What is presentation attack detection, and why does it matter for exam proctoring?
TL;DR: Presentation attack detection (PAD) is the standardized way biometric systems test whether a face or identity check can be fooled by a photo, video replay, mask, or deepfake — governed by ISO/IEC 30107. For exam and interview proctoring, PAD is what separates "we checked a selfie against an ID" from "we verified a live human is actually present," and it's the technical backbone behind deepfake and virtual-camera detection claims.
The claim
Any identity-verification system that only compares a photo to an ID is vulnerable to being shown a printed photo, a replayed video, or a deepfake instead of a live person — PAD is the discipline of testing and rating how well a system resists exactly that.
The evidence
- ISO/IEC 30107-1 defines the core framework for biometric presentation attack detection; ISO/IEC 30107-3 defines the testing and reporting methodology used to measure PAD performance.
- Independent test labs like iBeta are NIST-accredited to conduct PAD conformance testing, issuing Level 1 and Level 2 confirmation letters that vendors can point to as third-party proof of anti-spoofing performance.
- The key PAD metric, Attack Presentation Classification Error Rate (commonly summarized via the Attack Presentation Acceptance Rate, or APAR), quantifies how often a spoofed presentation is incorrectly accepted as genuine — a lower rate means stronger security.
- Industry explainers (Didit, Innovatrics, Biometrics Institute) consistently describe deepfakes, printed photos, video replays, and 3D masks as the attack categories PAD is specifically designed to catch — the exact threat model exam and interview proctoring cares about.
- Neuroxa's identity layer — ID + selfie match, continuous face verification, and deepfake/virtual-camera flags — is functionally a PAD implementation applied to the exam and interview use case, even where the term itself doesn't appear in marketing copy.
Comparison: identity checks without PAD vs. with PAD
| Approach | Photo-vs-ID comparison only | With presentation attack detection |
|---|---|---|
| Stops a printed photo held up to camera | No | Yes |
| Stops a pre-recorded video replay | No | Often, with liveness checks |
| Stops a real-time deepfake face swap | No | Partially — this is the hardest attack category |
| Independently testable/certifiable | Not standardized | Yes — ISO/IEC 30107-3, iBeta conformance letters |
| Confidence level for a defensible trust report | Low | High — testable claims, not just marketing language |
Step-by-step: evaluating a proctoring vendor's PAD claims
- Ask directly whether the vendor's liveness/deepfake detection has been independently tested against ISO/IEC 30107-3, not just internally validated.
- Request the specific PAD conformance level (e.g., iBeta Level 1 or Level 2) if independent testing exists.
- Ask which attack categories are covered — printed photo, video replay, 3D mask, and real-time deepfake are each a different technical challenge.
- Confirm the PAD check runs continuously through the session, not just at check-in — a one-time liveness check doesn't stop a mid-session swap.
- Make sure PAD results feed into your trust report as evidence, not just a pass/fail gate at login.
FAQ
Is PAD the same thing as facial recognition? No — facial recognition asks "whose face is this?" PAD asks "is this a live human face at all, or a spoof?" They're complementary, not the same check.
Does Neuroxa have independent PAD certification? Neuroxa's identity layer is built around continuous face verification and deepfake/virtual-camera detection functionally aligned with PAD principles; ask your account team for current third-party testing status specific to your deployment.
What's the hardest presentation attack to detect? Real-time deepfakes — face-swap software that generates a convincing live video feed — are widely considered the toughest attack category, harder than static photos or simple video replays.
Why does a lower APAR matter in practice? A lower Attack Presentation Acceptance Rate means fewer spoofed sessions get incorrectly accepted as genuine — directly reducing the risk of a fraudulently obtained certification or a proxy interview going undetected.
Should every proctoring vendor be required to publish PAD test results? It's a reasonable ask for high-stakes use cases (professional licensing, hiring for sensitive roles) — third-party PAD conformance is a stronger claim than unverified marketing language about "deepfake detection."
By Pinal Dave Last updated: 2026-07-31