Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

171–180 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#171

Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hard…

Then you just point the webcam at a screen or microphone at a speaker? I really don't think moving our trust to unknown, unnamed manufacturers of hardware in far away places is a solution. The solution is not going to be high tech, imho. Just like we have learned a skepticism resulting from Photoshop, we'll learn a skepticism of live video or audio.

You could layer on IR depth mapping, available in many Windows Hello providing camera systems.

I happen to agree with the other voices here saying this is a folly game of cat and mouse, but there are near-time methods of making this harder to fool. And that might be enough for now.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#173
You don't need to do silly head movements. You could send the other person and email with a password, or a text, or a signal message or ask where you last had a drink together or...

If you are concerned that all methods of communications are compromised you wouldn't suddenly trust zoom if they do some silly head movement.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#174
post #158
post #113

Earlier quoted context omitted.

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

Self-driving cars are a million times harder than this, this is a terrible comparison. Getting a model to work with images turned sideways is a few lines of code (just turn image sideways at training time).

>> images turned sideways

Instead of pictures of faces, now they're just vertical lines.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#175

Earlier quoted context omitted.

May I ask what card/Institution? This would be an immediate no for me.

I'd trust the data with a (real, not online) bank more than most other companies like Google. I'd be more worried about people hacking into networked security camera DVRs at stores and cafes and extracting image data from there. Multiple angles. Movement. Some are very high resolution these days. Sometimes they're mounted right on the POS, in your face. Sometimes they're actually in the top bezel of the beverage cool…

No bank is going to run such a system in house. It will be a contracted service whose data is one breach away from giving fraudsters a firehose of data to exploit their victims.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#176

Earlier quoted context omitted.

This sounds like a great way to get sufficient images/video of you to create a deepfake that could pass this test. Hmmm...

New mandatory security rule: Employees must never turn their heads side to side in a meeting.

I work as a Digital Gardener[1] and we’re trained to NEVER use our real name.

- [1] https://youtu.be/XQLdhVpLBVE

Re: To uncover a deepfake video call, ask the caller to turn sideways

#177
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

I wonder how good the deepfake would be for things it didn't have training data on. For example, making an extreme grimace. Or have the caller insert a ping pong ball in his cheek to continue, or pull his face with his fingers. One thing I notice with colorized movies is the color of the actor's teeth tends to flicker between grey and ivory. I wonder if there are similar artifacts with deep fakes.

"Please put one finger behind each ear and flap them at me."

Re: To uncover a deepfake video call, ask the caller to turn sideways

#178

Earlier quoted context omitted.

Last time I applied for a credit card online, they asked me to take a video of myself and turn my head from side to side.

Yes I believe this sideways turning thing is mandatory when doing online identifications

What is an "online identification"? In what context would such a thing occur?

Re: To uncover a deepfake video call, ask the caller to turn sideways

#179

Earlier quoted context omitted.

May I ask what card/Institution? This would be an immediate no for me.

I'd trust the data with a (real, not online) bank more than most other companies like Google. I'd be more worried about people hacking into networked security camera DVRs at stores and cafes and extracting image data from there. Multiple angles. Movement. Some are very high resolution these days. Sometimes they're mounted right on the POS, in your face. Sometimes they're actually in the top bezel of the beverage cool…

"I trust you more than Google" is a pretty low bar in terms of personal data.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#180
post #75

Serendipitously over the weekend I was thinking about a future where for key sensitive data access (e.g. production main) you may need to have a quick 5 minute call (4th factor, "3D verification") where you would be asked to turn on your camera and be asked to answer some simple question and in different positions... Main thinking was how out of control it would get, it would probably end up looking like anti-cheat s…

We have PK cryptography you know, yubikeys and such.

You need some way to activate the yubikey. That could well be an online interview.
Post reply on HN