iBeta certification
The lab test that measures liveness detection against the methodology of the standard. What the lab does, what its program levels separate, and what questions to ask of any certificate, including VU's.
In short
iBeta is an independent testing laboratory that evaluates presentation attack detection systems by applying the methodology of the ISO/IEC 30107-3 standard. Its program organizes tests into levels based on the attack potential: the time, expertise, equipment, and cost it takes to build the instrument.
Getting certified there is not a marketing seal. It is the result of a test run by someone who does not sell the product, and it is what distinguishes measured liveness detection from declared liveness detection.
What a lab does in a liveness detection test
The mechanics are easy to explain and hard to pass.
- Builds the attack instruments. Printed photographs, images reproduced on a screen, masks, and face replicas, depending on the level of the test.
- Presents them against the system under controlled and documented conditions, one presentation at a time, in a quantity defined by the protocol.
- Records what the system did with each presentation, both the attack ones and the legitimate ones.
- Reports the result with the metrics of the standard, which are what makes one report comparable to another.
What makes the test valuable is the combination of three conditions: instruments built by a third party, a public protocol, and a result expressed in standardized metrics. None of the three can be supplied by the vendor about its own product.
The levels belong to iBeta's program, not the standard
The confusion is constant and worth cutting off at the root: the ISO/IEC 30107-3 standard does not define conformance levels. It defines the method, the metrics, and the report format. The levels belong to the lab's testing program.
- Level 1 — the test uses low-cost, easy-to-build attack instruments: printed photographs, images and videos played on a screen, cutouts. It is the attack anyone could put together with what they have on hand.
- Level 2 — the test brings in more sophisticated and costly instruments, which require materials, time, and know-how. It approximates an attacker with resources.
- Level 3 — the lab added this after the previous two, for highly prepared instruments such as custom-made hyperrealistic masks.
Passing a higher level does not replace the previous one in the sense of being different scales of the same attack: the instruments change. When reading someone else's certificate, the level says what the system was tested against, and it is the piece of information that separates two claims that sound the same.
One detail worth checking alongside the level: the date. The lab's ladder changes over time, and a certificate was obtained against the instruments that existed on the day of the test.
What falls outside the scope of the certification
A certificate answers a narrow question. Treating it as a general guarantee of the system is the most common misuse, and both vendors and evaluators commit it.
- Video injection falls outside it. The scope of the methodology is presentation attacks, the ones that occur in front of the capture device. A video injection attack replaces the feed before it reaches the application, without going through the sensor, and no test under this methodology says anything about it.
- The tested modality is the one that counts. A facial liveness test says nothing about voice biometrics or fingerprint, even when the same vendor offers several modalities.
- The accuracy of the biometric comparison is not measured here. Match errors are FMR and FNMR, and they belong to a different test.
- The tested version is the one that got certified. The result applies to a specific version of the product on a specific date, not to the product forever.
How to read a certificate, including VU's
Four pieces of data turn a certificate into comparable information. If a vendor does not publish them, ask.
- Which lab ran the test. "Certified to ISO/IEC 30107-3" with no lab named tells you which manual it was measured against, not who measured it.
- Which program level was passed. This is the piece of information that says which instruments the system was tested against.
- On what date. A result from two years ago was obtained against the attack instruments of two years ago, and face-generation tools have not stood still.
- Against which version of the product. The SDK that was tested and the one being integrated need to be the same, or the certificate describes something else.
It is a criterion worth applying evenly. VU publishes it about itself for the same reason it recommends asking for it.
Frequently asked questions
It is the result of a test run by iBeta, an independent testing laboratory that evaluates presentation attack detection systems by applying the methodology of the ISO/IEC 30107-3 standard. The lab builds attack instruments, presents them against the system under controlled conditions, and reports the result with the metrics of the standard. Its value lies in being produced by a third party that does not sell the evaluated product.
The sophistication of the attack instruments used in the test. Level 1 uses low-cost, easy-to-build instruments, such as printed photographs or images played on a screen. Level 2 brings in more sophisticated and costly instruments, which require materials, time, and specific know-how. The lab also added a Level 3 for highly prepared instruments, such as custom-made hyperrealistic masks. All the levels belong to iBeta's program: the ISO/IEC 30107-3 standard does not define conformance levels.
When comparing two vendors, it helps to look at the level and the date together. A higher level does not make a lower one obsolete, but the ladder changes over time and a certification was obtained against the instruments that existed on the day of the test.
No. The methodology the test applies evaluates presentation attacks, meaning the ones carried out by showing something to the capture device. An injection attack replaces the video feed before it reaches the application and never goes through the sensor, so it falls outside the scope. It is a different control, and no certification under this methodology, from any vendor, covers it.
Four pieces of data: the lab, the level passed, the date of the test, and the version of the product tested. The last two are the most commonly omitted. Without a date and a version, the certificate proves that something was measured at some point, and does not let you know whether it describes the product being evaluated today.