Essential Guide

Advanced Deepfake Detection

Chapter 1

The Continued Rise of AI and Deepfakes

What is a deepfake?

GIF of faces interchanging showing a deepfake swap.

What is deepfake detection?

The Growing Surge of Deepfakes

95%

of consumers know what a deepfake is, but only 54% think they could spot a deepfake video. (Jumio)

74%

of consumers say that deepfakes are an ongoing concern for them. (Jumio)

62%

of organizations experience a deepfake attack each year. (Gartner)

30%

of organizations experience a deepfake video attack using against automated face biometrics or identity verification each year. (Gartner)

11%

Synthetic fraud represented 11% of all reported fraud by Q4 2025, up from just 1.4% the previous year. (LexisNexis)

$40B

Generative AI-driven fraud will reach approximately $40 billion in 2027, up more than threefold since 2023. (Deloitte)

deepfake icons

In 2026, fraudsters created and distributed two deepfake videos of the CEOs of India’s Bombay Stock Exchange and National Stock Exchange, each claiming to offer tips of hot stocks to buy. Each CEO and stock exchange had to issue statements clarifying their impartiality and warning investors against purchasing stocks based on the videos’ claims.

BBC NEWS
Chapter 2

Deepfake Tactics and Tools

image of two women photos. Woman on the left has short to mid brown hair. Woman on the right has same hair but different face.

Common Deepfake Tactics

black and white image of two faces being morphed.

Face morphs

black and white image of person holding piece of paper infront of their face with a headshot of a different person.

Synthetic faces

black and white image of split screening showing one half of face and another.

Face manipulations

black and white image of CA ID.

Synthetic identity documents

image of male with selfie on phone screen illustrating video injection

Video injection

Tools Used to Create Deepfakes

high-end-solutions-icon

High-end, custom-built solutions

More capable fraudsters combine separate tools to generate or alter a face, clone a voice, synchronize lip movement, and refine the final video. This “toolchain” approach lowers the barrier to creating deepfakes because the fraudster doesn’t need to build the underlying AI models.

The most sophisticated fraudsters use open-source deepfake frameworks, custom-trained models, virtual cameras, synthetic identity assets, and digital injection techniques, which enable them to feed synthetic media directly into an onboarding or authentication session.

While these two approaches continue to be used, the speed at which off-the-shelf, AI-based solutions have increased their sophistication is rapidly diminishing their benefits. As a result, custom-built solutions are far less prevalent today than just 2-3 years ago, and their use will continue to decline.

dedicated-infrastructure-icon

Dedicated infrastructure

Organized fraud operations maintain their own infrastructure, including libraries of stolen or synthetic identity data, automated scripts, device farms, custom model training, and quality-control processes designed to identify which variants are most likely to bypass verification checks. Fraudsters using higher end hardware can also perform face swaps in real time, allowing them to react to active liveness prompts in real time, even when doing a face swap.

As deepfake creation becomes cheaper and easier, the threat is shifting from isolated fake videos to industrialized identity deception, where AI-generated faces, voices, documents, and behavioral signals are combined into coordinated fraud campaigns.

low-end-tools-icon

Low-end consumer tools

Web-based face-swap tools, avatar generators and video filters that require little technical skill can produce synthetic profile videos, altered selfies, or short clips that appear realistic enough for low-friction onboarding flows, social engineering, or account takeover attempts.

Chapter 3

Liveness Detection

What is liveness detection?

GIF shows Jumio liveness process

Liveness detection strategies

Active liveness detection

Passive and semi-passive liveness detection

Motion analysis

Balancing Strong Liveness and a Smooth UX

Liveness detection is the core of remote identity verification, and while all solutions have now incorporated it, the real differentiator is how effectively these solutions can detect advanced deepfakes, while maintaining a seamless user experience.

Overly burdensome liveness checks can frustrate users and lead to onboarding abandonment. On the other hand, checks that are too lenient or simplistic may fail to detect sophisticated spoofing attempts, compromising security.

Striking the right balance combines advanced AI and biometric technology to deliver robust fraud detection without adding unnecessary friction. The ideal liveness detection system is fast, accurate and intuitive, providing clear instructions while identifying spoofing attempts, such as video injection attacks, replay attacks and AI-generated images in the background.

