iBeta launches Injection Attack Detection testing against CENS/TS 18099:2025

As biometric systems become more widely used for identity verification, fraud prevention, access control, financial services, healthcare, and digital security, the methods used to attack those systems are also becoming more advanced. 

Presentation attacks, such as printed photos, masks, or spoofed physical biometric traits, have been a major focus of biometric security testing for years. But biometric threats are no longer limited to what happens in front of a camera or sensor. 

Injection attacks introduce a different kind of risk. 

Instead of presenting a fake biometric sample to a sensor, an injection attack attempts to bypass or manipulate the biometric capture process itself. This may involve inserting manipulated biometric data, synthetic media, video streams, emulator feeds, or other digital inputs directly into the system pipeline. 

That distinction matters. 

A biometric system may perform well against traditional spoof attempts and still need additional validation against attacks that target the digital path between capture, processing, and decision-making. 

To help organizations address this emerging risk, iBeta now offers Injection Attack Detection testing against CEN/TS 18099:2025. 

iBeta’s launch of Injection Attack Detection testing was recently featured by Biometric Update, highlighting the company’s new testing capabilities against CEN/TS 18099:2025. 


What Is Injection Attack Detection?

Biometric facial recognition screen showing a person’s face being analyzed, representing injection attack detection and biometric security testing

Injection Attack Detection, or IAD, refers to a system’s ability to detect and prevent attempts to inject manipulated or unauthorized biometric data into the authentication process. 

In biometric systems, trust depends on more than whether the system can match a face, fingerprint, iris, palm, or voice. Trust also depends on whether the system can confirm the data being evaluated came through the expected capture channel and was not replaced, altered, or digitally inserted along the way. 

Injection attacks may target biometric systems through methods such as: 

  • virtual webcam or emulator injections 
  • manipulated camera feeds 
  • synthetic or replayed biometric data 
  • altered device pathways 
  • compromised capture environments 
  • attempts to bypass normal sensor or camera input 

These attacks are especially important as AI-generated media, deepfake technology, remote onboarding, mobile identity verification, and digital authentication workflows become more common.

For organizations relying on biometric systems, the question is no longer only: 

Can the system identify the right person? 

The stronger question is: 

Can the system detect when the biometric input itself has been manipulated or injected? 


Why IAD Testing Matters Now 

Biometric security is evolving quickly. Attack methods are becoming more digital, more scalable, and more difficult to identify with traditional defenses alone. 

As biometric systems move into more remote, mobile, and automated environments, the attack surface expands. A system may need to defend against physical presentation attacks, software-based attacks, device manipulation, deepfake media, and other forms of digital interference. 

This is where IAD testing becomes important. 

Injection attack testing helps organizations evaluate whether biometric systems can withstand attempts to bypass or manipulate the capture process. It provides structured evidence around how the system responds when attackers attempt to introduce biometric data through unauthorized or unexpected channels. 

For vendors, platforms, and organizations deploying biometric technologies, IAD testing can support: 

  • stronger fraud prevention 
  • improved trust in biometric authentication 
  • readiness for emerging industry expectations 
  • better visibility into system-level security posture 
  • more defensible evaluation of biometric system performance 
  • preparation for evolving standards and certification requirements 

As the biometrics industry continues to mature, IAD testing is expected to become a more important part of biometric security validation.


About CEN/TS 18099:2025 

CEN/TS 18099:2025 is a European technical specification developed to provide an early framework for evaluating biometric Injection Attack Detection. 

The specification gives the industry a structured way to assess IAD capabilities while the broader international standard continues to develop. It also helps organizations begin evaluating injection attack risk now instead of waiting for the threat landscape to become more established. 

For biometric vendors and organizations operating in or serving the European market, this technical specification is especially important. It gives teams a recognized framework for understanding, testing, and documenting injection attack detection capabilities.iBeta’s IAD testing against CEN/TS 18099:2025 allows organizations to begin preparing for this next layer of biometric security evaluation. 


Testing Up to Level 3 

iBeta’s Injection Attack Detection testing includes evaluations up to Level 3. 

In IAD testing, levels are used to represent increasing levels of attack complexity, effort, and sophistication. Lower-level attacks may involve more accessible or less complex methods, while higher-level testing evaluates more advanced attack paths. 

This matters because biometric systems need to be evaluated against realistic threat levels. 

A system that can detect basic injection attempts may still need validation against more complex methods that require greater attacker expertise, deeper system manipulation, or more advanced tooling. 

