Live data from Hacker News

To uncover a deepfake video call, ask the caller to turn sideways

metaphysic.ai

261–270 of 285 posts

Re: To uncover a deepfake video call, ask the caller to turn sideways

#261
post #227

Earlier quoted context omitted.

> The only way around this is to crop the input video quite heavily I mean that sounds a lot easier than making deep fakes work well with profile data surely?

Ask the caller to move their hand in front of the camera so the hand fully obstructs the view, and then slowly slide the hand to the side until it completely moves out of the view. Crop-resistant!

Until tech improves to fix this too. Detecting ai-generated content is a fool's errand since that is literally how they get better.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#262
post #113
post #18

Source: I work in the field. This is a current limitation, and an artifact of the data+method but not something that should be relied upon. If we do some adversary modelling, we can find two ways to work around this: 1) actively generate and search for such data; perhaps expensive for small actors but not well equipped malicious ones. 2) wait for deep learning to catch up, e.g. by extending NERFs (neural radiance fie…

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

The technique can in principle be defeated today so it should not be employed as a single test, but rather another arrow in the quiver.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#263
post #230

Earlier quoted context omitted.

The flip side of that is people feeling/assuming there's nothing they can really do with the resources they have therefore they choose to do nothing. Also, those that are actively using mitigations that are going to be outdated at some point are probably far more likely to be aware of how close they are to being outdated by encountering more ambiguous cases, as seeing the state of the art progress right in front of t…

Therefore, developing and customizing a proper framework for security and privacy starts by accurately assessing statutory, regulatory, and contractual obligations, and the organization's appetite for risks in balance with the organization's mission and vision, before developing the policies and and specific practices that organizational members should be doing. To use a Go (the game, not the language) metaphor, skil…

Asking the caller to turn sideways is also a cheap countermeasure without serious side-effects. So there's low risk to adopting it.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#264
post #258
post #113

Earlier quoted context omitted.

> This is a current limitation The thing with any AI/ML tech is that current limitations are always underplayed by proponents. Self-driving cars will come out next year, every year. I'd say that until the tech actually exists, this is a great way to detect live deepfakes. Not using the technique just because maybe sometime in the future it won't work isn't very sound. For an extreme opponent you may need additional s…

The self driving car of next year arrives just in time for the Iranian atomic bomb :-D which is ready in two years for about as long as I'm around. https://www.theatlantic.com/international/archive/2015/04/ir... If all the money on self driving cars would have been put into public transport (driverless on rails is a solved issue) and pushing shared car ownership instead, we might actually get somewhere towards conges…

We can already have congestion free-cities today, no new technology nor public transport required. We had the technology for quite a while now: congestion charging.

It works really well in Singapore to control congestion, and also worked well in London when they adopted it afterwards.

Public transport also works quite well in many places around the world.

It also used to work really well in North America in the past. A past when the continent was much poorer. (I'm mostly talking about USA plus Canada here.)

Public transport only works when after you step off the bus or train, you can get to your destination on foot. Density is outlawed in much of the USA and Canada.

https://www.youtube.com/watch?v=MnyeRlMsTgI&t=416s starts a good section about Fake London, Ontario. At great expense, they built a new train line. But approximately no one uses it, because you can't get anywhere when leaving the stations. The video shows an example of a station where the closest other building is about 150m away. And that's just a single building. The next ones are even further.

Land use restrictions and minimum parking requirements are a major roadblock. And just throwing money at public transit directly won't solve those.

Shared car ownership is an interesting idea. Uber can be seen as one implementation of this concept. It can be done profitably, but I'm not sure it has much impact on the shape of cities?

In the grand scheme of things, there's not much money being put into self-driving cars so far. A quick Googling gives a Forbes article that suggests about 200 billion USD.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#265

Earlier quoted context omitted.

It sounded to me like the parent poster wasn't saying not to use it, but simply that it cannot be relied upon. In other words, a deepfake could fail a 'turn sideways' test and that would be useful, but you shouldn't rely on a 'passing' test.

Another way to think of it might be that it can be relied on - until it can't. Be ready and wary of that happening, but until then you have what's probably a good mitigation of the problem.

How do you find out that it doesn't work?

Re: To uncover a deepfake video call, ask the caller to turn sideways

#266

Slightly more robust method... Ask the caller to move out of the frame and then back in again. You will see a noticable 'step' as the face that is partially in the frame suddenly gets detected as a face and the deepfake is applied. The only way around this is to crop the input video quite heavily - by at least one face diameter, which is a lot if the user is near the camera.

I don't think that's very robust. The entire image could easily be fake, as the face is fake, and people already have fake backgrounds. If the entire image is fake, there's no reason for the actual camera's view to match the fake image, so a wider angle camera would keep you in view as you move, and the system could generate a tighter fake view.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#267
post #4

Might be a great article but I had to stop reading since I couldn't bear the scroll hijacking.

No issue here. It appears your system allows it.

@Moderators, it very clearly appears from this puzzling case that the downvoting idea instilled in users is broken.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#268
Your face is one factor of identification, the solution is to add more.

A one time password that is shown or spoken would ensure authentication.

This is a general comment, in reality you want to do a real risk analysis, i.e. understand what you want to protect against, exactly.

Re: To uncover a deepfake video call, ask the caller to turn sideways

#269
post #240
post #190

Earlier quoted context omitted.

Not sure what to say to this one. Women can get sensitive, if requests of them can be seen in an unpleasant light. Women have also been historically tricked into posing for cameras, had their images misused, and are often quite sensitive about it. I thought my comment was legit, and on topic. If one is going to implement a policy where people have to slowly move their camera around their body, there may be severe mis…

The greater problem is that you've been breaking the site guidelines repeatedly. https://news.ycombinator.com/item?id=32364710 https://news.ycombinator.com/item?id=32364583 https://news.ycombinator.com/item?id=32299889 https://news.ycombinator.com/item?id=32299875 https://news.ycombinator.com/item?id=32295137 https://news.ycombinator.com/item?id=32292576 https://news.ycombinator.com/item?id=32292440 https://news.ycom…

Listen, I'm willing to try to adhere more closely. I see how some of the above posts click with what you're complaining about.

One suggestion ; some news articles are just, almost, entrapment. I feel like HN having an article about racism, is going to entice all sorts of comments which break the site guidelines.

Take my posts above ; I legitimately am concerned that by simply labeling those we are strongly opposed to, eg racists, we fail. If we just label, if we therefore misunderstand their motivations, any attempts at correction become flawed, and just plain don't work.

I want positive corrective action to fix things, not divisive posturing.

Obviously in hindsight I should not have waded in, I should have realised how my post, my motivations could be misunderstood. I agree, my bad. 100%. But once there, I'm left in this horrid position of suddenly feeling as if I'm being labelled as a racist sympathizer or some such. A reputation is a hard thing to leave on the ground, with no response!

Perhaps I should find better ways to wade out.

Anyhow, are we OK for now?

Re: To uncover a deepfake video call, ask the caller to turn sideways

#270
There is a tried and true method for making sure someone sending you pictures is real. Ask them to write today's date and a random word on a piece of paper and hold it up next to their face. People have been doing this on the Internet for ages. It doesn't authenticate them but it does show they are actually producing the pictures.
Post reply on HN