> ...a photo agency that makes stock photos available on its website with copyright watermarks can markpaint them in such a way that anyone using common editing software to remove a watermark will fail; the copyright mark will be markpainted right back. So watermarks can be made a lot more robust. I fail to see how this can actually combat against someone with the patience to manually paste out copyright marks using…
It won't defeat manual edit, nor do the authors claim it. They do however make a solid point in saying it will defeat cheap automated manipulation / deepfakes at scale that would otherwise be easy with inpainting features. Anything that can help us differentiate authentic images from manipulated ones, especially when it comes to news, is imo a welcome addition in the arsenal of societies attached to the concept of ve…
A new way to detect ‘deepfake’ picture editing
41–50 of 92 posts
Re: A new way to detect ‘deepfake’ picture editing
#42It's hard to see this as much anything but snake oil. While the technique allegedly allows you to target multiple models, it still requires you to know what adversarial model you're targeting before the fact. If the adversary sees there's visible artifacts they'll just change a few parameters or use a different model and be good to go none the less. In short, while this might be academically interesting, I can't help…
A few weeks ago, there was a post here about that guy who deepfaked female profile pictures. He showed that the visible artifacts go away by merely scaling up the number of parameters in the model. Give it a few years and these fake images will be impossible to detect unless we agree on some way of cryptographically signing images from real cameras.
Re: A new way to detect ‘deepfake’ picture editing
#43Earlier quoted context omitted.
It won't defeat manual edit, nor do the authors claim it. They do however make a solid point in saying it will defeat cheap automated manipulation / deepfakes at scale that would otherwise be easy with inpainting features. Anything that can help us differentiate authentic images from manipulated ones, especially when it comes to news, is imo a welcome addition in the arsenal of societies attached to the concept of ve…
Authentic images do not exist. They always include a viewpoint. Example here: https://2.bp.blogspot.com/-rHeyzklapsE/W5-yUBVnbxI/AAAAAAAAA...
Re: A new way to detect ‘deepfake’ picture editing
#44Re: A new way to detect ‘deepfake’ picture editing
#45While all this stuff around deep fakes and its detection is interesting I'm still left wondering why we don't use cryptography to prove if an image is authentic or not.
Besides, what will the camera sign? The produced JPG? The raw file? What about rescaling? Do we want ZKPs that a JPG was achieved by nothing more than re-scaling and tone-mapping another JPG or RAW file? Those ZKPs are going to be massively big and slow to verify.
Re: A new way to detect ‘deepfake’ picture editing
#46Re: A new way to detect ‘deepfake’ picture editing
#47Re: A new way to detect ‘deepfake’ picture editing
#48Re: A new way to detect ‘deepfake’ picture editing
#49Earlier quoted context omitted.
A few weeks ago, there was a post here about that guy who deepfaked female profile pictures. He showed that the visible artifacts go away by merely scaling up the number of parameters in the model. Give it a few years and these fake images will be impossible to detect unless we agree on some way of cryptographically signing images from real cameras.
Cryptographic keys embedded in hardware worked really well for the DRM industry. Eventually someone will work out how to extract the key, then create malware to spread around android devices to send back millions of valid keys. What do you do then? Blacklist millions of real peoples cameras and prevent them from using the internet?
Re: A new way to detect ‘deepfake’ picture editing
#50Earlier quoted context omitted.
A few weeks ago, there was a post here about that guy who deepfaked female profile pictures. He showed that the visible artifacts go away by merely scaling up the number of parameters in the model. Give it a few years and these fake images will be impossible to detect unless we agree on some way of cryptographically signing images from real cameras.
I'm not hopeful that the latter will do much. Just do your deepfake, point a camera at your screen and press the shutter button to get it cryptographically signed..? Ok, so that's tongue in cheek and we'd see some artifacts there but the general principle works. You could intercept the signal from the CCD, or just extract the signing key from the camera's ROM, etc etc.