Live data from Hacker News

A new way to detect ‘deepfake’ picture editing

lightbluetouchpaper.org

41–50 of 92 posts

Re: A new way to detect ‘deepfake’ picture editing

#41
post #19

> ...a photo agency that makes stock photos available on its website with copyright watermarks can markpaint them in such a way that anyone using common editing software to remove a watermark will fail; the copyright mark will be markpainted right back. So watermarks can be made a lot more robust. I fail to see how this can actually combat against someone with the patience to manually paste out copyright marks using…

It won't defeat manual edit, nor do the authors claim it. They do however make a solid point in saying it will defeat cheap automated manipulation / deepfakes at scale that would otherwise be easy with inpainting features. Anything that can help us differentiate authentic images from manipulated ones, especially when it comes to news, is imo a welcome addition in the arsenal of societies attached to the concept of ve…

Authentic images do not exist. They always include a viewpoint. Example here: https://2.bp.blogspot.com/-rHeyzklapsE/W5-yUBVnbxI/AAAAAAAAA...

Re: A new way to detect ‘deepfake’ picture editing

#42

It's hard to see this as much anything but snake oil. While the technique allegedly allows you to target multiple models, it still requires you to know what adversarial model you're targeting before the fact. If the adversary sees there's visible artifacts they'll just change a few parameters or use a different model and be good to go none the less. In short, while this might be academically interesting, I can't help…

A few weeks ago, there was a post here about that guy who deepfaked female profile pictures. He showed that the visible artifacts go away by merely scaling up the number of parameters in the model. Give it a few years and these fake images will be impossible to detect unless we agree on some way of cryptographically signing images from real cameras.

Cryptographic keys embedded in hardware worked really well for the DRM industry. Eventually someone will work out how to extract the key, then create malware to spread around android devices to send back millions of valid keys. What do you do then? Blacklist millions of real peoples cameras and prevent them from using the internet?

Re: A new way to detect ‘deepfake’ picture editing

#43
post #41
post #19

Earlier quoted context omitted.

It won't defeat manual edit, nor do the authors claim it. They do however make a solid point in saying it will defeat cheap automated manipulation / deepfakes at scale that would otherwise be easy with inpainting features. Anything that can help us differentiate authentic images from manipulated ones, especially when it comes to news, is imo a welcome addition in the arsenal of societies attached to the concept of ve…

Authentic images do not exist. They always include a viewpoint. Example here: https://2.bp.blogspot.com/-rHeyzklapsE/W5-yUBVnbxI/AAAAAAAAA...

I'd say cropping an image leaves the image 'authentic'. Even if it changes the meaning. It's when you start painting out objects that you are making a 'non-authentic' picture.

Re: A new way to detect ‘deepfake’ picture editing

#44
post #38
post #33

The better you can detect deepfakes, the better deepfakes will be using that method as discriminator.

I guess that means they better start working on non differentiable ways of detecting deep fakes.

Most functions can be approximated by differentiable ones.

Re: A new way to detect ‘deepfake’ picture editing

#45
post #30

While all this stuff around deep fakes and its detection is interesting I'm still left wondering why we don't use cryptography to prove if an image is authentic or not.

Will signing come from the camera? At that point you run into DRM.

Besides, what will the camera sign? The produced JPG? The raw file? What about rescaling? Do we want ZKPs that a JPG was achieved by nothing more than re-scaling and tone-mapping another JPG or RAW file? Those ZKPs are going to be massively big and slow to verify.

Re: A new way to detect ‘deepfake’ picture editing

#47
post #8
post #6

Earlier quoted context omitted.

Friedrich Nietzsche called that "Superhuman", or "Übermensch".

And that we're just a tightrope stretched over the abyss from the monkey until ai.

From where or from whom will 'ai' be getting its moral outlook on the actions it takes?

Re: A new way to detect ‘deepfake’ picture editing

#49

Earlier quoted context omitted.

A few weeks ago, there was a post here about that guy who deepfaked female profile pictures. He showed that the visible artifacts go away by merely scaling up the number of parameters in the model. Give it a few years and these fake images will be impossible to detect unless we agree on some way of cryptographically signing images from real cameras.

Cryptographic keys embedded in hardware worked really well for the DRM industry. Eventually someone will work out how to extract the key, then create malware to spread around android devices to send back millions of valid keys. What do you do then? Blacklist millions of real peoples cameras and prevent them from using the internet?

You only need a method of key invalidation and renewal, that's all. Ssl certificates have been facing this problem for years. The threat model is equal to someone infecting millions of devices and then sending back banking data, so it's not like people aren't working on mitigating that stuff.

Re: A new way to detect ‘deepfake’ picture editing

#50

Earlier quoted context omitted.

A few weeks ago, there was a post here about that guy who deepfaked female profile pictures. He showed that the visible artifacts go away by merely scaling up the number of parameters in the model. Give it a few years and these fake images will be impossible to detect unless we agree on some way of cryptographically signing images from real cameras.

I'm not hopeful that the latter will do much. Just do your deepfake, point a camera at your screen and press the shutter button to get it cryptographically signed..? Ok, so that's tongue in cheek and we'd see some artifacts there but the general principle works. You could intercept the signal from the CCD, or just extract the signing key from the camera's ROM, etc etc.

You can already do that today to fool basic image forensics. Security is never absolute, but if you make the hassle big enough it might suffice to protect the general population. Just like almost all smartphones don't let you mess with the wifi card or spoof your mac address unless you root them. If that wasn't the case, you'd see way more hostapd-wpe attacks these days, since every kid could do it.
Post reply on HN