In a biometric injection attack, the fraudster never shows anything to a camera. Instead, they insert fake media — usually a deepfake — directly into the software capture pipeline, using a virtual camera, a device emulator, a tampered app, or by intercepting the network request itself. The verification system receives what looks like a normal camera feed showing a live, genuine face.
This is what makes injection the blind spot of traditional anti-spoofing. Presentation attack detection examines the face in the frame; injection attacks compromise how the frame got there. A verification stack that only runs PAD will confidently approve a deepfake delivered through a virtual camera.
Injection attack detection (IAD) closes that gap by verifying the integrity of the capture itself — and it now has its own standard, CEN/TS 18099, dedicated to biometric data injection attack detection.