Blog

Deepfake Detection vs Liveness Detection vs Injection Attack Detection: What Each Stops (and Misses)

Sandy Kronenberg

Sandy Kronenberg

Chief Executive Officer

Published: September 30, 2026

Liveness vs deepfake vs injection attack detection: attacks stopped at three gates, with a few passing through every layer
TL;DR
  • Deepfake detection asks whether media is synthetic or manipulated. It catches AI faces and cloned voices, but can miss high quality fakes and says nothing about who is really on the other end.

  • Liveness detection (presentation attack detection) asks whether a real, live person is in front of the sensor. It stops photos, masks and screen replays, but can be bypassed when a deepfake is fed straight into the data stream.

  • Injection attack detection asks whether the camera or microphone feed is genuine. It stops virtual cameras, emulators and hooked apps, but does not judge whether the content itself is fake.

  • In the deepfake vs liveness detection debate, the answer is not either/or. Gartner recommends combining presentation attack detection, injection attack detection and image inspection, plus device and behavioral signals.

  • For live calls and meetings, where there is no selfie check at all, deepfake detection plus device and metadata signals is the main defense.

What is deepfake detection, liveness detection and injection attack detection?

Keep the three-sentence definition paragraph exactly where it is, since that's your snippet target, and keep the table under it. Adding a separate "What is" section above it would duplicate the same content twice in the first 300 words, which costs you more than the inconsistent heading does.

If you want the comparison framing preserved, split it: "What is deepfake detection, liveness detection and injection attack detection?" for the definitions, then "Which control stops which attack" for the table. But that's only worth doing if you actually have distinct content for each, and right now you don't.

Key Takeaways

  • checkmark

    The three controls answer three different questions: is the media fake, is a live person present, and did the media really come from the sensor.

  • checkmark

    Liveness stops physical spoofs and misses injected deepfakes. A synthetic face fed through a virtual camera never presents to the sensor, so there is nothing for PAD to reject.

  • checkmark

    Injection attack detection proves the pipe is genuine, not that the person in it is. A deepfake played to a real webcam passes IAD.

  • checkmark

    Deepfake detection is the only one of the three that protects live calls and meetings, where no liveness check is run at all.

  • checkmark

    None of the three catches a real person committing fraud. Device, behavioral and relationship signals fill that gap.

  • checkmark

    Each has a standard except deepfake detection. ISO/IEC 30107-3 covers PAD, CEN/TS 18099 covers IAD, and NIST SP 800-63-4 now folds in injection attack and forged media controls.

  • checkmark

    The layering is settled, not a debate. Use all three at onboarding and login, then run deepfake detection with device and metadata signals on every conversation after.

In This Article

Deepfake vs liveness detection

Deepfake detection determines whether audio, video or images were generated or altered by AI. Liveness detection determines whether a real, physically present person is interacting with a camera or microphone at that moment. Injection attack detection determines whether the media reached the system through a genuine sensor or was inserted digitally.

Each control answers a different question, so each stops a different attack and misses others:

Control

Question it answers

Primary attack it stops

Deepfake detection

Is this media synthetic or manipulated?

AI generated faces, voices and images

Liveness detection (PAD)

Is a live human in front of the sensor?

Printed photos, masks, screen replays

Injection attack detection (IAD)

Did this media really come from the camera or mic?

Virtual cameras, emulators, stream tampering

These terms matter most in identity proofing and authentication, the workflows NIST's SP 800-63-4 now addresses with controls for injection attacks and forged media.

Deepfake detection: what it stops and what it misses

Deepfake detection analyzes the content of media for traces of AI generation or manipulation, such as face swap boundaries, unnatural blinking, lip sync errors, spectral artifacts in cloned voices, and generator fingerprints.

What deepfake detection stops

  • Face swaps and synthetic avatars on video calls.

  • Cloned voices on phone calls and voicemail.

  • AI generated or edited images, IDs and documents.

  • Deepfakes delivered through channels with no liveness check at all, such as Zoom, Teams and phone calls.

What deepfake detection misses

  • New generators. The US GAO warns that detection may not work reliably in real world conditions and that newer models are expected to remove today's tells.

  • Degraded media. Compression, low light and phone codecs strip the artifacts detectors look for.

  • Real people with bad intent. A genuine face used by a fraudster, or a money mule on camera, is not a deepfake.

  • Identity. Detection says whether content looks fake, not who the person is. Netarx covers this gap in Video deepfake detection isn't enough.

To see deepfake detection that also weighs device and metadata signals, explore the Netarx platform.

Liveness detection: what it stops and what it misses

Liveness detection, formally called presentation attack detection (PAD), checks that a live human is physically in front of the camera or microphone during a biometric check. It is tested against ISO/IEC 30107-3, the international standard for evaluating PAD mechanisms, now in its 2023 edition.

Passive liveness analyzes a single image or short clip for depth, texture and light reflection. Active liveness asks the user to blink, turn their head or follow a prompt.

