Overview
ISO/IEC 20059:2025 - "Information technology - Methodologies to evaluate the resistance of biometric systems to morphing attacks" defines a standardized methodology to assess how image-based biometric systems resist morphing attacks, including multiple identity attacks (MIA). The standard is limited to image-based modalities such as face, iris and finger image data and provides definitions, evaluation metrics and procedures to measure the morphing attack potential (MAP) of morphing methods. It also describes how morphing algorithms can be used to evaluate biometric systems and includes informative annexes for reference implementation and visualization.
Key technical topics and requirements
- Scope and terminology: Clear definitions of image modification, image manipulation, biometric morphing, and related attack/detection concepts (e.g., S-MAD, D-MAD).
- Morphing attack potential (MAP): A methodology and matrix-based metrics to quantify a morphing method’s capability to deceive one or more biometric systems across multiple verification attempts.
- Detection and error rates: Standardized metrics for morphing attack detection performance, including BSCER (bona fide sample classification error rate) and MACER (morphing attack classification error rate), with procedures to report these values.
- Multiple contributing subject generalization: Treatment of morphed samples that combine multiple identities and how to measure their effect on system vulnerability.
- Benchmarking and influencing factors: Guidelines for benchmarking morphing methods, visualizing morphed samples, and understanding factors that impact MAP (e.g., number of systems, thresholds, probe attempts).
- Reporting and reproducibility: Guidance for consistent measurement, visualization (examples in Annex B), and a reference implementation (Annex A) to support reproducible evaluation.
- Limitations: The standard focuses on evaluation methodology and explicitly notes that resistance evaluation is not a full security evaluation.
Practical applications
- Evaluating the robustness of automated border control (ABC) gates, passport issuance workflows and enrolment systems against image-based morphing attacks.
- Benchmarking morphing and morph-detection algorithms in laboratories and testbeds.
- Integrating MAP and MACER metrics into procurement, conformance testing and risk assessments for biometric systems.
- Supporting research into morphing generation and detection methods and informing operational policies for trusted capture and enrolment.
Who should use ISO/IEC 20059:2025
- Biometric system vendors and integrators
- Border control and identity document authorities
- Testing laboratories and certification bodies
- Security architects, risk managers and policy makers
- Researchers developing morphing or morph-detection algorithms
Related standards
Normative references include:
ISO/IEC 20059:2025 provides a consistent, repeatable framework for assessing image-based morphing threats and integrating quantitative MAP metrics into biometric security programs.