IDEMIA Public Security said its WebCapture SDK has completed an independent assessment of its ability to detect and block biometric fraud attacks, including deepfakes and AI-generated identities.
The assessment, carried out by the independent testing firm BixeLab, examined whether attackers could trick the system by injecting fake biometric data into the identity verification process. According to the company, none of the 900 attack attempts succeeded. Ten different injection attack instrument species were tested across several methods, among them deepfakes, face swaps, replay attacks, morphing and avatar reenactment. BixeLab concluded that, within the scope defined for the evaluation, WebCapture SDK v3.38 satisfied the requirements of a CEN/TS 18099:2024 aligned Level 2 (Substantial) assessment for the instruments and methods tested.
Ted Dunstone, chief executive of BixeLab, said independent testing is becoming more important as deepfakes and injection attacks grow more sophisticated and easier to obtain, and that measuring systems against recognized standards such as CEN/TS 18099 gives organizations independent evidence that the protections hold up in practice.
The company said the technology also held up for genuine users: during baseline testing of legitimate transactions, two classification errors were recorded across 300 attempts, a bona fide classification error rate of 0.67%. Virginie Flam, senior vice president and global head of smart biometrics at IDEMIA Public Security, said organizations need confidence that their identity verification systems can keep up as AI-driven fraud evolves, and that the validation reflects the company's commitment to helping them address emerging threats while keeping the process simple for legitimate users.
The company said its identity verification technology combines biometric liveness detection with fraud prevention capabilities to help establish that the person completing a verification is physically present and authentic, and that the evaluation provides evidence of the solution's resistance to the injection attack methods and instruments that were tested.