Back to Webinars

Liveness, Deepfakes, and the Root of Trust: Why Identity Verification Starts with a Live Human

Date Aired: May 12, 2026

What You’ll Learn

Liveness detection answers a question that passwords, device signals, and behavioral analytics cannot settle on their own: is a real human being actually behind this session? This webinar examines how presentation attacks, injected camera feeds, and deepfakes undermine identity verification, why analyzing pixels alone is a weak foundation, and where a liveness check provides enough additional trust to justify the friction. You will also see how that decision changes across onboarding, account recovery, promotional abuse, high-value transactions, and agent-driven workflows.

Key Takeaways:

  • A face appearing on camera proves very little by itself. An attacker can hold up a photograph, display a face on another screen, wear a mask, or replace the camera feed entirely. Liveness detection determines whether the session involves a real person presenting a real face through a camera signal the application can trust.
  • Presentation attacks happen in front of the camera. Injection attacks compromise the signal behind it. Defending against both requires more than inspecting the final image for suspicious pixels.
  • Device integrity, camera-path signals, depth information, and session context provide stronger evidence than a deepfake classifier working from the picture alone.
  • Pixel-level deepfake detection produces false positives because legitimate filters, image enhancement, virtual cameras, and cosmetic effects can resemble manipulation. The webinar explains why the device and signal path provide a more dependable foundation for deciding whether the pixels originated where the application thinks they did.
  • False accepts and false rejects belong in the same risk calculation. A system that blocks every transaction will achieve an impressive fraud rate and a less impressive customer count. Teams need to measure how many attackers get through without treating every abandoned session as proof that a legitimate user was rejected.
  • Drop-off data rarely tells the whole story. A failed liveness session could indicate customer friction or a stopped account takeover attempt. Support tickets, help desk contacts, return attempts, and account-level behavior can reveal whether rejected users were frustrated customers or attackers who quietly moved on.
  • Liveness detection works best at specific trust inflection points rather than during every authentication. A platform can establish a biometric baseline during account opening, rely on lower-friction signals during ordinary activity, and return to liveness when a user resets a password, binds a new passkey, changes devices, ships an expensive purchase to a new address, or performs another high-risk action.
  • Identity verification should be designed as a dynamic waterfall. Email verification, phone checks, database queries, device intelligence, behavioral signals, and liveness checks each carry different costs and abandonment risks. Their order should reflect customer lifetime value, expected fraud loss, regional expectations, and the amount of friction users will tolerate at each stage.
  • Promotional abuse becomes materially expensive when every fraudulent account consumes compute, tokens, delivery subsidies, or other real resources. A liveness check can block fully automated account creation, while biometric deduplication can identify the same person returning under multiple email addresses to claim repeated introductory offers.
  • Biometric matching does not have to dictate the business response. A repeated face can trigger a hard block, redirect the user to an existing account, prompt additional verification, or move the person toward a paid plan. The control produces a signal. Product and security teams still decide what that signal means.
  • Agentic workflows make human approval harder to prove because an agent may possess the user’s credentials, tokens, and saved payment methods. A liveness check at a high-risk step can establish that a real person approved a deployment, purchase, transfer, or other consequential action at a specific point in time.
  • Blocking agents at the perimeter will become increasingly unreliable as browser automation and other workarounds improve.
  • Platforms need approved paths for agent activity, such as purpose-built APIs or MCP servers, where they can observe behavior, constrain permissions, and introduce human approval before an agent crosses a meaningful risk boundary.
  • Friction should be placed where the cost of a mistake exceeds the cost of interruption. A delayed code deployment may be acceptable. Interrupting every routine purchase probably is not. The architectural decision is where stronger proof of human presence changes the risk enough to justify asking for it.
View Transcript

Who Should Watch This Webinar?

  • CTOs
  • CISOs
  • Security architects
  • Identity architects
  • Platform engineers
  • Product leaders
  • Fraud teams
  • Trust and safety teams

Topics Discussed:

  • Liveness detection as a root of trust
  • Presentation attacks
  • Injection attacks
  • Deepfake detection and its limits
  • 3D face depth mapping
  • Device and camera signal integrity
  • False accept and false reject rates
  • Interpreting drop-off data
  • Support tickets as a fraud signal
  • Identity verification waterfalls
  • Customer lifetime value and verification budgets
  • Step-up liveness at account recovery
  • One-to-N biometric deduplication
  • Promotional abuse on AI platforms
  • Encrypted face vector storage
  • Agentic commerce consent
  • Human-in-the-loop approval
  • Friction as a security feature

Speakers:

Cameron D'Ambrosi Image
Cameron D'Ambrosi
Head of Strategic Partnerships, NA & EU, FaceTec
Cameron D'Ambrosi has spent nearly a decade at the forefront of digital identity market intelligence, helping organizations navigate the fast-moving landscape of consumer identity, compliance, and emerging technology. With a background that stretches from consulting at Deloitte to analyst roles at the NYSE, he brings a rare blend of financial rigor and technology insight to the identity space. He's best known as the longtime host of The State of Identity podcast and as a regular moderator and keynote speaker at industry gatherings like Identiverse, where he breaks down the companies, regulations, and technologies reshaping how we verify who we are online.
Dan Moore Photo
Dan Moore
Sr. Director of CIAM Strategy, FusionAuth
Dan Moore has spent his career across the full stack of software leadership, from back-end developer and engineering manager to CTO and AWS certification instructor at organizations including Oracle and Culture Foundry. He holds AWS and identity certifications and has contributed to 97 Things Every Cloud Engineer Should Know. His speaking reflects where his interests have landed: Identiverse sessions on CIAM, OAuth compliance, and decentralized authentication; Devnexus workshops on enterprise authentication and microservice architectures; and webinars on passkeys, modern MFA, and identity challenges in agentic AI workflows. He's also been a featured guest on Corey Quinn's Screaming in the Cloud.
Featured Capability
Biometric Authentication
learn more
Sample app login screen prompting biometric fingerprint authentication with a pattern login alternative.
Share this post
Watch  On-Demand
Subscribe to The FusionAuth Newsletter
Get updates on techniques, technical guides, and the latest product innovations coming from FusionAuth.