does liveness, but which Level of Identity Proofing, which use case, and which operation mode it is assessed against.
  • ZealiD's own practice statement publishes all three: unattended remote proofing, hybrid manual and automated operation, Extended LoIP.

What Is an Injection Attack, and How Does It Differ From a Presentation Attack?

A presentation attack puts something fake in front of a genuine camera: a printed photograph, a mask, a screen replaying a video. An injection attack skips the camera. The attacker feeds manipulated media straight into the verification flow, so the system receives a stream that never corresponded to anything physical in front of a lens.

The delivery paths are well documented. A virtual camera driver presents any video source to the operating system as though it were a webcam. On mobile, an attacker can run the onboarding app inside an emulator mapped to the host's virtual camera, root the device and hook the camera API to return frames from a file, or substitute the media payload in transit between the app and the backend. MITRE's ATLAS knowledge base carries this as a documented case study, AML.CS0033, "Live Deepfake Image Injection to Evade Mobile KYC Verification".

This is no longer only a security-research concern. The US Financial Crimes Enforcement Network's alert on deepfake media targeting financial institutions (FIN-2024-Alert004) names the technique directly, noting that identity verification solutions may flag attempts to circumvent verification checks "such as the use of third-party webcam plugins, which can let a customer display previously generated video rather than live video." A customer using a webcam plugin during a live verification check appears in the alert's list of red flag indicators, alongside a customer who repeatedly reports technical glitches and asks to switch communication methods mid-check.

The distinction matters because it decides what can possibly detect the attack. A liveness algorithm reasons about the content of an image. An injection attack is a statement about that image's origin. No amount of improvement to the first will answer the second.

ZealiD's CPO Tomas Zuoza described both variants at an ENISA workshop on remote video identification: "I'd highlight two types of AI-powered injection attacks here. The first one targets liveness checks as fraudsters project someone else's face onto their own. The second type is more common and targets documents, usually by altering their validity period or projecting security features when they're not actually there."

How Common Are Injection Attacks Now?

When this article was first published in 2023, the reference point was a 295% rise in video injection attacks over six months. That figure now understates the problem by an order of magnitude.

Entrust's 2026 Identity Fraud Report, drawn from over a billion identity verifications, puts injection attacks up 40% year on year, with deepfakes accounting for roughly one in five biometric fraud attempts. iProov recorded a 741% annual increase in iOS-targeted injection attacks across 2025. The World Economic Forum's Cybercrime Atlas, published in January 2026, tested seventeen face-swapping tools and eight camera injection tools and found that most defeated standard biometric onboarding checks.

These are vendor and consortium telemetry rather than regulatory statistics, and they are not directly comparable to one another. The direction is not in dispute. FATF's Horizon Scan on AI and deepfakes, published in December 2025, names deepfakes as a direct threat to anti-money-laundering and customer due diligence controls worldwide.

What Does ETSI TS 119 461 Actually Require?

This is the change that matters, and it is the reason the 2023 framing no longer holds. ETSI TS 119 461 sets policy and security requirements for the identity proofing component of a trust service. Version 2.1.1, published in February 2025, extended the standard from Baseline to include Extended LoIP, broadly tracking the move from eIDAS to eIDAS 2.

The standard does three things a buyer can use. It classifies identity proofing into defined use cases: physical presence, attended remote with a registration officer in real-time contact, unattended remote with no human supervision, use of an existing eID, and use of a digital signature. It splits each into manual, hybrid manual and automated, and fully automated operation. And it requires the party performing identity proofing to meet the operational security requirements of ETSI EN 319 401, so the proofing component inherits trust-service-grade obligations rather than sitting outside them.

That gives a procurement team something better than a marketing claim to compare. The table below sets out what each control can and cannot establish.

 

Control Catches presentation attacks Catches injection attacks Why
Passive liveness on the captured image Yes No It reasons about the content of the image, not where the image came from.
Device and capture-path attestation Partly Yes Detects virtual cameras, emulators and hooked camera APIs, which is where injection happens.
NFC read of the document chip Yes Yes Chip data is cryptographically signed by the issuing state, so it cannot be synthesised or projected.
Registration Officer review (hybrid operation) Yes Yes Catches novel patterns no model has been trained on yet, and feeds them back into detection.
Fully automated decision Depends Depends Only as strong as the signals behind it. Safe at the highest match confidence, exposed below it.

