What is a spoof bounty program and liveness detection? What are their similarities and differences? How easy is it to fool an authenticator app? If you are looking for answers to these specific questions, continue reading this article.

What is the Spoof bounty program?
A spoof bounty program is a public white hat security test, designed to ensure that a biometric authenticator is secure in the real world (not just in the lab or classroom). Similar to a software bug bounty program, if a tester finds a spoof that fools the system, they are rewarded with a cash prize. Through this process, the vendor providing the biometric authentication software learns about potential vulnerabilities and takes steps to fix them.
How do Spoof Bounty programs enhance security?
With this open-source testing, biometric authentication software providers can no longer hide behind “Request A Demo” links. Their security software must be open to everyone for evaluation and testing. This approach provides transparency and vendors demonstrate their security in the same real-world environment where their customers operate.
See also: Wombo.AI deepfake singing app: Turn your photos into deepfake videos
The Liveness.com Level 1-5 Threat Vector Scale – Spoof Artifact & Bypass Levels
When a non-living object displays human characteristics (Artifact) and is presented to a camera or biometric sensor, it is called a “spoof”. Photos, videos, deepfake puppets, masks and dolls are common examples of spoof artifacts. When biometric data is compromised after capture, or the camera is bypassed completely, this is called a “bypass”. The ways in which the above breaches are done have been categorized into levels. There are no laboratory tests available for Artifacts (level 1-3) or Bypasses (Level 4 & 5), as these attack vectors are missing from the ISO 30107-3 Standard. Only a Spoof Bounty program can currently address Levels 1-5 breaches.
See Levels 1-5 below:


Anti-Spoofing & Liveness Detection: Are they the same thing?
Live Detection is the ability of a computer to determine that it is interacting with a human who is physically present and not an inanimate spoof artifact.
See also: Deepfake: An ever-growing threat to businesses
To a large extent, then, it's the same thing. If an artifact (photo, video, mask, etc.) fools a face authenticator, we're talking about a spoof. If such a tool is fooled by another human, and not by a non-living object, we're talking about an impostor (matching false accept).
How Liveness Detection protects us from identity fraud;
Liveness detection prevents an artifact from fooling the authenticator app. The legitimate user must be physically present to access their accounts. Essentially, Liveness detection prevents bots and malicious criminals from using stolen photos, deepfake, masks, or other artifacts to gain access to third-party accounts. Only then can real users create and access accounts.
Liveness checks solve some very serious problems. For example, Facebook had to delete 5.4 billion fake accounts in 2019 alone! Requiring Liveness checks would have prevented the creation of these fake accounts.
Why Spoof Bounty Programs Are More Reliable Than Lab Tests;
Spoof Bounty programs are the future of biometric security testing because no lab can create or purchase all the spoof artifacts. Most labs test presentation attack detection (PAD) using only five or six artifacts. This small number does not reflect real-world risks.
For example, if you had a million users, then the biometric authenticator would see 10,000-20,000 different spoof artifacts. If you compare that to the five or six in lab tests, you can see why it's much harder to be secure in the real world.

FaceTec
It’s important to know if your authentication software vendor has a spoof bounty program to ensure they can address emerging threats, such as deepfakes. Currently, the only biometric authentication vendor with an active, real-world spoof bounty is FaceTec. Having already thwarted over 80,000 spoof attacks, the goal of the Spoof Bounty program is to uncover unknown vulnerabilities in its 3D Face Authentication solution so the company can patch them and strengthen its anti-spoofing capabilities.
FaceTec launched its multi-tiered spoof bounty program in the fall of 2019, initially offering $30,000 to hackers who were able to trick its biometric authentication system, 3D Face Authentication. Level 1 offered $15,000 to anyone who could trick the system using a high-resolution photo or video. Level 2 offered $10,000 for presentation attacks using materials such as masks, while Level 3 offered $5,000 for attacks using highly realistic 3D sculptures.
See also: Microsoft: Fight against deepfakes with new detection tool

Since last year, fees have increased significantly, while two additional levels have been added.
FaceTec reported last year that there had been thousands of spoofing attempts against 3D Face Authentication, through its spoof bounty program, and its technology had an accuracy rate of greater than 99.997%.
Information source: spoofbounty.com
