Verihubs Logo
Home Blog Injection Attack Detection: Virtual Cameras, Hooks
10 min read • Deepfake Detection • Published on October 4, 2026

Injection Attack Detection: Virtual Cameras, Hooks

Injection Attack Detection: Virtual Cameras, Hooks

Injection attack detection is the set of checks that spot fake video fed into a verification flow without passing through a real camera. Fraudsters use virtual cameras, emulators, function hooking, man-in-the-middle tools and even hardware capture devices to do it. Because the injected video looks like a live face, detection has to examine the device and the stream, not just the image.

What a Video Injection Attack Targets in Digital KYC

An injection attack targets the path between the camera and your server. So the fraudster does not need to fool the lens. Instead, they replace what the camera would have sent with a file or a live deepfake of their choosing.

That makes injection different in kind from a print or a mask, since nothing physical is involved. For the side-by-side, our deepfake guide compares injection with presentation attacks. This article picks up where that one stops: how the injection happens, and where you can catch it.

The usual payload is a face that already passes your face match, such as a deepfake built from a stolen ID photo. So the injected video does not need to be perfect. It only needs to reach the liveness model without anything noticing how it arrived.

Why Video Injection Attacks Are Rising

Injection used to need real engineering skill. Today, most of the toolchain is free or cheap. Virtual camera software is a free download, Android emulators are standard developer tools, and open-source face swap projects now run live on an ordinary gaming PC.

Fraud rings also share the work. Some sell ready-made injection kits or rent out deepfake identities, so the person attacking your app may not understand how the tools work at all. Meanwhile, liveness checks have made physical spoofs less rewarding. As liveness catches more prints and replays, attackers move to the path it cannot see.

Five Injection Attack Methods Used Against Selfie Checks

1. Virtual Camera

A virtual camera is software that presents itself to the operating system as a webcam. Streamers, for instance, use them legitimately to add overlays. However, a fraudster can point one at a prerecorded clip or a real-time face swap, and the browser or app treats it as a camera. This is the simplest method on desktop web flows, which is why virtual camera detection is often the first control teams add.

2. Emulator

An emulator runs a mobile operating system on a PC. First, the attacker installs your app inside it. Then they route a video file to the emulated camera. Emulators also make scripting easy, so one person can push many onboarding attempts. On mobile, this is the main route into an app that refuses virtual cameras.

3. Function Hooking

Hooking tools such as Frida attach to a running app and rewrite what its functions return. With a hook, an attacker can swap the camera frames inside the app, or skip a check and return “passed”. Hooking usually needs a rooted or jailbroken phone, or a repackaged copy of the app. So root detection and app integrity checks are part of injection defence, not a separate topic.

4. Man-in-the-Middle on the Upload

Here, the attacker leaves the app alone and intercepts the network traffic instead. They capture the upload, swap the selfie or video, and then send it on. Without payload signing and certificate pinning, the server cannot tell that the file changed in transit.

5. Hardware Injection Devices

The most advanced method uses hardware. A USB or HDMI capture device presents itself to the computer as an ordinary webcam, while it actually plays a video from another machine. Because the operating system sees a genuine camera driver, simple virtual camera checks pass. Catching it takes stream analysis and content checks, which the next sections cover.

Why Image-Only Liveness Misses Injection Attacks

Video injection attack - a fake video stream bypassing the real phone camera and reaching the liveness check directly

Liveness models were built to judge what a camera saw. For example, they look for texture, depth, motion and reflections that separate a real face from a print or a screen. An injected stream contains none of those print or screen artefacts, because it never passed through a physical medium.

Worse still, a good deepfake behaves like a live person. It blinks, turns and follows prompts, so active liveness challenges do not help much either. In other words, the model is answering its own question correctly. The video does show a “face that looks alive”. The real question, whether a camera captured it just now, sits outside the model’s view.

This is why stronger liveness detection alone does not fix injection. Instead, you need signals about the capture path, and you also need a separate model that looks for generation artefacts. Our piece on liveness vs deepfake explains why the two controls answer different questions.

How CEN/TS 18099 Frames Injection Attack Detection

Until recently, however, injection had no standard of its own. Presentation attacks had ISO/IEC 30107 since 2016, while injection relied on vendor claims. That changed in October 2024, when CEN approved CEN/TS 18099, a technical specification for biometric data injection attack detection.

