Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

191–200 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#191
post #113

Earlier quoted context omitted.

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

The only person who is promising self driving cars next year (and has done so every year for the past 5 years) is Elon Musk. Most respectable self-driving car companies are both further along than Tesla and more realistic about their timelines.

Let's take a look at some of those realistic timelines. A quick googling gave me a very helpful listicle by VentureBeat from 2017, titled Self-driving car timeline for 11 top automakers. [1]

Some examples:

Ford - Level 4 vehicle in 2021, no gas pedal, no steering wheel, and the passenger will never need to take control of the vehicle in a predefined area.

Honda - production vehicles with automated driving capabilities on highways sometime around 2020

Toyta - Self-driving on the highway by 2020

Renault-Nissan - 2020 for the autonomous car in urban conditions, probably 2025 for the driverless car

Volvo - It’s our ambition to have a car that can drive fully autonomously on the highway by 2021.

Hyundai - We are targeting for the highway in 2020 and urban driving in 2030.

Daimler - large-scale commercial production to take off between 2020 and 2025

BMW - highly and fully automated driving into series production by 2021

Tesla - End of 2017

It certainly wasn't just Tesla who was promising self-driving cars any second now. Tesla was definitely the most agressive, but failed to meet its goals just like every other manufacturer.

--

[1] https://venturebeat.com/2017/06/04/self-driving-car-timeline...

Re: To uncover a deepfake video call, ask the caller to turn sideways

#192

Long term, the only robust way to solve this is going to involve a remote attestation chain i.e. video that's being signed by the web cam as it's produced, and then transformed/recompressed inside e.g. SGX enclaves or an SEV protected virtual machine that's sending an RA to the other side. Although hard to set up (you need a lot of people to cooperate and CPU vendors have to bring these features back to consumer hard…

I think it would be useful if news outlets signed their video content using watermarking techniques. Then social media sites where news is shared could automatically check for recognised signatures for major outlets and give it a checkmark or something. The signature could be easily removed but video without the checkmark would then be suspicious. It would also be useful if they added signed timecodes to frames so it could be checked if the video has been edited.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#194
post #125

Earlier quoted context omitted.

> Banks are the hardest way to get this data, not the easiest one. Is this statement based on data or a hunch? A quick google turns up a lot of bank data breaches.

A quick google turns up a lot of bank data breaches. Because banks have to report data breaches. Do you think every neighborhood Gas-N-Blow is publicizing, or even knows, that it's been hacked?

Good point. I’m still wary of just assuming (if that’s what we’re doing here?) that old established organizations you’d expect to be secure are in fact secure. For example I would have expected credit rating agencies to be secure…

Mandatory reporting certainly helps IMO. Reporting should be mandatory for anyone handling PII.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#196
post #74

Earlier quoted context omitted.

For what it's worth, it looks more like an aggressive filter rather than a deepfake.

My thoughts too - but giving benefit of doubt to gp since it’s a still shot vs video

Of course - just my opinion. To me, it looks like the combination of low quality webcam + aggressive skin smoothening "beauty" filter.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#197
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

1) actively generate and search for such data

What about doing a bunch of video calls, and asking for callers to show their profile, "to guard against deepfakes?"

Re: To uncover a deepfake video call, ask the caller to turn sideways

#199

Earlier quoted context omitted.

It sounded to me like the parent poster wasn't saying not to use it, but simply that it cannot be relied upon. In other words, a deepfake could fail a 'turn sideways' test and that would be useful, but you shouldn't rely on a 'passing' test.

Another way to think of it might be that it can be relied on - until it can't. Be ready and wary of that happening, but until then you have what's probably a good mitigation of the problem.

I think the concern is complacency, and the inertia that existing security practices leads to security gaps in the future. "However, I don't know one organisation that doesn't have some outdated security guideline that they cling to, e.g. old school password rules and rotations."

Or put another way, humans can't be ready and wary, constantly and indefinitely. At some point, fatigue sets in. People move in and out of the organization. Periodic reviews of security practices don't always catch everything. Why something was implemented was forgotten by institutional memory. And then there's the cost for retraining people.

Post reply on HN