Ultimately, user trust depends on a solution’s ability to provide both security and a smooth experience, ensuring customers feel protected without being inconvenienced.
Chapter 4

How Video Injection Works

What is video injection?

GIF of video injection

How do injection attacks impact identity verification?

Injection attacks are challenging for identity verification systems that rely on video-based authentication for a number of reasons:
video injection icon graphic

Why are injection attacks becoming harder to stop?

Injection Detection Strategies

Injection attacks feed fake media directly into the system, which means catching them requires a different set of checks than traditional liveness or presentation attack detection.

Camera and device authenticity checks

The first line of defense is confirming the video stream is actually coming from a real, physical camera rather than a virtual camera, emulator or software tool designed to simulate one. This involves validating device-level signals and hardware signatures that legitimate cameras produce naturally and that injection tools typically can't replicate cleanly.

Data stream integrity analysis

Beyond confirming the camera is real, detection systems examine the data stream itself for signs of tampering, looking at encoding patterns, frame timing and metadata that should be consistent with a live, unedited capture. Injected media, even high-quality injected media, tends to leave inconsistencies in how the stream is packaged and delivered compared to a genuine live feed.

Environmental and session signal analysis

Detection also looks beyond the video itself to the broader session, including device fingerprinting, app and SDK integrity checks, and behavioral signals that flag emulators, rooted or jailbroken devices, or other environments commonly used to run injection tools. A single suspicious signal in isolation may not be conclusive, but a combination of them raises confidence that something isn't right.

Frame-level forensic analysis

At the media level, detection systems look for subtle artifacts such as irregular frame rates, unnatural transitions between frames, or compression signatures that don't match what a real-time camera capture would produce.

Chapter 5

Liveness Detection Use Cases

Financial Services

financial services graphic
gaming graphic

Gaming

Shared/Gig Economy

Shared technology graphic
image of phone with pay button

Marketplaces and Digital Platforms

Chapter 6

Security Standards & Liveness Detection

security icon
Deepfake detection standards are still in their early stages. The current standard – published in early 2025 – is CEN TS 18099:2025, which focuses on the threat delivery mechanism (i.e., camera injections).

A future development is ISO/IEC AWI 26655, Information Technology – Biometric Deepfake Attack Detection – Testing and Reporting, which is currently under development by ISO/IEC JTC 1/SC 37. This standard will focus on the payload (i.e. the image) and not on the delivery mechanism. However, publication is not expected until approximately 2029.

In contrast, biometric security already benefits from mature standards for presentation attack detection (PAD), such as the ISO/IEC 30107 series. These focus on defending against spoofing attempts using photos, video replays, masks, and other physical attacks presented to a camera or sensor. Deepfakes introduce a more sophisticated threat, particularly when synthetic media is injected directly into digital systems rather than physically presented to a sensor, creating challenges that existing PAD standards were not originally designed to address.
Chapter 7

Forensic Signal Analysis

Forensic signal analysis is the layer of deepfake detection that examines the actual image, video or audio file for the technical fingerprints AI generation leaves behind, rather than looking at the device or session it came through. It ensures that the piece of media holds up to scrutiny at the pixel, frame and signal level.

Forensic Signal Analysis Strategies

Even the most convincing deepfakes are built by AI models that generate media frame by frame, and that process leaves behind small technical inconsistencies a human eye will miss but an analysis system can catch.

Visual artifact detection

Forensic analysis flags unnatural skin smoothness, asymmetries around the eyes and teeth, or blending errors at the edges of a face, which are common giveaways that an image or video frame has been generated or swapped rather than captured live.

Lighting and shadow consistency

Deepfake generation tools check that the lighting behaves according to physics, shadows fall in the right direction, reflections match the light source, and skin tone shifts naturally as a person moves.

Temporal and motion analysis

Deepfakes are generated frame by frame, which can introduce subtle flickering, jitter, or unnatural transitions between frames that a genuine continuous video capture wouldn't have. Analyzing motion smoothness and frame-to-frame consistency over time helps surface these irregularities.

Audio-visual sync analysis

For voice-cloned or fully synthetic video, lip movement and audio don't always line up as precisely as they should. Forensic analysis can measure the timing between spoken sounds and mouth shape, flagging drift or mismatches that indicate the audio and video were generated or combined separately rather than recorded together.

