Another Great Renaming (From 2024)

In August 2023, I talked about what I called a “great renaming” in which the National Institute of Standards and Technology (NIST) differentiated between its face recognition tests and its face analysis tests: a very important distinction and a critical update.

FRVT becomes FRTE and FATE. From NIST.

The ramifications of that renaming persist. Just last week I reminded a biometric firm that its references to “FRVT” were dated.

But what if references to biometrics are dated?

Find…what?

Over twenty years ago a publication called FindBiometrics was established that discussed you-know-what. Fingerprints, faces, irises, and all sorts of stuff.

You would think that a name that incorporated “biometrics” would be all inclusive. It certainly was twenty years ago. But as the industry evolved, the name became a little dated. While biometrics remain critically important, I have to say (with apologies to my former Motorola colleague Edward Chen) that biometrics is not “4” ALL. (You see what I did there.)

The publication realized this also, and performed its own great renaming.

“TORONTO, ONTARIO, CANADA, November 21, 2024 /EINPresswire.com/ — FindBiometrics, a leading news media platform for the biometrics and digital identity industry, is now ID Tech—a refreshed brand identity that reflects the beginning of a new era in the identity technology space.”

Why?

“…the scope of identity tech has expanded to integrate new developments in areas like artificial intelligence, blockchain, and digital ID.”

One example being mobile driver’s licenses, which can utilize biometrics but goes far beyond it. After all, biometrics (something you are) is just one of the six factors of identity verification and authentication. See below.

So now the former FindBiometrics platform is called “ID Tech,” and its URL is now https://idtechwire.com/. And biometrics now shares the stage with other factors.

Biometrics shares the stage. “Revealed” from Google Lyria; Public Domain.

But ID Tech isn’t the only place to learn about identity beyond biometrics. There’s also my book.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.

If You Can’t Make It, Fake It: Generation of Synthetic Faces for Algorithmic Testing

Sometimes it seems like there’s a catch-22 in facial algorithm development. On the one hand, opponents complain: “How do you know these algorithms work if they’ve never been tested on real faces?” Then in the next breath they complain, “You can’t use the faces of real people to test your algorithms! That violates their privacy!”

So what do you do?

Fake it.

There are many ways to create fake faces for enterprise and consumer use, but how do we know that synthetic faces are sufficiently representative of real ones?

That’s the challenges these researchers faced:

“Face recognition models are trained on large-scale datasets, which have privacy and ethical concerns. Lately, the use of synthetic data to complement or replace genuine data for the training of face recognition models has been proposed. While promising results have been obtained, it still remains unclear if generative models can yield diverse enough data for such tasks. In this work, we introduce a new method, inspired by the physical motion of soft particles subjected to stochastic Brownian forces, allowing us to sample identities distributions in a latent space under various constraints. We introduce three complementary algorithms, called Langevin, Dispersion, and DisCo, aimed at generating large synthetic face datasets. With this in hands, we generate several face datasets and benchmark them by training face recognition models, showing that data generated with our method exceeds the performance of previously GAN-based datasets and achieves competitive performance with state-of-the-art diffusion-based synthetic datasets. While diffusion models are shown to memorize training data, we prevent leakage in our new synthetic datasets, paving the way for more responsible synthetic datasets.”

If you want to see the synthetic data these researchers created, and if you have the ability to uncompress tar.gz files (Mac and Windows 11 support this), visit this page.

The May 6, 2026 List of PAD 3 Conforming Solutions

Update to the April 2 version. Added Shufti.

VendorModalityConfirming LabLink/Date
AwareFaceBixeLabNovember 2025
BioIDFaceTüvitAugust 2025 (1) (2)
FaceTecFaceBixeLabOctober 2025
IncodeFaceiBetaFebruary 2026
Oz ForensicsFaceBixeLabMarch 2026
ParavisionFaceIngeniumSeptember 2025
ShuftiFaceiBetaApril 2026
YotiFaceiBetaJanuary 2026

Yet Another Presentation Attack Detection Independent Testing Body

I’ve been compiling a list (April 2 update here) of PAD 3 conforming solutions, or biometric solutions (so far only face) that satisfy a high level of presentation attack detection (liveness detection). This satisfaction is determined by independent testing bodies such as BixeLab, iBeta, Ingenium, and Tüvit.

