Deepfake injection attacks are rising. See how deepfake detection works in KYC: passive versus active liveness, and why active is now an attack surface.
Table of contents
- Deepfake detection in KYC has moved from a nice-to-have to a core control, as generative video and voice tools make convincing synthetic identities cheap to produce.
- Passive liveness analyses what the camera captures, texture, depth cues, and micro-movement, without asking the user to perform an action.
- Active liveness uses challenge-response, asking the user to turn, blink, or smile, and it has itself become an attack surface for injected deepfake video.
- The crucial distinction is presentation attack versus injection attack: ISO/IEC 30107-3 defines presentation attacks, while injection attacks bypass the camera entirely by feeding a synthetic stream.
- Threat intelligence from vendors and law enforcement reports sharp rises in deepfake and injection-based fraud, so detection must address both attack types, not just spoofed photos.
- No single liveness method is sufficient alone; layered detection plus device and signal integrity is the defensible standard.
Deepfake detection in KYC is the set of techniques that confirm an identity verification is a genuine, live person rather than an AI-generated face, a replayed video, or an injected synthetic feed. It combines passive and active liveness with defences against injection attacks, and it has become central to identity verification as generative video and voice tools rapidly improve.
TL;DR
Deepfake detection in KYC is now a core control, not an add-on, because generative AI has made convincing synthetic faces, videos, and voices cheap and fast to produce, and threat reports from vendors and law enforcement describe steep rises in deepfake-enabled fraud and injection attacks. The verification question has shifted from is this a real document to is this a real, live human.
The two defences are passive liveness, which analyses what the camera captures without user action, and active liveness, which asks the user to perform a challenge. The critical and underappreciated distinction is between a presentation attack, showing a fake to the camera, and an injection attack, bypassing the camera to feed a synthetic stream directly, which ISO/IEC 30107-3 frames for presentation attacks specifically. This guide explains both liveness types, both attack types, why active liveness became a target, the 2026 landscape, and how to defend.
11 min read. Last updated 7 October 2026.
What is deepfake detection in KYC?
Deepfake detection in KYC is the layer of an identity verification flow that confirms the face being verified belongs to a real, live person present at the time, rather than an AI-generated or manipulated artifact. It sits on top of document verification: even a genuine document is worthless if the selfie matched to it is a deepfake of the document's owner or an entirely synthetic face.
The discipline has two jobs. First, liveness, confirming a live human is present and not a photo, mask, screen replay, or generated video. Second, integrity, confirming the captured feed actually came from the device's camera and was not injected. As generative tools improve, both jobs get harder, which is why deepfake detection has become a defining feature of strong identity verification software rather than a checkbox.
What is the difference between passive and active liveness?
The two liveness approaches answer the live-human question differently. Passive liveness analyses the captured image or video for signals that distinguish a real person from a spoof, texture and skin detail, depth and three-dimensional cues, lighting consistency, and subtle natural micro-movement, without asking the user to do anything. The user simply presents their face, and the system judges authenticity in the background.
Active liveness uses challenge-response: the system asks the user to perform an unpredictable action, turn their head, blink, smile, or follow a prompt, and confirms the response matches. Active liveness was long considered stronger because the challenge is hard to pre-record, but as the next sections explain, injected deepfake video has turned the challenge into a target. In practice, modern deepfake detection in KYC uses passive liveness as the low-friction default and may add active or other signals based on risk, the friction-versus-security balance that shapes onboarding completion, as in perpetual KYC.
What is the difference between a presentation attack and an injection attack?
This distinction is the heart of modern deepfake detection, and most teams under-weight the second. A presentation attack is when an attacker presents a fake artifact to the camera, a printed photo, a mask, a screen showing a video, or a deepfake played on another device held up to the lens. ISO/IEC 30107-3 is the international standard that defines and frames testing for presentation attack detection, or PAD, and reputable liveness vendors test against it.
An injection attack is different and more dangerous: the attacker bypasses the physical camera entirely, using a virtual camera or compromised software to feed a synthetic video stream, a deepfake, directly into the verification pipeline. Because nothing is physically presented to a real lens, presentation-attack detection alone may not catch it. Defending against injection requires device and signal-integrity checks, confirming the feed genuinely originates from the device's hardware camera, not a virtual one. Conflating the two, and assuming PAD covers injection, is the gap deepfake fraudsters exploit.
Why has active liveness become an attack surface?