What liveness detection stops

  • Printed photos and cut-out masks held up to the camera

  • Replays of a video on another screen

  • Silicone and 3D masks, depending on the tested level

  • Recorded voice played back to a voice biometric system

What liveness detection misses

  • Injected deepfakes. If an attacker feeds a synthetic face directly into the data stream through a virtual camera, the sensor never sees a presentation to reject. Gartner notes that current PAD standards and testing do not cover digital injection attacks that use AI generated deepfakes.

  • Real time face reenactment. Deepfake tools that respond to active prompts can pass blink and head turn challenges.

  • Everything after onboarding. Liveness runs at a checkpoint, such as account opening or login. It does not protect the video call, phone call or chat that follows.

Injection attack detection: what it stops and what it misses

Injection attack detection (IAD) verifies that audio or video really came from a physical camera or microphone on a genuine device, and was not inserted into the data flow. Attackers use it to skip the sensor entirely, which is why a perfect liveness score can still be a fraud.

Injection attacks are growing fast. Gartner reported that injection attacks increased 200% in 2023. In response, Europe published CEN/TS 18099, a technical specification for evaluating biometric data injection attack detection, which covers attacks that bypass the sensor through virtual cameras or smartphone emulators.

What injection attack detection stops

  • Virtual camera software that replaces the webcam feed with a deepfake

  • Emulators and rooted or jailbroken devices that fake a phone camera

  • Hooked or tampered apps that swap frames in memory

  • Replayed or modified streams sent directly to an API

What injection attack detection misses

  • Deepfakes shown to a real camera. A synthetic face played on a high quality screen in front of a genuine webcam passes IAD; that is PAD's job.

  • Content quality. IAD confirms the pipe is genuine, not that the person or voice in it is.

  • Channels it cannot instrument. On an inbound phone call or a third party meeting, you may not control the attacker's device, so you rely on network, caller and metadata signals instead.

Side by side: which control stops which attack

No single control covers every attack; each one closes a gap the others leave open.

Attack

Deepfake detection

Liveness detection (PAD)

Injection attack detection (IAD)

Printed photo or mask at onboarding

Partial

Stops

Misses

Video replay on a second screen

Partial

Stops

Misses

Deepfake fed through a virtual camera

Stops if artifacts remain

Misses

Stops

Deepfake played to a real camera

Stops if artifacts remain

Partial

Misses

Emulator or tampered app

Misses

Misses

Stops

Face swap on a live Zoom or Teams call

Stops

Not applied

Rarely applied

Cloned voice on an inbound phone call

Stops

Not applied

Not applied

Real person committing fraud (mule)

Misses

Misses

Misses

Where it is typically used

Calls, meetings, files, messaging

Onboarding, login, KYC

Onboarding, login, KYC

Relevant standard

None dominant yet

ISO/IEC 30107-3

CEN/TS 18099

The mule row is the reminder that media checks alone never prove intent. Device, behavioral and relationship signals fill that gap.

Where each control sits in the attack path

Liveness guards the sensor, injection attack detection guards the device and stream, and deepfake detection judges the content that arrives.

A spoof shown to the camera meets liveness first. An injected feed skips the camera, so only injection attack detection and deepfake detection stand in its way.

How to layer them, and where Netarx fits

Layer the three controls at onboarding, then keep verifying identity in every conversation after it. Gartner predicted that by 2026, 30% of enterprises would no longer consider identity verification and authentication reliable in isolation because of deepfakes, and advised combining PAD, IAD and image inspection with device identification and behavioral analytics.

  1. At onboarding and login: require PAD tested to ISO/IEC 30107-3 and IAD evaluated against CEN/TS 18099, plus document and image inspection.

  2. On every call, meeting and message: run deepfake detection on live media, because most enterprise impersonation happens here, where no liveness check exists.

  3. Across both: weigh device fingerprints, caller metadata and behavior, which do not change when the attacker upgrades their face or voice model.

  4. For high risk requests: require out of band verification for payments, credential resets and data exports.

Netarx covers steps 2 and 3. The Netarx platform analyzes live video on Zoom, Teams, Meet and Webex, phone calls and texts, email and files, and fuses media analysis with over 1,000 metadata signals and multiple inference models. Tiers of Identity builds verified trust in each contact over time, which helps where liveness and IAD do not reach. For the standards context, read Netarx's guide to NIST SP 800-63-4 and deepfakes, or explore solutions for banking, financial services and compliance teams.

SOURCES & REFERENCES

sandy

Sandy Kronenberg

VerifiedVerified

Chief Executive Officer

CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.

LinkedIn

Not sure how your defenses would hold up against a real-time deepfake?

Frequently Asked Questions

Deepfake detection checks whether media was created or altered by AI. Liveness detection checks whether a real, live person is physically present at the sensor. A deepfake injected through a virtual camera can pass liveness, and a real photo held up to a camera is not a deepfake, so each misses what the other catches.