Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

111–120 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#111

Earlier quoted context omitted.

Last time I applied for a credit card online, they asked me to take a video of myself and turn my head from side to side.

This sounds like a great way to get sufficient images/video of you to create a deepfake that could pass this test. Hmmm...

New mandatory security rule: Employees must never turn their heads side to side in a meeting.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#112
Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hardware), it has a lot of advantages over what you might call trick-based approaches:

1. Robust to AI improvements.

2. Blocks all kinds of faking and tampering, not just deepfakes.

3. With a bit of work can securely timestamp the video such that it can become evidence useful for dispute resolution.

4. Also applies to audio.

5. Works in the static/offline scenario where you just get a video file and have to check it.

There are probably other advantages too. The way to do such things has been known about for a long time. The issue is not any missing pieces of tech but simply building a consensus amongst hardware vendors that there's actual market demand for [deep]fake-proof IO.

In reality, deepfakes have been around for some years now but have there been any reports of actual real world attacks using them? Not sure, I didn't hear of any but maybe there's been one or two. Problem is, that's not enough to sustain a market. Attacks have to become pretty common before it's worth throwing anything more than cheap heuristics at it.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation

The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year.

I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound.

For an extreme opponent you may need additional steps. So this sideways trick probably isn't enough for CIA or whatnot, but that's about as fringe as you can get and very little generic advice applies anyway.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#114

Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hard…

Then you just point the webcam at a screen or microphone at a speaker?

I really don't think moving our trust to unknown, unnamed manufacturers of hardware in far away places is a solution.

The solution is not going to be high tech, imho. Just like we have learned a skepticism resulting from Photoshop, we'll learn a skepticism of live video or audio.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#115
post #113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

No post body was provided.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#116
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

I wonder how good the deepfake would be for things it didn't have training data on. For example, making an extreme grimace. Or have the caller insert a ping pong ball in his cheek to continue, or pull his face with his fingers. One thing I notice with colorized movies is the color of the actor's teeth tends to flicker between grey and ivory. I wonder if there are similar artifacts with deep fakes.

Years and years of having to do increasingly more insane things to log into banking apps until we’re fully doing karaoke in our living rooms or stripping nude to reveal our brand tattoos

Re: To uncover a deepfake video call, ask the caller to turn sideways

#117

Earlier quoted context omitted.

Last time I applied for a credit card online, they asked me to take a video of myself and turn my head from side to side.

May I ask what card/Institution? This would be an immediate no for me.

I'd trust the data with a (real, not online) bank more than most other companies like Google.

I'd be more worried about people hacking into networked security camera DVRs at stores and cafes and extracting image data from there. Multiple angles. Movement. Some are very high resolution these days. Sometimes they're mounted right on the POS, in your face. Sometimes they're actually in the top bezel of the beverage coolers.

Banks are the hardest way to get this data, not the easiest one.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#118

Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hard…

Applying technological solutions to social problems hasn't worked a single time before, but SURELY it'll work this time

Re: To uncover a deepfake video call, ask the caller to turn sideways

#119
Patiently waiting for the government(s) to step in and start providing a modern ID service - a driver license with a built in private key, a fingerprint unlock, and a PIN.

The combination of the three can still be defeated by someone following you, stealing the card, lifting fingerprint from a glass, and spying the PIN, but that’s a lot of trouble to go through and online identity fraud will become extinct.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#120
post #82
post #53

Probably a more robust test would be asking the caller to run their hand through their hair a few times. Maybe you could pre-render a few samples, but it would be trivial to request the person pass their hands through their hair in a specific way, or simply do it again after their hair is already messed up a bit from the first time. It could still be defeated by the caller having the same hair style (or wearing a goo…

in my career i've personally worked with no less than half a dozen bald coworkers. i do think this is a good idea but won't work for everyone

why wouldn't it still work? Hands in front of faces are already a huge problem for live deepfakes, wether or not the faker or the faker are bald shouldn't make this much easier. The only scenario this wound't be extra difficult for is if both the faker and the person being faked are bald, and even then the presence of a hand will likely cause some artifacts.
Post reply on HN