Authors - Oussama H Hamid, Ayman Ahmed, Arif Al-Nahdi Abstract - The increasing reliance on web-based services has intensified the need for secure and reliable authentication mechanisms. Facial recognition has emerged as a widely adopted biometric modality owing to its convenience and contactless operation. However, static facial recognition systems remain vulnerable to presentation attacks such as printed-photo spoofing, screen replay, and mask-based impersonation. Existing face anti-spoofing techniques typically implement liveness detection as a preliminary filtering stage rather than as an integral component of the authentication decision process, creating a structural security gap that this paper addresses. A threat-model-driven architectural framework is proposed that integrates motion-based behavioural verification as a second authentication factor within facial recognition systems deployed in web-based environments. The framework introduces a system-generated challenge–response mechanism in which users perform randomised facial actions; facial landmark tracking and temporal motion analysis verify challenge execution in real time. A formal threat model distinguishes remote attackers, limited physical attackers, and generative adversarial attackers, and maps each adversary class to specific architectural countermeasures. A structured security analysis evaluates the framework against six presentation attack scenarios, including deepfake-based adaptive attacks. The proposed design operates on commodity hardware without specialised sensors, and the paper discusses biometric template protection, client–server deployment models, and privacy compliance in detail. This work contributes a principled architectural foundation for multi-factor biometric authentication in web environments and identifies concrete directions for future empirical validation