Skip to content

Passive vs active liveness: which attack each one stops

The two approaches to liveness are not interchangeable. Here is how each works, the attacks it closes, and how to choose for your integration.

Dilshod RasulovLead biometrics engineer
In this article

In short

  • Active liveness asks for a gesture and costs conversion; passive liveness is invisible but puts more weight on the model.
  • The attack class matters: printed photos, screen replays, masks and deepfakes are each caught by a different signal.
  • In practice a hybrid flow wins: passive by default, active only when the score looks weak.

A face recognition model can be flawless and still worthless if what stands in front of the camera is a photo on a phone screen rather than a living person. That makes liveness, not recognition, the most fragile part of a biometric flow.

Two approaches, two different costs

Active liveness asks the user for a specific action: turn your head, blink, follow a dot on screen. Passive liveness asks for nothing — it analyses frame texture, light distribution, depth cues and micro-movement.

  • Active: harder for an attacker, but every extra step costs 4–9% of users during enrolment.
  • Passive: completes in 1.2 seconds on average and stays completely invisible to the user.
  • Hybrid: passive runs first, and the active step is requested only when the confidence score is low.

99.6%

Liveness accuracy

1.2s

Average check time

4

Attack classes covered

40M+

Attempts verified

Which attack hits which barrier

It helps to split presentation attacks into four classes. Each class is caught by a different signal, which is exactly why no single model closes all of them.

  • Printed photo: paper texture and the way light reflects are immediately visible to a passive model.
  • Screen replay: moire patterns, frame rate and display brightness give it away.
  • Silicone mask: it is the absence of micro-expression, not a depth map, that reports the problem.
  • Deepfake stream: this needs camera-level attestation plus temporal consistency analysis.

The liveness question is not «is this person alive?». It is this: did the signal from the camera come from a real person, in real time?

RS-ID biometric core team

What to choose for your integration

If your flow is mass enrolment, start passive — conversion decides here. If the flow carries real risk, such as a large transfer or signing a document, making the active step mandatory pays for itself.

One identity layer for your entire product

Talk to our team to choose the right integration for your product — Mobile SDK, Web SDK, Backend API, or a combination of all three.