Live data from Hacker News

Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

spie.org

71–80 of 105 posts

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#71
post #16

The problem will increasingly be "whose algorithm do we believe". Internet has revealed that people believe mostly what they want to. We have seen that a large subset of people are believing Bill Gates is behind the pandemic. Why would masses somehow be more rational in picking the most rigorous and objective neural network to recognize deepfakes, than they are in making sense of the world in general? In the end we w…

This is absolutely right. I've become frustrated with people trying to fight misinformation by just telling anonymous strangers "facts". Algorithms are not going to help win the argument. There are a lot of people who hate those who they perceive to be "elite technocrats". And its not completely unwarranted! Its a really tricky challenge. The "steady state" of conversations online is mutual distrust. Unless we handle…

> trying to fight misinformation by just telling anonymous strangers "facts"

It’s even worse when you realize that most mistruths are factual. You can very easily lie with facts.

The texas sharpshooter falaft is a great example.

You get 500 samples, take 10 good samples, and say “Look! An objective truth in 10 samples we have success!”. You omit the other 490

You never said a lie, facts only, but the interpretation you lead people towards is a lie.

Or a more common example: Thing Y increases your risk of X by up to ten times!!!

Risk goes from 0.0001% to 0.001%. It’s completely irrelevant and you got a nice scary clickbait with objective facts.

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#72
The challenge with algos like this is that they could be used to claim events that actually did happen didn't. So as an example credible/convincing footage of Jeffrey Epstein by a pool in Paraguay last week could be 'identified as a deep fake' and discredited, despite other supporting facts and information that lent credence to veracity.

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#73
post #17

Earlier quoted context omitted.

The difference is that all the bacteria can become resistant to the antibiotic soon after it is created.

As can deepfakes. All it takes is an additional step to optimise wrt the model that tries to catch it.

Yeah, I was dismissing the analogy with antibiotics because usually it takes quite some time between creating the antibiotic and germs being resistant. But with deepfakes the arms race is almost instantaneous. The moment something appears to tell apart deepfakes, the moment people can train deepfakes against that something.

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#75
post #16

The problem will increasingly be "whose algorithm do we believe". Internet has revealed that people believe mostly what they want to. We have seen that a large subset of people are believing Bill Gates is behind the pandemic. Why would masses somehow be more rational in picking the most rigorous and objective neural network to recognize deepfakes, than they are in making sense of the world in general? In the end we w…

For me, one reason not to freak out about this is Photoshop.

It's been around for decades. Perfect photographic fakes (literally called "photoshops") are possible. Yet is there a great crisis of fake photographs taking over the news? Not really. The actual "fake news" barely even bother with photoshop (and those for whom it works, don't care about the quality). It's somehow still fairly easy to get context and at some point, you just have to trust a news outlet, just like you had to trust them for text-based news.

All we see is a trend of making it easier for people to subscribe to a bubble of "news" that fits their world view. The quality of the fakeness barely factors into this.

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#76
post #37

Earlier quoted context omitted.

Aren't digital signatures the best solution we have for this problem? Commercial entities want to have the priviledge of being able to modify the content submitted by content creators, but the culture of trusting i.e. Twitter over client verification needs to change.

Digital signatures would only match of the contents match bit for bit. This means that you can't recompress/remux/resize the video. This will probably provide a very poor ux for mobile or other bandwidth limited users. Also, if the video was used as part of another video (eg. TV broadcast), you'd either have to splice the digitally signed video into your existing stream (not modifying the bits at all), or provide the…

There's some cryptographic work in this direction. PhotoProof allows a photographer to prove that the image they're presenting is, e.g., the cropped version of the true original image they took. Video is still way out there, but at least people are thinking about this.

https://www.cs.tau.ac.il/~tromer/papers/photoproof-oakland16...

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#77
post #37

Earlier quoted context omitted.

Aren't digital signatures the best solution we have for this problem? Commercial entities want to have the priviledge of being able to modify the content submitted by content creators, but the culture of trusting i.e. Twitter over client verification needs to change.

Digital signatures would only match of the contents match bit for bit. This means that you can't recompress/remux/resize the video. This will probably provide a very poor ux for mobile or other bandwidth limited users. Also, if the video was used as part of another video (eg. TV broadcast), you'd either have to splice the digitally signed video into your existing stream (not modifying the bits at all), or provide the…

Signature chain for the transformations. The video host signs the pre-recompressed video and provides the original signature.

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#78
post #75
post #16

The problem will increasingly be "whose algorithm do we believe". Internet has revealed that people believe mostly what they want to. We have seen that a large subset of people are believing Bill Gates is behind the pandemic. Why would masses somehow be more rational in picking the most rigorous and objective neural network to recognize deepfakes, than they are in making sense of the world in general? In the end we w…

For me, one reason not to freak out about this is Photoshop. It's been around for decades. Perfect photographic fakes (literally called "photoshops") are possible. Yet is there a great crisis of fake photographs taking over the news? Not really. The actual "fake news" barely even bother with photoshop (and those for whom it works, don't care about the quality). It's somehow still fairly easy to get context and at som…

The other reason not to freak out about this is that we're already far down the path the people think deep fakes are creating.

Reddit and Twitter and the internet prove that people will react to an image of text by the tens of thousands, going straight into their brain. All of us have been guilty of this at some point.

To me it's naive to freak out about Photoshop and video deepfakes because it reveals that you're completely unaware of the degree of "shallowfaking". A screenshot of a headline or tweet spreads in a way that a deepfaked video can't, and it apparently goes right past our bullshit detector in a way that video can't.

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#79
post #75
post #16

The problem will increasingly be "whose algorithm do we believe". Internet has revealed that people believe mostly what they want to. We have seen that a large subset of people are believing Bill Gates is behind the pandemic. Why would masses somehow be more rational in picking the most rigorous and objective neural network to recognize deepfakes, than they are in making sense of the world in general? In the end we w…

For me, one reason not to freak out about this is Photoshop. It's been around for decades. Perfect photographic fakes (literally called "photoshops") are possible. Yet is there a great crisis of fake photographs taking over the news? Not really. The actual "fake news" barely even bother with photoshop (and those for whom it works, don't care about the quality). It's somehow still fairly easy to get context and at som…

Maybe, but I've found that a lot of viral images are doctored in one way or another.

Here are some links to recent examples of doctored photos. I know I've seen at least the deceptive image of cops "pointing a gun at children" when they were actually not on the front page of Reddit, so it's not like manipulated images have no effect:

https://www.hackerfactor.com/blog/index.php?/archives/884-Pr...

http://hackerfactor.com/blog/index.php?/archives/891-Count-o...

That said, remember that not all alterations are digital:

https://www.hackerfactor.com/blog/index.php?/archives/590-Un...

Re: Stopping deepfake news with an AI algorithm that can tell when a face doesnt fit

#80
post #73

Earlier quoted context omitted.

As can deepfakes. All it takes is an additional step to optimise wrt the model that tries to catch it.

Yeah, I was dismissing the analogy with antibiotics because usually it takes quite some time between creating the antibiotic and germs being resistant. But with deepfakes the arms race is almost instantaneous. The moment something appears to tell apart deepfakes, the moment people can train deepfakes against that something.

Perhaps the deepfake checking should be a third-party service? So you can only check so many deepfakes per day, limiting these attacks (i.e., you can't realistically put the checking inside a training loop). Just an idea ...
Post reply on HN