Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

161–170 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#161

Slightly more robust method... Ask the caller to move out of the frame and then back in again. You will see a noticable 'step' as the face that is partially in the frame suddenly gets detected as a face and the deepfake is applied. The only way around this is to crop the input video quite heavily - by at least one face diameter, which is a lot if the user is near the camera.

Or pass a piece of paper or splayed fingered hand slowly in front of your face?

Re: To uncover a deepfake video call, ask the caller to turn sideways

#162

"profile view challenge" coming in 3, 2, 1 ...

"Hey! To make sure you stay secure, we require a short video. Please look straight into the camera and tap the screen." "You look great! We just need you to blink 5 times, and you're almost done!" "Almost done! Just show us your best side and turn your head to the left like shown above." "Of course, you only have best sides. Just turn your head to the right like displayed above, and we can continue." "You've almost g…

I think you also need to add video of occluded areas, so backs of ears and nostrils too. Shouldn't be too invasive but you have got to do this so you don't get deep faked.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#163
post #135

Is there a "client side" way to detect this? Similar to how we can detect photoshopped still images: checking edges, shadows, pixels, etc... The benefit is you would not have to rely on issuing commands to the remote party.

Media forensics algorithms do work on various forms of rebroadcast, transmission, and compression, so yes this should be possible (for now). look up darpa medifor project. Siwei Lyu (in the article) did a bunch of work in this space. Also see Hany Farid and Shruti Agarwal. They've worked specifically with deep fake detection.

https://arxiv.org/abs/2004.14491

Re: To uncover a deepfake video call, ask the caller to turn sideways

#164
post #36

Hybrid Video/audio/semantic Captcha, perhaps? An audio prompt like 'Using your hand, repeat the numbers that I am signaling. Use set of fingers from what I am using'.

This is why I got really upset when my employer said the swimsuit competition segment of the interview was past its time. Its time is now!

I can wear a swimsuit, but the person verifying the video is not going to enjoy seeing me in a swimsuit, at all.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#165

Signed up for one of those 'neobanks' (that don't have physical branches) and part of the signup required me to turn my head sideways. I wondered why they wanted me to do that. Now I know.

Thanks for contributing to the dataset.

www.hownormalami.eu

Re: To uncover a deepfake video call, ask the caller to turn sideways

#166
It's a constant cat-and-mouse game. When I worked in this space (2019-2021), the best defense against deep fakes was looking at the microfacial behavior/kinematics of the "puppetmaster" and comparing against known standards of the deepfake subject. Works even if the fake is pixel-perfect (since it looks at the facial "wireframe" rather than the image itself). The obvious downside is you need sample data of the subject (and usually tons of it). I wonder if that general approach can be optimized. E.g. Deep fakes tend to struggle with certain fine movement/detail, if you had a reflection of the subject, the algorithm would have to not just replicate the main face and the mirror, but also be completely optically consistent.

Was a fun project, but the cat-and-mouse feeling was inescapable. For those curious, look up the DARPA MediFor project. Siwei Lyu (in the article) did a bunch of work in this space. Also see Hany Farid and Shruti Agarwal. They've worked specifically with deep fake detection.

https://arxiv.org/abs/2004.14491

Re: To uncover a deepfake video call, ask the caller to turn sideways

#167
I suppose this turning sideways trick will work until it doesn't.

I do appreciate everyone on this site contributing to my knowledge of infosec. I don't work directly in the space, but I feel the contributions on this site help educate those of us not directly working the profession.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#168
post #113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

> Self-driving cars will come out next year, every year.

"Come out" could mean different things in different contexts. Deepfake defence context is analogous to something like: there are cars on public roads with no driver at the wheel. And this is already true in multiple places in the world.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#169
post #113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

The only person who is promising self driving cars next year (and has done so every year for the past 5 years) is Elon Musk. Most respectable self-driving car companies are both further along than Tesla and more realistic about their timelines.
Post reply on HN