ISO 30107-3 and PAD levels, in plain English
Every liveness vendor waves a badge — “iBeta Level 2”, “ISO 30107-3”. Very few buyers can say what those actually measure, which makes the badges hard to compare and easy to over-read. This is the short, honest version: what the standard tests, what the numbers mean, and what a certification letter does and doesn’t prove.
What ISO/IEC 30107-3 actually is
It is a testing and reporting standard for presentation-attack detection — the discipline of telling a real, live face from an artefact. It doesn’t certify a product by itself; it defines a common language — the attack categories, the metrics, and the reporting rules — so an independent lab can evaluate a system and publish a result others can interpret. The standard spans face, fingerprint, iris, voice and palm; in identity verification we care about face.
PAI species: the catalogue of attacks
A Presentation Attack Instrument (PAI) is any object or characteristic used to spoof the camera — a printed photo, a phone playing a video, a silicone mask. A PAI species is a category of these. A meaningful test states which species it covered, because “we stop attacks” means nothing without saying which.
APCER and BPCER: the only two numbers that matter
APCER — the security miss
How often an attack is wrongly accepted as a live person. Lower is safer.
BPCER — the friction cost
How often a genuine person is wrongly rejected as an attack. Lower means fewer users blocked.
These trade off: you can drive attacks to zero by rejecting everyone, which is useless. So a liveness claim with only one figure — or none — tells you almost nothing. Always ask for both, at the same operating point.
iBeta Level 1, 2 and 3
iBeta is the lab most people mean by “certified”. Its levels differ by how hard — and expensive — the attacks are allowed to be:
- Level 1: low-cost attacks (printed photos, screen replays), each artefact capped around $30.
- Level 2: sophisticated artefacts — custom 3D masks and the like — capped around $300 and built by a specialist.
- Level 3: a newer, tougher tier that tightens the bona-fide error bar further.
To “pass” Levels 1–2 a system must catch the attacks while keeping BPCER within iBeta’s 15% threshold — i.e. not wreck the experience for real users in the process.
What a letter does — and doesn’t — prove
A confirmation letter is genuinely useful: it is an independent, repeatable result against a named set of attacks. But read the fine print. It reflects the specific PAI species tested, at a point in time. It typically covers physical artefacts presented to a camera — not necessarily digital-injection attacks, where synthetic frames are fed past the camera entirely, which is where much of today’s fraud has moved. And a lab pass is not a promise of how the system behaves on your users, devices and lighting. Use it as a data point, not a guarantee.
What to ask a liveness vendor
- Which iBeta level, and can I see the actual confirmation letter (not just a logo)?
- What are your APCER and BPCER, at the same operating point?
- Do you test injection / deepfake attacks, and how — not just physical artefacts?
- Passive, active, or both — and how do you handle accessibility and drop-off?
- How often is the model retrained as new attacks appear?
Frequently asked questions
- What is ISO/IEC 30107-3?
- ISO/IEC 30107-3 is the international standard for testing and reporting the performance of presentation-attack detection (PAD). It defines the categories of attack (“PAI species”), the error metrics (APCER and BPCER), and how a test must be run and reported so results from different systems can be compared on the same terms.
- What do APCER and BPCER mean?
- APCER (Attack Presentation Classification Error Rate) is how often an attack is wrongly accepted as a real person — the security miss. BPCER (Bona Fide Presentation Classification Error Rate) is how often a genuine person is wrongly rejected as an attack — the friction cost. They trade off against each other, so a single number without both is close to meaningless.
- What is the difference between iBeta Level 1 and Level 2?
- iBeta is the best-known lab that runs ISO/IEC 30107-3 evaluations. Level 1 tests low-cost attacks — printed photos, screen replays — with each artefact capped at roughly $30. Level 2 tests sophisticated artefacts such as custom 3D masks, capped at roughly $300, made by a specialist. A newer Level 3 raises the bar further. Passing means the system kept BPCER within iBeta’s threshold (15% for Levels 1–2) while catching the attacks.
- Does an iBeta letter mean a system stops deepfakes?
- Not necessarily. A confirmation letter reports performance against the specific physical PAI species tested at a point in time. Injection attacks and rapidly-evolving deepfakes may fall outside the artefacts a given evaluation used, and lab results don’t guarantee field performance on your users and devices. Treat a letter as a useful, verifiable data point — not a guarantee.