Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

151–160 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#151
post #53

Probably a more robust test would be asking the caller to run their hand through their hair a few times. Maybe you could pre-render a few samples, but it would be trivial to request the person pass their hands through their hair in a specific way, or simply do it again after their hair is already messed up a bit from the first time. It could still be defeated by the caller having the same hair style (or wearing a goo…

> run their hand through their hair

That would have trouble passing anti-discrimination requirements: disability (no hands), medical (bandanna covering cancer treatment hair loss), religious (burka, rasta, yarmulke, sheitel), racist (cornrow).

And trouble with: dreadlocks (can’t run fingers through), bald headed guys (as mentioned by sibling comment), and people with hairdo’s (coiffure, hairspray, topknots, plaits etcetera).

Re: To uncover a deepfake video call, ask the caller to turn sideways

#153

Earlier quoted context omitted.

Agreed. Now they have the data to deep fake you turning your head. I hope they delete the data immediately after use.

Frankly, of all the personally identifying data I share with my bank, a low resolution phone video of the side of my head is the least worrying. It's like worrying the government knows my mum's maiden name! In the eventuality that robust deepfake technology to provide fluid real-time animation of my head from limited data sources exists and someone actually wants to use it against me, they can probably find video con…

And, if deepfake technology becomes so easy to use, video of your face will no longer serve to identify you.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#154

Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hard…

So your answer is .. more DRM?

Re: To uncover a deepfake video call, ask the caller to turn sideways

#156
post #113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

In terms of this particular tech previous obvious limitation, namely no blinking, worked for something like a quarter from discovery.

Venn diagram of people who someone wants to trick by this particular tech, those who read any security guidelines and those worthy of applying this kind of approach to in the first place is however pretty narrow for the foreseeable future. It's more of a narrative framing device to talk about 'what to do to uncover deepfake video call' as a way to present interesting current tech limitations - not that I particularly mind it.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#157
post #19
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

As far as I can see, secops is an eternal cat-and-mouse game.

Some see secops as futile until the tools are here. So we're making those tools instead.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#158
post #113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

Self-driving cars are a million times harder than this, this is a terrible comparison.

Getting a model to work with images turned sideways is a few lines of code (just turn image sideways at training time).

Re: To uncover a deepfake video call, ask the caller to turn sideways

#159

Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hard…

The solution you propose sounds vastly overengineered. Why would we need remote attestation, tampering resistance and enclaves when this is simply a problem of your peers being unauthenticated?

If you care about the identity of who you are speaking to remotely, the only solution is to cryptographically verify the other end, which just requires plain old key distribution and verification. It's just not widespread enough today for videocalls because up to now, there wasn't much need for this.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#160
post #44

Earlier quoted context omitted.

I'm not sure there's a basic question we can ask that a lot of human users wouldn't fail. President of the country? Too difficult.

The point isn't to check if they actually know - it's to gauge the response. If they say "I don't know" that may be a valid answer, but if they say "George Bush" then something is seriously wrong.

Also, if a human has to be told a basic fact they'll generally provide an indication of embarrassment or an excuse or "why are you asking me these questions", not try to continue the conversation with interesting facts...
Post reply on HN