While nosing around, I found one other entity that performs these assessments: the Swiss Biometrics Center of the Idiap Research Institute.

The SBC’s attestation letters can be found here, including PAD Level A and PAD Level B conformance letters for entities such as Mobai and Identy.

No PAD Level C attestation letters yet.

The April 2, 2026 List of PAD 3 Conforming Solutions

Update to the March 25 version. Added BioID.

VendorModalityConfirming LabLink/Date
AwareFaceBixeLabNovember 2025
BioIDFaceTüvitAugust 2025 (1) (2)
FaceTecFaceBixeLabOctober 2025
IncodeFaceiBetaFebruary 2026
Oz ForensicsFaceBixeLabMarch 2026
ParavisionFaceIngeniumSeptember 2025
YotiFaceiBetaJanuary 2026

I’m slowly finding these vendors. I won’t maintain this list forever, but as long as there are so few Level 3 solutions, I want to highlight them.

Coincidentally, I just reviewed an eBook by one of the vendors listed above, detailing things that you should seek in your liveness detection vendor.

  • The eBook listed several items.
  • To no one’s surprise, this particular vendor provided ALL of these items in its liveness detection solution.
  • Surprisingly, however, the vendor did NOT mention independent confirmation of PAD capabilities.

What is the NIST Facial Recognition Technology Evaluation (FRTE)? And Why Should You Care?

I’m guilty of acronym overuse. I just wrote a post that mentioned something called “FRTE,” and I belatedly realized that many of the people who read the post…and many of the people who need to read the post…have no idea how to spell FRTE, much less WHY it’s important. So let me explain.

But before I explain FRTE, I should explain NIST. It’s the National Institute of Standards and Technology, part of the U.S. Department of Commerce, and it promotes technology standards throughout the country and throughout the world.

Among the many, many, many things that NIST does, it looks at the use of biometrics for identification and classification of individuals, including face. NIST’s face work is split into face recognition and face analysis. While the latter concerns classification of faces (whether the face is real or a presentation attack, the estimated age of the person), the former focuses on individualization.

FRTE and other stuff, from NIST.

But I’m not going to talk about FATE today. Let’s focus on FRTE.

Why FRTE?

There are hundreds upon hundreds of algorithms out there that purport to compare a face to another face, or to compare a face to many faces, and indicate the likelihood that the compared faces belong to the same person.

And any algorithm provider can claim that its facial recognition algorithm provides 100.00% accuracy or 99.99% accuracy or whatever.

Or that it can search a trillion record database in 0.1 seconds or whatever.

Perhaps the provider even backs up this claim with published data in which the provider tested its algorithm with 1,000 searches against a 100,000 record database and the algorithm did not make a single error.

Are you impressed?

I’m not.

Anyone can score 100% on a self-test.

But what happens when you are given a test by someone else…closed book…with no answer key?

(And yes, I’m aware of the claims that these independent tests are flawed. So design a better one that more than one algorithm provider supports.)

If you’re looking to buy facial recognition technology, the second best way to evaluate the different facial recognition algorithms is to consult the NIST FRTE tests.

  • These tests are continuous, with new algorithms usually added monthly.
  • These tests are complex, measuring umpteen diffferent databases and search types. One or more of these may match your particular use case.
  • These tests are black box. The algorithm providers send their algorithms to NIST, and they are tested against all the other algorithms on identical setups.

Most importantly, the results of these tests are public, and you can view them yourself. The 1:1 testing is here, and the 1:N testing is here.

Oh, and the tests are listed by the algorithm provider, so if Omnigarde says they’ve been tested by NIST, you can look at the test results and find Omnigarde’s algorithm.

And if Vendor X says its algorithm tested well, but you can’t find Vendor X in the algorithm list, then you need to ask Vendor X which algorithm it’s using.

And if Vendor Y says it’s really accurate, but doesn’t state that the algorithm it uses was NIST tested…ask Vendor Y to prove its accuracy claims.

So that’s FRTE. And if your facial recognition vendor isn’t talking about FRTE…ask why.

On Melanin

If you’re examining a person’s fingerprints, palm prints, face, and irises, you need to understand melanin.

The Cleveland Clinic goes into great detail on melanin, but for now I’m going to concentrate on one item.