Active liveness was designed on the assumption that an attacker could not respond, live, to an unpredictable challenge. Generative video broke that assumption. With real-time or near-real-time deepfake tools, an attacker can drive a synthetic face that turns, blinks, and smiles on command, and inject that responsive deepfake into the pipeline, satisfying the challenge with a fake that does exactly what was asked.
So the very interactivity that made active liveness strong now provides a script the deepfake can follow. This does not make active liveness useless, but it means a challenge-response on its own is no longer proof of a live human, and it must be paired with injection detection and passive signals. The lesson for deepfake detection in KYC is that no single method is durable against improving generative models; layered detection is the only defensible posture, which is the same theme as why your KYC vendor is your biggest data breach risk: single points of reliance fail.
How serious is the 2026 deepfake landscape?
The threat is escalating quickly. Identity-verification threat-intelligence reports, including from biometric vendors such as iProov, have described sharp year-on-year increases in deepfake and injection-based attacks, and law-enforcement bodies including the FBI's Internet Crime Complaint Center have flagged record fraud losses with a growing AI-enabled component. The capability driving this is the leap in generative video and voice quality: synthetic faces that hold up under scrutiny, and voice clones produced from seconds of audio.
The practical consequence is that verification flows built for the pre-deepfake era, document plus a basic selfie, are increasingly exposed. Attackers no longer need a stolen physical document and a lookalike; they can generate a synthetic identity or animate a stolen one. That shifts deepfake detection in KYC from an optional enhancement to a baseline requirement, and it raises the bar from spoof detection to injection-aware, layered liveness.
How do you defend KYC against deepfakes?
A defensible deepfake detection approach layers several controls rather than betting on one. Use passive liveness for low-friction authenticity analysis on every verification. Add injection detection that confirms the feed originates from the device's real camera, not a virtual or injected source, because this is where modern deepfakes attack. Treat active liveness as one signal among several, not as standalone proof. Capture the verification in a controlled way, some systems capture multiple frames themselves rather than accepting a user upload, which removes the easiest injection vector of an uploaded file.
Zyphe's verification reflects this: it reads the NFC chip from the document for a cryptographically strong identity anchor, applies a two-step biometric liveness check combining passive micro-movement detection with an active consistency check, and does not allow image upload during verification, capturing the photos itself instead. Removing the upload path and anchoring on the chip closes common deepfake and injection vectors at the source, and pairing detection with strong document binding is more robust than liveness alone. Test your stack against ISO/IEC 30107-3 for presentation attacks and against injection scenarios specifically.
When does liveness alone not protect you?
Liveness is necessary but not sufficient, and assuming it is the whole answer is the mistake. Liveness confirms a live human, but it does not, on its own, confirm that the human is the right person or that the feed was not injected. A perfect live human can be an impostor using a stolen identity, which is why liveness must be bound to a verified document and biometric match, not used in isolation.
Liveness also does not address the upstream problem of where identity data is stored after verification: defeating a deepfake at onboarding does not help if the verified identities then sit in a breachable central store that an attacker can steal and reuse. So deepfake detection is one layer in a chain that includes document binding, injection detection, and secure, ideally decentralised, storage of the result. Relying on any single layer, liveness included, is the gap. The defensible posture is layered detection plus strong binding plus minimal data retention. To stress-test your flow against deepfakes and injection, book a walk-through.
The bottom line
Deepfake detection in KYC has crossed from optional to essential, because generative video and voice have made synthetic and animated identities cheap, and the attack has moved from showing a fake to the camera to injecting one past it. Passive and active liveness each play a role, but active liveness alone is now a target, and presentation-attack detection does not cover injection.
The durable defence is layered: passive liveness, injection and device-integrity checks, active liveness as one signal, strong binding to a chip-verified document, and capturing the image rather than accepting an upload. Test against ISO/IEC 30107-3 and against injection scenarios, and remember liveness is one link in a chain that ends with how securely you store the result.
Book a deepfake and injection walk-through, or see how it works.
Related resources
- Identity verification software comparison 2026
- Perpetual KYC: from photograph to video
- Why your KYC vendor is your biggest data breach risk
- L1 alert triage with AI
- Decentralised KYC
- KYC software
- Proof of address verification
Cited sources
- ISO/IEC 30107-3, biometric presentation attack detection: https://www.iso.org/standard/79520.html
- FBI Internet Crime Complaint Center (IC3) annual reports: https://www.ic3.gov/
- iProov, Threat Intelligence on deepfakes and injection attacks: https://www.iproov.com/
- NIST, biometrics and presentation attack detection research: https://www.nist.gov/programs-projects/face-recognition-vendor-test-frvt
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.