European specification CEN/TS 18099 establishes a framework for assessing digital attacks on biometric authentication systems
The security of biometric systems is increasingly becoming a focus for standardisation organisations, testing bodies and technology providers. Whilst the industry has primarily focused in recent years on detecting physical spoofing attempts – so-called ‘presentation attacks’ – digital manipulation methods are now taking centre stage. The European technical specification CEN/TS 18099:2025 provides, for the first time, a standardised framework for the evaluation of Injection Attack Detection (IAD) systems.
In parallel, the international standardisation body is working on a standalone ISO/IEC standard, which is currently expected to be published in 2027. The aim is to establish uniform procedures for assessing the resilience of biometric systems against digital injection attacks.
From presentation attacks to digital manipulation
Biometric authentication systems today face a wide range of potential attacks. Whilst classic presentation attacks aim to deceive sensors using photographs, videos, masks or other physical aids, injection attacks occur directly within digital data paths.
In such attacks, manipulated biometric data is not captured via the camera or sensor, but is injected directly into the processing workflow. Attackers attempt, for example, to replace camera data streams, deploy virtual cameras or manipulate operating system and software components in order to feed fake biometric features into an authentication system.
The increasing availability of powerful AI tools and deepfake technologies has further heightened the significance of such attacks. In particular, highly realistic synthetic faces and videos pose new challenges for identity verification and remote onboarding processes.
CEN/TS 18099 defines an assessment framework
The European specification CEN/TS 18099:2025 was developed to enable a structured assessment of protective mechanisms against injection attacks. Unlike traditional functional tests, the specification considers the capabilities of potential attackers and assigns attack scenarios to different risk levels.
This is based on a weighting-based model that takes into account factors such as the specialist knowledge required, the tools needed, the time involved and technical complexity. The sum of these factors results in an assessment of the attack potential.
Different test levels are defined on this basis. Systems that achieve higher protection levels must also be able to successfully fend off attack scenarios of lower complexity.
Focus on different attack scenarios
Typical attack methods at medium security levels include, for example, virtual webcams or emulators that transmit manipulated image data to a biometric system.
Higher test levels involve significantly more complex attack techniques. These include, amongst other things, interference with operating system components, modifications to camera services, kernel manipulations or modified Android system images. The aim of such methods is to replace legitimate camera signals with manipulated data streams without the biometric system detecting the interference.
The tests are based on realistic attack methods, such as those that could be employed by cybercriminals or professional attackers.
Convergence of cybersecurity and biometrics
A key feature of modern IAD assessments is that they do not merely consider individual protection mechanisms. Rather, the security architecture of the entire system is evaluated.
In practice, this means that various security components can work together to defend against an attack. In addition to specific IAD mechanisms, operating system security, device protection, integrity checks, secure hardware elements and traditional cybersecurity measures therefore also play an important role.
This development highlights the increasing convergence of biometric security and cybersecurity. Whilst biometric methods were originally focused primarily on detecting physical spoofing attempts, modern systems must now take complex digital attack chains into account.
Regulatory pressure is mounting
The demand for standardised testing procedures is further reinforced by regulatory developments. In Europe in particular, demonstrating resilience against injection attacks is becoming increasingly important. Manufacturers of biometric solutions must increasingly be able to demonstrate that their systems can detect and prevent both physical and digital manipulation attempts.
With the planned publication of an international ISO/IEC standard, this trend is likely to gain further momentum. Whilst the European CEN/TS 18099 already provides an initial framework, the international standard is expected to include additional test requirements and more detailed evaluation procedures.
Implications for the future of biometric systems
The development of standards for injection attack detection highlights just how significantly the threat landscape in the field of digital identities is changing. Modern biometric systems must now be protected not only against traditional spoofing attacks, but also against complex software-based manipulations.
With the increasing prevalence of digital identities, remote identification procedures and AI-generated content, standardised testing procedures are becoming a key tool for assessing the security and trustworthiness of biometric solutions. At the same time, this development underscores the fact that future security concepts can no longer treat biometric security and cybersecurity as separate entities, but must instead view them as interconnected disciplines.