There are three types of melanin, two of which affect the skin, eyes, and hair.

Eumelanin. There are two types of eumelanin: black and brown. Eumelanin is responsible for dark colors in skin, eyes and hair. People with brown or black hair have varying amounts of brown and black eumelanin. When there’s no black eumelanin and a small amount of brown eumelanin, it results in blonde hair.

Pheomelanin. This type of melanin pigments your lips, nipples and other pinkish parts of your body. People who have equal parts eumelanin and pheomelanin have red hair.

Melanin obviously affects the coloration of your skin, although some parts of your body (such as your fingertips) may have less melanin than other parts (such as your face).

Concentrating on fingertips and faces (and ignoring irises for the moment), let’s look at a situation where we use an optical mechanism (such as an optical fingerprint reader or a camera), along with available illumination, to photograph fingers and faces of people with varying skin tones.

But what if your entire photographic system is based upon reference materials optimized for light melanin levels? As late as the 1970s, Kodak’s reference materials, called “Shirley cards” after the first model, used to exclusively white people.

In the 1970s, photographer Jim Lyon joined Kodak’s first photo tech division and research laboratories. He says the company recognized there was a problem with the all-white Shirley cards.

“I started incorporating black models pretty heavily in our testing, and it caught on very quickly,” he says. “It wasn’t a big deal, it just seemed like this is the right thing to do. I wasn’t attempting to be politically correct. I was just trying to give us a chance of making a better film, one that reproduced everybody’s skin tone in an appropriate way.”

So hopefully today optical devices are properly capturing fingers, faces, and irises of people at all melanin levels.

Or is this wishful thinking?

Who Can Write My Biometric Company’s Product Marketing Content?

Someone who is a biometric product marketing expert.

Someone who has three decades of expertise in biometrics.

I remember ANSI/NIST-CSL 1-1993.

Someone who has worked with fingerprints, faces, irises, voices, DNA, and other biometric modalities.

Some modalities. Butts and tongues not included.

Someone who understands the privacy landscape in Europe (GDPR), Illinois (BIPA), California, and elsewhere.

BIPA is a four-letter word.

Oh…and someone who can write.

A slight exaggeration.

So who can write this stuff?

I know someone. Bredemarket.

Some great videos


Biometric product marketing expert.
Questions.
Services, process, and pricing.

Which Biometric Modalities Does NIST Investigate?

I’ve spent a lot of time in the Bredemarket blog looking at a variety of NIST studies of different biometric modalities.

But you can read up on them yourself.

NIST has investigated the following biometric modalities, using both definitions of the word biometrics:

But NIST has not spent taxpayer money researching other biometric modalities, such as tongue identification.

Biometric product marketing expert.

Yoti iBeta Confirmation of Presentation Attack Detection Level 3

We’ve talked about Levels 1 and 2 of iBeta’s confirmation that particular biometric implementations meet the requirements of ISO 30107-3. But now with Yoti’s confirmation, we can talk about iBeta Level 3.

From iBeta:

“The test method was to apply 1 bona fide subject presentation that alternated with 3 artefact presentations such that the presentation of each species consisted of 150 Presentation Attacks (PAs) and 50 bona fide presentations, or until 56 hours had passed per species. The results were displayed for the tester on the device as “Liveness check: Passed” for a successful attempt or “Liveness check: Failed” for an unsuccessful attempt.

“iBeta was not able to gain a liveness classification with the presentation attacks (PAs) on the Apple iPhone 16 Pro. With 150 PAs for each of 3 species, the total number of attacks was 450, and the overall Attack Presentation Classification Error Rate (APCER) was 0%. The Bona Fide Presentation Classification Error Rate (BPCER) was also calculated and may be found in the final report.

“Yoti Limited’s myface12122025 application and supporting backend components were tested by iBeta to the ISO 30107-3 Biometric Presentation Attack Detection Standard and found to be in compliance with Level 3.”

More from Yoti itself.

“Yoti’s MyFace is the first passive, single-selfie liveness technology in the world to conform to iBeta’s Level 3 testing under ISO/IEC 30107-3 – their highest level for liveness checks.”

Also see Biometric Update and UK Tech.

After all, facial age estimation is of no meaning whatsoever if the face is fake. So it was important that Yoti receive this confirmation.