Language

False Positive

What is a false positive?

A false positive occurs when a system reports that something is present even though it is known to be absent. In simpler terms, the correct answer is “no,” but the system returns “yes.” The known correct answer used to evaluate the system is called the ground truth.
In fraud detection, fraud is usually treated as the “positive” class. A false positive therefore means that a legitimate customer, genuine document, or valid activity is incorrectly flagged as fraudulent. Fraud that passes without being flagged is a false negative.
Other identity checks use more specific terms and metrics. Reports should name the check instead of using “false positive” on its own.

Which metrics describe false positives in identity verification?

Identity verification systems perform several separate checks, each with its own terminology:
  • 1:1 biometric comparison. A comparison between samples from different people that incorrectly returns a match is called a false match. False match rate (FMR) measures how often impostor comparisons produce this error. The opposite error is a false non-match, in which samples from the same person fail to match.
  • 1 biometric identification. A false positive identification occurs when a search involving a person who is not enrolled returns one or more candidates above the selected threshold. False positive identification rate (FPIR) measures this error.
  • Document validation. When a genuine document is incorrectly classified as fraudulent, document-specific testing may report a document false rejection. This is different from accepting a fraudulent document, which is a document false acceptance.
  • Presentation attack detection (PAD). A bona fide presentation classified as an attack may be described generally as a false positive. PAD standards use their own error metrics, which should be named in technical reports.
  • Sanctions or watchlist screening. A false positive occurs when a person or entity that is not the listed party is incorrectly returned as a potential match. This result usually requires review rather than automatic rejection.
Confusion starts when a report does not name the target. It should state the check, positive class, ground-truth method, threshold, and test population. The same definitions must be used when comparing vendors.

What causes false positives?

False positives can result from poor input quality, weak reference data, unsuitable thresholds, broad matching rules, or missing context.
Look-alike faces and low-quality images may contribute to a false match. Document checks may reject a genuine credential when glare, blur, damage, or an incomplete image obscures a security feature. Screening systems may return the wrong person because of a shared name, alias, transliteration, or incomplete identifying data.

Why are false positives important?

False fraud alerts delay legitimate applicants, increase manual-review work, and may cause customers to abandon onboarding. A biometric false match creates a different risk: the wrong person may pass a comparison. Combining both events under one figure makes the results difficult to interpret and can lead teams to adjust the wrong control.
Performance reports should separate false fraud alerts, false matches, document false rejections, screening false alerts, and other component errors. They should also show the corresponding miss metric so decision-makers can see the effect of threshold changes on both sides.

How can Regula support false-positive analysis?

Regula Face SDK returns similarity scores for 1:1 face comparisons and assesses face-image quality. Organizations can test decision thresholds against representative data and send uncertain cases for another capture or manual review. Active and passive liveness checks provide separate results for presentation attack detection.
Regula Document Reader SDK verifies identity documents using more than 16,500 document templates from 254 countries and territories. It checks document security features and compares information from the visual inspection zone, machine-readable zone (MRZ), barcodes, and supported NFC/RFID chips.
Organizations remain responsible for establishing ground truth, selecting thresholds, measuring each error separately, and defining review rules.

FAQ

How is a false positive different from a false negative?

A false positive reports a target that is not present; a false negative misses a target that is present. If fraud is the target, a legitimate customer incorrectly flagged as fraudulent is a false positive, while undetected fraud is a false negative. The positive class must be stated before either label can be interpreted correctly.

Can a false positive allow a fraudster to pass face matching?

The general phrase can be misleading here. In fraud detection, a fraudster who passes is a false negative because the fraud was missed. In 1:1 face matching, an impostor who incorrectly matches another person’s reference produces a false match, sometimes loosely called a biometric false positive. Reports should use false match and FMR for the biometric comparison so the two errors are not confused.

Is every rejected legitimate customer a false positive?

No. The rejection is a false positive only if a system incorrectly classified the customer or their evidence as the target it was meant to detect, such as fraud. A customer may also fail because required evidence is missing, an image cannot be processed, or a business rule prohibits the transaction. These events should be measured separately.

How is the false-positive rate calculated?

The false-positive rate is the number of false positives divided by all ground-truth negative cases: False-positive rate = false positives ÷ (true negatives + false positives). If fraud is the positive class, the denominator contains all confirmed legitimate cases in the test set. Biometric comparison and identification use specific metrics such as FMR and FPIR.

 

Does changing the threshold reduce false positives?

It can, but the direction depends on the score. Raising a face-similarity threshold generally reduces false matches and increases false non-matches. For a fraud-risk score, changing the alert threshold may have the reverse numerical direction. Any threshold change should be assessed against both error types using representative data.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules