Implementing Face Recognition in a Mobile Application
An app for customer verification needs accurate biometrics, but incorrect anti-spoofing turns the system into a filter for photos from a screen. Legal risks are no less: overlooked GDPR or 152-FZ requirements lead directly to app store rejection. We solve both levels—from detection to compliance—turnkey.
A typical scenario: a developer integrates ML Kit for detection, extracts a face embedding via FaceNet, and stops there. The first security review shows the system accepts a printed photo. And App Store Review rejects the build due to missing explicit biometric consent. To avoid these issues, the pipeline must include three mandatory steps: detection + alignment, embedding, anti-spoofing—and a compliance audit.
Our experience shows: without splitting the pipeline into independent steps, you cannot achieve stable results across different devices and lighting conditions. Below is how we do it.
How the Face Recognition Pipeline Works
The pipeline consists of three sequential steps:
-
Detection — find a face in the frame, get a bounding box and landmarks.
-
Verification/Identification — get a face embedding (128- or 512-dimensional vector) and compare against a database of references.
-
Anti-spoofing — ensure a live person is in front of the camera, not a photo/video/mask.
Skipping the third step creates a system that any printed photo can bypass. Even basic passive anti-spoofing filters out 70–80% of simple attacks.
Detection and Landmarks
The choice of library depends on the platform and accuracy requirements. Below is a comparison of two main approaches:
| Framework |
Platform |
Landmark accuracy |
Inference time |
Features |
| Vision Framework |
iOS |
76 key points |
8–15 ms on iPhone 12 |
Built-in, no network required, works with ML models |
| ML Kit Face Detection |
Android |
up to 468 points (contour detection) |
15–30 ms on Pixel 6 |
Requires Google Play Services; detection available in ACCURATE mode |
On iOS: VNDetectFaceLandmarksRequest from Vision framework. Returns VNFaceObservation with landmarks (76 points: face contour, eyebrows, nose, lips, eyes) and boundingBox. On-device, no network, ~8–15 ms on iPhone 12.
On Android: ML Kit Face Detection with FaceDetectorOptions.ACCURATE. Returns FirebaseFace with 468 points when setContourDetectionEnabled(true) is enabled—full face mesh. Heavier but needed for precise face alignment before embedding.
Face alignment before embedding inference is critical. Without alignment by the eyes, face recognition accuracy drops by 15–25%. Geometrically: find the centers of the eyes, calculate the rotation angle, affine transform to a standard position (eyes at 1/3 from the top, symmetric).
Embedding and Comparison
Standard choices are FaceNet (128D) or ArcFace (512D). FaceNet is available out of the box as a TFLite model. ArcFace is more accurate but heavier. For mobile: FaceNet INT8—12 MB, inference ~35 ms on Pixel 6.
Cosine distance between vectors is the primary metric. Threshold for "same face": typically cosine similarity > 0.75. The threshold is tuned to the specific dataset—it is not a universal constant.
Storage of reference embeddings: in encrypted Keychain (iOS) or EncryptedSharedPreferences / Android Keystore (Android). Never store original photos. Embeddings are (theoretically) irreversible, photos are not.
How Anti-Spoofing Works
Two approaches:
| Type |
Principle |
Performance |
Protection against 3D masks |
| Passive |
Skin texture analysis, optical artifacts |
<10 ms, no user action |
Weak (30–40% false accept) |
| Active |
Challenge-response: blink, turn head |
50–200 ms, requires UX |
Strong (up to 98% attack detection) |
Passive anti-spoofing is faster, but active is 2× more reliable against 3D masks. For banking and fintech apps, we recommend a combination: passive + active challenge. For corporate access, passive is sufficient. Get a consultation to choose the optimal method for your scenario.
What Is Needed for Compliance?
Biometric data (face embedding is biometrics under GDPR Article 9 and 152-FZ Article 11) requires explicit user consent, separate from the general Terms of Service. Storing embeddings in the cloud is allowed only with encryption in transit and at rest and a DPA with the provider. If the app operates in Russia with Russian users, 152-FZ data localization requirements apply.
The App Store Review Guidelines Section 5.1.1 explicitly prohibit collecting biometrics without explicit permission. Rejection on this point is common. Order a compliance audit at the start—it saves weeks of rework.
What Is Included in the Work
Implementation includes:
- Integration of the detector (Vision / ML Kit) and selection of the embedding model (FaceNet / ArcFace)
- Development of active or passive anti-spoofing
- Setup of encrypted reference storage
- Preparation of compliance documentation (consents, DPA)
- Testing against 100+ attack samples (photo, video, mask)
- Deployment to App Store / Google Play with review support
- Source code, documentation, and team training
Timelines and Guarantees
Detection + identification on-device without anti-spoofing: 1–2 weeks. Full pipeline with anti-spoofing, encrypted storage, and compliance audit: 3–4 weeks. The cost is calculated individually.
We guarantee accuracy of at least 95% FAR at 0.1% FRR on a reference dataset (specified per task). We have 5+ years and 20+ projects with biometrics in banks and fiscal systems. Contact us for a consultation and to evaluate the integration plan for your product.
Machine Learning in Mobile Apps: CoreML, TFLite, and On-Device Models
We distinguish two fundamentally different approaches: an app with on-device AI and an app that simply calls a cloud API. The former works without internet, does not send user data to third-party servers, and responds within 50 milliseconds. The latter depends on network latency and pricing plans. Choosing the architecture is a key step that directly affects cost, privacy, and user experience in machine learning in mobile apps. Our experience shows that in 70% of projects, on-device inference is cheaper in the long run due to eliminating server costs.
How to Choose Between CoreML and TFLite for On-Device Inference?
