Overview
ISO/IEC 30107-3:2023 - Information technology - Biometric presentation attack detection - Part 3: Testing and reporting - defines principles, methods and reporting requirements for evaluating presentation attack detection (PAD) mechanisms. This second-edition international standard focuses on how to test PAD performance, how to report results, and how to classify known attack types (Annex A). It does not standardize specific PAD algorithms, countermeasures, sensors, or perform full system vulnerability assessments.
Key topics and technical requirements
- Levels of evaluation: guidance for assessing PAD at multiple levels - PAD subsystem, data capture subsystem, and full system evaluations.
- Terminology and roles: standardized terms for attacks, metrics and test roles (see Annex C) to ensure consistent testing and reporting.
- Metrics and reporting: defines metrics tailored to PAD testing (classification metrics, non‑response metrics, acquisition and efficiency metrics, full-system accuracy measures). The 2023 edition adds the relative impostor attack presentation accept rate for generalized evaluation.
- Artefact & attack handling: principles for creating, preparing and using presentation attack instruments (PAIs) and handling process-dependent evaluation factors (enrolment, verification, identification).
- Test design considerations: addresses statistical challenges unique to PAD testing (diversity of PAI species, variability across instances) and recommends iterative testing to identify effective artefacts.
- Common Criteria alignment: discusses evaluation using the Common Criteria framework and how PAD testing fits into broader assurance processes.
- Informative annexes: Annex A classifies attack types; Annex B provides example artefact species (e.g., for fingerprint devices); Annex C details testing roles.
Practical applications - who uses this standard
ISO/IEC 30107-3:2023 is intended for:
- Vendors and developers of biometric PAD systems wanting to validate and benchmark performance.
- Independent test laboratories conducting accredited PAD evaluations and certification testing.
- System integrators and procurers requiring objective PAD performance evidence for procurement or compliance.
- Regulatory and certification bodies that need standardized reporting formats and metrics.
- Researchers designing experiments and comparing PAD approaches across modalities (fingerprint, face, iris, etc.).
Practical uses include test plan development, reproducible performance reporting, vendor claims verification, procurement specifications, and R&D benchmarking.
Related standards and frameworks
- Other parts of the ISO/IEC 30107 series (for PAD lifecycle and requirements).
- Common Criteria approaches for vulnerability assessment and assurance alignment.
Keywords: ISO/IEC 30107-3:2023, biometric presentation attack detection, PAD testing, PAD metrics, presentation attack instruments, biometric security, PAD reporting.