stile

iBeta PAD

iBeta PAD Level 1 and Level 2 are laboratory testing methodologies for presentation-attack detection evaluated under ISO/IEC 30107-3. Level 2 gives the attacker more time, expertise, and artifact budget than Level 1; a result applies only to the tested configuration.

iBeta PAD Level 1 and Level 2 are lab test methodologies for evaluating how a biometric presentation-attack-detection (PAD) mechanism responds to attacks at the capture device. They are applied within ISO/IEC 30107-3:2023, which defines principles, performance assessment, and reporting for PAD testing. The standard does not define a specific liveness product or provide a blanket vendor certification.

Level 1 models a lower-effort attacker: iBeta's current methodology allows up to eight hours per subject or attack species, requires no prior expertise, limits artifacts to equipment readily available in a home or office, and caps material cost at $30. Its current limit is 0% penetration or match rate.

Level 2 raises the effort: two to four days per subject or species, moderate PAD-testing experience and knowledge of the target, equipment such as 3D printers or resin and latex masks, and up to $300 in materials. Its current allowable penetration or match rate is 1%.

These levels describe test conditions, not a universal security grade. A confirmation letter applies to the product, software and backend versions, capture device, operating system, decision threshold, and other configuration recorded for that test. iBeta explicitly says its testing indicates conformance with the ISO testing and reporting requirements and does not itself certify an entire vendor or every deployment.

The scope is also narrow. ISO/IEC 30107-3 covers presentation attacks delivered at the biometric capture device. Camera-bypass injection through a virtual camera, emulator, tampered application, or substituted media feed is outside that scope. So are a general system-security or vulnerability assessment, biometric matching accuracy or demographic-bias evaluation, and organizational controls such as SOC 2.

Amazon Rekognition Face Liveness is a useful sourced example of why configuration details matter. iBeta's public Level 1 letter reports 0% APCER across 900 attacks for Amazon Rekognition Face Liveness v1.0 with backend component 3.4.15.0, a 50% liveness threshold, and a Samsung Galaxy S21 running Android 12. The Level 2 letter reports 0% APCER across 750 attacks for the stated tested configuration.

How Stile uses liveness detection

Stile includes liveness checks within its verification flow to help detect presentation attacks before it returns an eligibility decision.

See liveness detection