CoreML — Apple's native framework for running ML models on device. Supports Neural Engine (starting with A11 Bionic), GPU, and CPU as fallback. Models are converted to .mlmodel format via coremltools from PyTorch, ONNX, or TensorFlow. Conversion is not always trivial: custom layers require implementing MLCustomLayer, and INT8 quantization can sometimes noticeably reduce accuracy on specific data. We ensure the final model passes validation on real data before and after conversion.
TensorFlow Lite — cross-platform alternative for Android and Flutter. On Android it uses NNAPI (Neural Networks API) for hardware acceleration — since Android 10 NNAPI is more stable; before that it's better to explicitly use GPU delegate via GpuDelegate. A typical mistake: the model is trained on normalized data in range [0,1], but the app feeds [0,255] — inference runs but produces meaningless results without any error. We include an automatic input data validation module in the SDK.
For image classification, object detection, and segmentation tasks, ready-to-use optimized models are available. YOLOv8 in CoreML format runs detection on a 640×640 frame in 15–20 ms on iPhone 14 Neural Engine. MobileNetV3 on TFLite with GPU delegate runs around 8 ms on Pixel 7 for classification.
| Parameter |
CoreML |
TFLite |
| Platforms |
iOS, macOS, watchOS |
Android, iOS, Linux, embedded |
| Hardware acceleration |
Neural Engine, GPU, CPU |
NNAPI, GPU (OpenCL/OpenGL), CPU |
| Quantization support |
FP16, INT8 (with coremltools) |
FP16, INT8, dynamic range |
| Custom operations |
Via MLCustomLayer (Swift) |
Via delegates (Java/Kotlin) |
| Model bundle size |
~3–5 MB (MobileNetV2 quantized) |
~2–4 MB |
What If You Need Text Generation On-Device?
Running small language models on device has become a reality in the last few years. Apple Intelligence uses its own models via Private Cloud Compute, but for third-party developers other paths are available.
llama.cpp with Metal backend on iOS is a working approach for phi-3-mini (3.8B parameters, 4-bit quantization, ~2.3 GB). Inference: 15–25 tokens/second on iPhone 15 Pro. For integration in Swift, use the Swift Package llama.swift or a wrapper via C interface llama.h. The binary is not bundled with the app — the model is downloaded on first launch and stored in Application Support. Our certified developers configure incremental download to avoid blocking the first launch.
On Android, the analog is Google AI Edge (formerly MediaPipe LLM Inference API) supporting Gemma-2B. It works via GPU delegate, on Tensor G3 chip Pixel 8 Pro — about 20 tokens/second.
Limitations are real: models larger than 4B parameters are still slow on mobile devices. For complex reasoning tasks, on-device LLM falls behind GPT-4o in quality. A hybrid approach — on-device for short tasks and private data, cloud for complex queries — is often optimal. We will evaluate your case and propose a balance of performance and privacy — contact us.
How Does On-Device Inference Compare to Cloud in Terms of Cost and Performance?
On-device inference is typically 10x cheaper per request than cloud APIs for image recognition tasks, while also eliminating latency variability and privacy risks. The table below summarizes the trade-offs.
| Criteria |
On-Device Inference |
Cloud API |
| Latency |
<50ms |
200–500ms (including network) |
| Cost per 1M requests |
$0 (no server) |
$10–50 (AWS Rekognition, Google Vision) |
| Privacy |
Data stays on device |
Data sent to server |
| Offline |
Yes |
No |
| Scalability |
No server scaling issues |
Need to provision API capacity |
For an app with 100k MAU running 10 image recognitions per user per month, on-device inference can save up to $5,000 monthly compared to cloud API. Get a free consultation on your ML architecture today.
Integrating OpenAI API and Other Cloud Models
For scenarios where cloud inference is acceptable, integrating OpenAI, Anthropic, or Google Gemini is an HTTP client + streaming SSE. In Swift, AsyncThrowingStream is convenient for streaming responses. In Kotlin, use Flow.
Critically: API keys must never be stored in the app bundle. Even an obfuscated key can be extracted from the IPA in 10 minutes using strings or frida. Correct architecture: mobile app → your own backend → OpenAI API. The backend controls rate limiting, logs requests, and protects the key.
What Is Included in the Work (Deliverables)
- Trained and quantized model for the target device (documentation with metrics)
- SDK for integration (Swift/Kotlin/Flutter) with call examples
- Performance tests on 3–5 real devices
- Instructions for OTA model updates
- Support during App Store / Google Play moderation (compliance with Guidelines 4.2, 5.1)
- 2 weeks of technical support after release
Typical Project Pipeline
-
Task analysis — measure latency, privacy, size, supported devices.
-
Model prototyping — in Python, evaluate accuracy on target data.
-
Conversion and quantization — for CoreML/TFLite with validation.
-
Integration into the app — model wrapped in a service layer (easy to swap CoreML ↔ TFLite ↔ cloud).
-
Testing — on real devices, measure FPS, RAM, battery.
-
Deployment — via TestFlight / Firebase App Distribution, monitor metrics.
Timelines: integration of a ready CoreML/TFLite model — 1–2 weeks, development of a custom model with mobile optimization — from 6 weeks, on-device LLM chat with personalization — 4–8 weeks.
Why We Take on Complex Cases?
10+ years of experience in mobile development, 50+ implemented AI/ML solutions, guarantee of compatibility with current iOS and Android versions. All projects undergo code review and load testing. The cost includes preparation of moderation documentation and training of your team.
Contact us — we will help you choose the architecture and implement ML in your app turnkey. Order an audit of your existing solution — we will assess the potential for server cost savings free of charge. In some projects, savings can reach significant amounts per month.