Skip to content
Verify
All posts
Security·· 15 min read

A threat model for liveness attacks in 2026

The attacks our red team rehearses, the ones we’ve seen in the wild, and the ones we expect next.

By Dr. Kenji Mori

A threat model for liveness attacks

Liveness attacks split into four broad classes: replay (re-presenting valid biometric data), masking (3D printed faces or silicone masks), injection (compromising the device camera), and synthesis (generating a real-time deepfake feed).

The threat surface has shifted hard toward injection and synthesis over the last 12 months. Replay attacks, by contrast, are now solved at the hardware-attestation layer for anyone willing to enforce it.

#liveness#deepfake#fraud