Compression and metadata forensics

Every generation and editing tool leaves a signature in how it compresses and encodes media. Forensic systems compare compression patterns, file structure and metadata against what a genuine live capture from a real device would produce, since re-encoded or synthetically generated files often carry telltale differences even when the visual content looks clean.

Chapter 8

Choosing the Best Capture Channel

It’s crucial to choose the right capture channel for liveness detection, to minimize risk while maximizing convenience for users. Different channels offer varying capabilities to ensure accurate verification while maintaining a user-friendly experience.

Mobile phones and apps

Mobile phones and apps are particularly well-suited for liveness detection thanks to their combination of advanced hardware and high-quality cameras, consistent configurations, and seamless integration with biometric features.

Laptops/PCs

Laptops/PCs with browser-based verification may present challenges such as inconsistent camera quality, browser variability and vulnerabilities to fraud, and they are far less widely used, especially in developing countries.

Expand Your Knowledge

7 Questions to Ask Your Liveness Detection Vendor

Chapter 9

How Jumio Can Help

Watch a Quick Explanation of Jumio Liveness

Watch now

Next-Gen Liveness Detection

AI-driven technology
analyzing real-time user behavior to prevent deepfakes, masks and spoofing attempts.
ISO/IEC 30107-3 compliant
meeting rigorous industry standards for biometric security and fraud prevention.
Conforms to NIST/NVLAP testing standards
ensuring top-tier accuracy and reliability.
Detects sophisticated fraud
while staying compliant, delivering a secure and seamless customer experience.

Covering Industry Standard Checks

ID image used as
selfie
Paper
printouts
Digital
copy
Face
masks

Beyond the Standard

Image Quality Checks

Incorporating advanced image quality checks to help ensure precise verification, detecting fraud with accuracy even in challenging environments.

Face not fully visible
Is there a covering over the face?
Multiple people
Is there more than one person in the image?
No face present
Is there a nose, mouth and eyes?
Black and white image
Is the image in color or black and white?

Deepfake Detection

Leveraging cutting-edge deepfake detection technology to identify even the most sophisticated synthetic fraud attempts, safeguarding the integrity of your identity verification process.

Synthetic images
Face / head swaps

Injection and Replay Detection

Including robust camera and video injection detection, blocking fraudulent attempts at bypassing verification by using pre-recorded or manipulated content.

Additional Fraud Checks

Offering advanced fraud prevention features, including detecting sleeping individuals and manipulated selfies. Identifying inactive users and tampered images to help ensure only genuine, alert individuals pass verification.

svg
“Online platforms hold a critical duty to leverage cutting-edge detection measures like multimodal, biometric-based verification systems to fortify our defenses against deepfakes."
Daryl Huff, Vice President of Biometrics, Jumio
Learn more about the world of biometric security.

Biometrics & Fraud Analytics: Stopping Fraud at the Source

Frequently Asked Questions

What is deepfake detection?

Deepfake detection is the process of identifying AI-generated or manipulated images, video and audio before they can be used to impersonate a real person during identity verification or authentication. It works by analyzing biometric and technical signals, like whether a face or voice was captured live versus synthetically created, to flag content that isn’t what it claims to be.

How do you detect a deepfake?

Deepfakes are detected using a combination of methods rather than one single check. Liveness detection confirms a real person is physically present in front of the camera. Injection detection identifies when fake media, such as a pre-recorded video or AI-generated image, is being fed directly into the verification system instead of coming from an actual camera. Forensic analysis looks for the subtle artifacts deepfake generation tools tend to leave behind, including irregular blinking patterns and mismatched lighting or audio that doesn’t quite sync with lip movement. Because deepfake tools keep improving, the AI models evaluating deepfakes need to be retrained continuously on new attack patterns.

What's the difference between liveness detection and deepfake detection?

Liveness detection is one specific tool used within the broader category of deepfake detection. Liveness detection answers a narrower question: is there a real, physically present person behind this camera right now? Deepfake detection is the wider umbrella that also covers catching injection attacks, where fake media is inserted directly into the data stream rather than shown to a camera at all, along with other forensic signs of AI manipulation. In practice, a strong deepfake detection strategy uses liveness detection as one layer alongside these other checks, since liveness alone can’t catch every way a deepfake attack can happen.

It's time for a more intelligent, connected, and compliant approach to identity.

image of man with facial hair smiling wearing a suit.