CEN/TS 18099 does three useful things. First, it defines injection attack instruments, the tools and techniques an attacker uses to insert data. Second, it describes how detection systems should work across different capture setups. Third, it sets out how to build test plans, so labs can evaluate injection detection with a repeatable method.

Two other developments point the same way. For example, ISO has opened ISO/IEC 25456, an international project built on the CEN specification. Meanwhile, NIST’s Digital Identity Guidelines, SP 800-63-4, finalised in July 2025, add controls against injection attacks and forged media alongside presentation attack detection. In practice, buyers can now ask for injection test evidence separately from a PAD result.

Layered Injection Attack Detection: Device, Stream and Content

Layered injection attack detection - device and app integrity, stream and transport checks, and content analysis

No single signal catches every injection method. Effective setups combine three layers, each covering a different part of the path.

LayerWhat it checksMethods it catches best
Device and app integrityEmulators, root or jailbreak, hooking frameworks, repackaged apps, virtual camera driversEmulator, function hooking, most virtual cameras
Stream and transportSigned and encrypted payloads, certificate pinning, session binding, frame timing and metadata consistencyMan-in-the-middle, replayed uploads, some virtual cameras
Content analysisDeepfake and face swap artefacts, synthetic texture, frame blending, lighting that does not fit the sceneAny injected deepfake that slips past the first two layers

Of course, each layer has blind spots. Device checks can be evaded by skilled attackers who hide root. Similarly, content models can miss a very clean deepfake. Stream checks do nothing against a virtual camera on an honest network. But together, an attacker must beat all three at once, which raises the cost of every attempt.

Stream Signals That Expose Injected Video

Stream checks get less attention than device checks, yet they often catch what device checks miss. A real camera produces small, constant variation. Injected video tends to break that pattern in measurable ways:

  • Duplicated or looped frames that a live sensor would never repeat exactly.
  • Odd frame timing, such as perfectly even intervals or sudden jumps.
  • Resolution and format quirks that do not match the camera the device reports.
  • Re-encoding traces in metadata, which suggest a file rather than a live capture.

The VeriSecure SDK follows this structure and checks the device before it trusts the camera. It detects emulators, root, Frida and injection or MITM tampering on the device, then runs active liveness. Its deepfake detection then analyses the same capture for face swaps and AI-generated video, and the flow returns a single decision.

For crypto exchanges, where injected deepfakes often target withdrawals as well as signups, our piece on deepfake detection in crypto shows how these layers apply to that sector.

Frequently Asked Questions About Injection Attack Detection

What is an injection attack in biometrics?

A biometric injection attack inserts fake data, usually a video or image, into the verification flow without it passing through a real camera. Attackers use virtual cameras, emulators, hooking tools or network interception to do it.

What is virtual camera detection?

Virtual camera detection identifies when a video source is software rather than a physical camera. To do so, it typically checks driver names, device properties and stream behaviour. It is one part of injection defence, alongside emulator, root and hooking detection.

Can liveness detection stop injection attacks?

Not on its own. Liveness models judge whether the face looks alive, and a good deepfake does. Stopping injection needs device integrity checks, protected uploads and deepfake detection working with liveness.

What is CEN/TS 18099?

CEN/TS 18099 is a European technical specification for biometric data injection attack detection, approved by CEN in October 2024. It defines injection attack instruments and describes how to test detection systems. ISO is developing ISO/IEC 25456 based on it.

Is injection attack the same as SQL injection?

No. SQL injection inserts malicious code into a database query. A biometric injection attack inserts fake media into a verification flow. They share a name because both “inject” something the system did not expect.

Which industries are most targeted by injection attacks?

Any business that opens accounts or moves money after a remote selfie check is a target. Digital lenders, crypto exchanges, e-wallets and digital banks see the most attempts, because fraudsters can cash out each approved fake account quickly.

Injection Attack Detection Moves the Question From the Face to the Path

For years, face verification asked whether a face was real. Injection forces a second question: did this face arrive the way you think it did? A model can answer the first question perfectly and still be fooled, because the second one was never asked.

Fortunately, the standards have caught up with that shift. CEN/TS 18099 and NIST SP 800-63-4 both treat injection as its own risk with its own evidence. So when you review a verification vendor, ask for PAD evidence and injection evidence as two separate items. If the vendor can only show one, you know which half of the path is unguarded.

Not sure how your current flow handles virtual cameras and hooked apps? Request an injection test of your onboarding and step-up journeys.

Client Verihubs
Detect Face Swap with Verihubs Deepfake Detection
Get FREE Trial
View Blog