Why Fully Automated Verification Is Not Enough

Tomas made the case for automation plainly: "As long as we define a certain strategy or approach that fraudsters use, we can establish an algorithm to detect those attempts. In such cases, automated checks are extremely effective and can identify even the most subtle traces of video injection that would be invisible to the human eye."

The limit is definitional. An algorithm detects the strategies it has been given. "Algorithms detect patterns, and humans do a much better job at detecting unusual, new attempts to commit fraud. Besides, having a manual element in our identity verification process allows us to collect data and identify new, emerging patterns," he notes.

In 2023 that was an opinion. It is now a documented operating practice, which is what a buyer should be looking for. As a Qualified Trust Service Provider on the EU Trusted List, ZealiD publishes its Trusted Registration Authority Practice Statement, and it states the position precisely: the service supports unattended remote identity proofing with hybrid and manual operation, performed according to ETSI TS 119 461 for the Extended LoIP, conforming to eIDAS Article 24(1)(c) and confirmed by a conformity assessment body.

Two operational details in that document are worth more than the claim itself. Automated binding of the applicant's face to the identity document returns one of seven confidence levels, and only the highest of them may be used for a fully automated decision. Below that threshold a Registration Officer makes the final call, using everything available in the system including the facial photograph extracted from the NFC chip. And Registration Officers are trained, as an audited requirement, on the detection of presentation and injection attacks specifically.

That is the shape of an answer a procurement team can actually test. A vendor that cannot say which of these applies to its own service is describing a product, not a proofing method.

What Happens When the Check Passes and the Identity Was Never Real

The failure mode here is unusually unkind, because a successful injection attack does not look like a failure. The document validated. The biometric matched. Liveness passed. The audit trail records a clean verification, which is exactly what makes the problem hard to find later.

FinCEN documented exactly this pattern from Bank Secrecy Act reporting. Its finding is worth reading literally: "Beyond account opening, financial institutions detected deepfake identity documents through enhanced due diligence on accounts that exhibited separate indicators of suspicious activity." The onboarding check did not catch it. The account opened, money moved, and an unrelated review surfaced the problem afterwards. The same analysis notes that institutions often find synthetic content in identity documents only by re-reviewing account opening documents after the fact.

For a regulated firm this is worse than an ordinary control gap. You cannot demonstrate to a supervisor that a verification was sound when the only evidence you hold is the verification's own clean result. That is the same reproducibility problem that runs through what happens when you cannot prove who signed a document, arriving from the identity side rather than the signature side.

What to Ask an Identity Provider Before You Rely on Their Liveness Check

Four questions, all of which a provider operating under TS 119 461 can answer from a published document:

  • Which Level of Identity Proofing are you assessed against, Baseline or Extended? Extended is the tier aligned to eIDAS 2. If the answer is neither, the provider is not working to the standard at all.
  • Which use case and operation mode applies to our volume? Unattended remote with fully automated operation is a different risk position from hybrid manual and automated, and a provider should say which one our transactions will receive.
  • What detects the capture path, as opposed to the image? If the answer is only liveness, injection attacks are out of scope by construction. NFC chip reads and device attestation are the controls that speak to origin.
  • Are your human reviewers trained on injection attack detection, and is that auditable? A hybrid process is only as good as what the reviewer has been taught to look for.

As the power and accessibility of the underlying technology keep growing, new attack types will keep arriving. Recording changes in fraud patterns as they happen has been the constant in this cat-and-mouse game for decades, and Tomas's read has held up: "I don't see the industry moving to a single data proofing method anytime soon." What has changed since 2023 is that there is now a standard to measure the answer against, which means a buyer no longer has to take anybody's word for it. For a wider view of where this is heading, see our outlook on identity safety and fraud in 2030.

References

  • ETSI TS 119 461 V2.1.1, "Electronic Signatures and Trust Infrastructures: Policy and security requirements for trust service components providing identity proofing." ETSI, February 2025. etsi.org
  • ETSI EN 319 401, "General Policy Requirements for Trust Service Providers." ETSI. etsi.org
  • Regulation (EU) No 910/2014 (eIDAS), Article 24(1)(c). European Union, 2014. eur-lex.europa.eu
  • MITRE ATLAS, case study AML.CS0033, "Live Deepfake Image Injection to Evade Mobile KYC Verification." October 2024. atlas.mitre.org
  • Financial Crimes Enforcement Network. "FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions," FIN-2024-Alert004. FinCEN, 13 November 2024. fincen.gov
  • Financial Action Task Force. "Horizon Scan: artificial intelligence and deepfakes." FATF, December 2025. fatf-gafi.org