Implementing Face Recognition in a Mobile Application
An app for customer verification needs accurate biometrics, but incorrect anti-spoofing turns the system into a filter for photos from a screen. Legal risks are no less: overlooked GDPR or 152-FZ requirements lead directly to app store rejection. We solve both levels—from detection to compliance—turnkey.
A typical scenario: a developer integrates ML Kit for detection, extracts a face embedding via FaceNet, and stops there. The first security review shows the system accepts a printed photo. And App Store Review rejects the build due to missing explicit biometric consent. To avoid these issues, the pipeline must include three mandatory steps: detection + alignment, embedding, anti-spoofing—and a compliance audit.
Our experience shows: without splitting the pipeline into independent steps, you cannot achieve stable results across different devices and lighting conditions. Below is how we do it.
How the Face Recognition Pipeline Works
The pipeline consists of three sequential steps:
- Detection — find a face in the frame, get a bounding box and landmarks.
- Verification/Identification — get a face embedding (128- or 512-dimensional vector) and compare against a database of references.
- Anti-spoofing — ensure a live person is in front of the camera, not a photo/video/mask.
Skipping the third step creates a system that any printed photo can bypass. Even basic passive anti-spoofing filters out 70–80% of simple attacks.
Detection and Landmarks
The choice of library depends on the platform and accuracy requirements. Below is a comparison of two main approaches:
| Framework | Platform | Landmark accuracy | Inference time | Features |
|---|---|---|---|---|
| Vision Framework | iOS | 76 key points | 8–15 ms on iPhone 12 | Built-in, no network required, works with ML models |
| ML Kit Face Detection | Android | up to 468 points (contour detection) | 15–30 ms on Pixel 6 | Requires Google Play Services; detection available in ACCURATE mode |
On iOS: VNDetectFaceLandmarksRequest from Vision framework. Returns VNFaceObservation with landmarks (76 points: face contour, eyebrows, nose, lips, eyes) and boundingBox. On-device, no network, ~8–15 ms on iPhone 12.
On Android: ML Kit Face Detection with FaceDetectorOptions.ACCURATE. Returns FirebaseFace with 468 points when setContourDetectionEnabled(true) is enabled—full face mesh. Heavier but needed for precise face alignment before embedding.
Face alignment before embedding inference is critical. Without alignment by the eyes, face recognition accuracy drops by 15–25%. Geometrically: find the centers of the eyes, calculate the rotation angle, affine transform to a standard position (eyes at 1/3 from the top, symmetric).
Embedding and Comparison
Standard choices are FaceNet (128D) or ArcFace (512D). FaceNet is available out of the box as a TFLite model. ArcFace is more accurate but heavier. For mobile: FaceNet INT8—12 MB, inference ~35 ms on Pixel 6.
Cosine distance between vectors is the primary metric. Threshold for "same face": typically cosine similarity > 0.75. The threshold is tuned to the specific dataset—it is not a universal constant.
Storage of reference embeddings: in encrypted Keychain (iOS) or EncryptedSharedPreferences / Android Keystore (Android). Never store original photos. Embeddings are (theoretically) irreversible, photos are not.
How Anti-Spoofing Works
Two approaches:
| Type | Principle | Performance | Protection against 3D masks |
|---|---|---|---|
| Passive | Skin texture analysis, optical artifacts | <10 ms, no user action | Weak (30–40% false accept) |
| Active | Challenge-response: blink, turn head | 50–200 ms, requires UX | Strong (up to 98% attack detection) |
Passive anti-spoofing is faster, but active is 2× more reliable against 3D masks. For banking and fintech apps, we recommend a combination: passive + active challenge. For corporate access, passive is sufficient. Get a consultation to choose the optimal method for your scenario.
What Is Needed for Compliance?
Biometric data (face embedding is biometrics under GDPR Article 9 and 152-FZ Article 11) requires explicit user consent, separate from the general Terms of Service. Storing embeddings in the cloud is allowed only with encryption in transit and at rest and a DPA with the provider. If the app operates in Russia with Russian users, 152-FZ data localization requirements apply.
The App Store Review Guidelines Section 5.1.1 explicitly prohibit collecting biometrics without explicit permission. Rejection on this point is common. Order a compliance audit at the start—it saves weeks of rework.
What Is Included in the Work
Implementation includes:
- Integration of the detector (Vision / ML Kit) and selection of the embedding model (FaceNet / ArcFace)
- Development of active or passive anti-spoofing
- Setup of encrypted reference storage
- Preparation of compliance documentation (consents, DPA)
- Testing against 100+ attack samples (photo, video, mask)
- Deployment to App Store / Google Play with review support
- Source code, documentation, and team training
Timelines and Guarantees
Detection + identification on-device without anti-spoofing: 1–2 weeks. Full pipeline with anti-spoofing, encrypted storage, and compliance audit: 3–4 weeks. The cost is calculated individually.
We guarantee accuracy of at least 95% FAR at 0.1% FRR on a reference dataset (specified per task). We have 5+ years and 20+ projects with biometrics in banks and fiscal systems. Contact us for a consultation and to evaluate the integration plan for your product.







