Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

141–150 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#141
It sounds like part of this issue is that it loses tracking if it can't see both of your eyes, which of course could be defeated by using a couple of cameras spaced at 45° to one another and calibrated to work together in some way.

Instead of a "deep fake" face swap an attacker could send virtual video from a fully-virtual environment using something like an nvidia Metahuman controlled by the camera array. I think that would be pretty easily detectable today but maybe less so with an emulated bad webcam and low-res video link. The models/rigging are only going to improve in the future.

The classic "Put a shoe on your head" verification route would still defeat that, at least until someone invents a very good tool to allow those types of models to spawn and manipulate props.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#142

Earlier quoted context omitted.

And now that scan could eventually end up out there someplace.

Agreed. Now they have the data to deep fake you turning your head. I hope they delete the data immediately after use.

Frankly, of all the personally identifying data I share with my bank, a low resolution phone video of the side of my head is the least worrying. It's like worrying the government knows my mum's maiden name!

In the eventuality that robust deepfake technology to provide fluid real-time animation of my head from limited data sources exists and someone actually wants to use it against me, they can probably find video content involving the side of my head from some freely available social network anyway.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#145
post #113

Earlier quoted context omitted.

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

It sounded to me like the parent poster wasn't saying not to use it, but simply that it cannot be relied upon. In other words, a deepfake could fail a 'turn sideways' test and that would be useful, but you shouldn't rely on a 'passing' test.

Another way to think of it might be that it can be relied on - until it can't. Be ready and wary of that happening, but until then you have what's probably a good mitigation of the problem.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#146

Earlier quoted context omitted.

I wonder how good the deepfake would be for things it didn't have training data on. For example, making an extreme grimace. Or have the caller insert a ping pong ball in his cheek to continue, or pull his face with his fingers. One thing I notice with colorized movies is the color of the actor's teeth tends to flicker between grey and ivory. I wonder if there are similar artifacts with deep fakes.

Years and years of having to do increasingly more insane things to log into banking apps until we’re fully doing karaoke in our living rooms or stripping nude to reveal our brand tattoos

Plenty of new content for the banks' TikTok followers to enjoy :D

Re: To uncover a deepfake video call, ask the caller to turn sideways

#147
post #12

Tangentially related but a simple way to bust a chatbot is to ask “What is larger, the Eiffel Tower or a shoe box?”

Here's what Meta's blenderbot replied with: "The Tokyo tower is taller than the eiffel tower. Interesting facts like that interest me. Do you know about it?"

I'm not surprised that it responded with a random unrelated fact, but it is funny that the second sentence is incredibly awkward, and the last one isn't really coherent English.

Just a total AI meltdown from one simple question.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#148

Earlier quoted context omitted.

This sounds like a great way to get sufficient images/video of you to create a deepfake that could pass this test. Hmmm...

New mandatory security rule: Employees must never turn their heads side to side in a meeting.

Interesting that you bring that up. The most egregiously invasive student and employee monitoring software requires that the subject always face the camera. That seems most ripe for bypassing with the current state of deepfakes. https://www.wired.com/story/student-monitoring-software-priv...

Re: To uncover a deepfake video call, ask the caller to turn sideways

#149
Heh, at some point I'm convinced that we'll use both:

* customizable 3D avatars

* customizable voices

to communicate in meetings and in communities (VR Chat style). So the origin won't be associated to your avatar or your voice, but it'll be associated with your account (like in good old chat).

Re: To uncover a deepfake video call, ask the caller to turn sideways

#150
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

What about reflections? When I worked on media forensics, the reflection discrepancy detector worked extremely well, but was very situational, as pictures were not guaranteed to have enough of a reflection to analyze.

Asking the subject to hold up a mirror and move it around pushes the matte and inpainting problems to a whole nother level (though it may require automated analysis to detect the discrepancies).

I think that too might be spoofable given enough time and data. Maybe we could have complex optical trains (reflection, distortion, chromatic aberration), possibly even one that modulates in real time...this kind of just devolves into a Byzantine generals problem. Data coming from an untrusted pipe just fundamentally isn't trustable.

Post reply on HN