Testing up to Level 3 gives organizations a more complete understanding of how their systems respond to higher-risk attack scenarios. 

It also helps teams identify where additional controls, security layers, or design improvements may be needed. 


Why Injection Attacks Require a System-Level View 

Injection attacks are not always isolated to one single feature or defense mechanism. 

In many cases, the strength of the system depends on how multiple security layers work together. A biometric platform may rely on capture controls, device integrity, liveness detection, encryption, session handling, fraud detection, backend validation, and other security mechanisms to prevent unauthorized input from being accepted. 

That means IAD testing should not only ask whether one specific detection feature worked. 

It should ask whether the system as a whole prevented the attack. 

This system-level perspective is important because attackers often look for the weakest link in the process. If biometric capture, device handling, transmission, or backend processing can be manipulated, the entire authentication decision may be affected. 

iBeta’s testing approach helps organizations understand whether their biometric systems can resist injection attack methods across the broader authentication pathway. 


How IAD Fits With Presentation Attack Detection 

Injection Attack Detection does not replace Presentation Attack Detection. 

It adds another layer of evaluation. 

Presentation Attack Detection, or PAD, focuses on attacks presented to the biometric sensor. Examples may include printed photos, masks, synthetic fingerprints, replayed voice recordings, or other attempts to fool the capture device. 

Injection Attack Detection focuses on attacks that attempt to insert or manipulate biometric data digitally within the system process. 

Both matter. 

As biometric fraud evolves, organizations need to consider physical spoofing risk and digital injection risk. A stronger biometric security posture may require testing across both areas, especially for systems used in remote identity verification, mobile authentication, financial services, healthcare, access control, government services, and other high-trust environments. 

The growth of IAD testing reflects a broader shift in biometric security. 

Fraud prevention is becoming more interconnected with cybersecurity, software integrity, device trust, and system-level validation. 


Why Organizations Are Preparing Now 

Organizations are paying closer attention to injection attack risk because biometric systems are being used in more critical workflows. 

Biometrics increasingly influence access, identity, transactions, onboarding, account recovery, workforce authentication, and regulated digital services. As usage increases, attackers have more incentive to find new ways to bypass these systems. 

At the same time, AI-generated media and deepfake capabilities are changing what fraud attempts can look like. Attacks can be more convincing, more automated, and more difficult to detect without structured evaluation. 

For biometric vendors and relying organizations, waiting until a standard becomes mandatory can create unnecessary pressure. 

Preparing early gives teams more time to: 

  • understand system exposure 
  • evaluate current detection capabilities 
  • identify gaps 
  • improve controls 
  • document findings 
  • prepare for future certification expectations 
  • build greater confidence with customers and stakeholders 

IAD testing gives organizations a proactive path forward. 


iBeta’s Role in Biometric Testing 

iBeta has extensive experience in independent biometric testing and certification. The addition of Injection Attack Detection testing reflects iBeta’s continued focus on helping organizations validate biometric systems against evolving threats and emerging standards. 

Biometric security cannot remain static. 

As fraud techniques advance, testing methods must advance as well. The launch of IAD testing against CEN/TS 18099:2025 gives biometric vendors and relying organizations a way to evaluate injection attack risk with a structured, independent testing partner. 

iBeta’s role is to help teams understand how their systems perform, where risk exists, and what evidence supports the security claims being made. 


Preparing for the Future of Biometric Security 

Injection attacks represent an important next step in biometric threat evaluation. 

As industry standards continue to evolve, organizations will need stronger evidence that biometric systems can withstand both physical and digital attack methods. IAD testing helps teams move from assumption to validation. 

For biometric vendors, IAD testing can support product improvement, customer trust, market readiness, and future compliance preparation. 

For organizations deploying biometric systems, it can provide clearer insight into whether the technologies they rely on are prepared for modern fraud techniques. 

Biometric security is no longer only about matching the right person. 

It is about protecting the entire path from capture to decision. 


Get Started With Injection Attack Detection Testing 

iBeta now offers Injection Attack Detection testing against CEN/TS 18099:2025, including testing up to Level 3. 

If your organization develops, deploys, or relies on biometric authentication technology, IAD testing can help you evaluate system resilience, identify risk, and prepare for emerging biometric security expectations. 

Contact iBeta to discuss Injection Attack Detection testing and how independent biometric evaluation can support your security and certification goals.