Tricks That Can Outsmart Deepfake Videos for Now
wired.com
wired.com
Deepfakes will have the same impact on law enforcement as convincing photoshopped pictures before. Which is to say absolutely no impact.
This comment seems to imply that all court admissible video evidence comes from trusted chains of custody and thereby trusted sources, which isn't necessarily the case.
What's stopping a defense attorney informing a jury about DeepFakes and having that fact factor into their "beyond a reasonable doubt" criterium for criminal cases?
DeepFakes have more potential in PsyOps than legal cases.
So, yes, that information should be given to the jury (as soon as it becomes accurate), and it will lower the potential for false positives (convictions), but with an equal and opposite increase in false negatives.
Is a verbal statement from an impartial witness useless? What if they say recognise the defendant as the criminal they witnessed? Obviously it's not as ideal as unfakable video evidence, but it is useful and has been the basis of legal systems for the millennia before computers and photography arrived.
Fakable video evidence is somewhere between these: you still have to account for the possibility that the person isn't honest, but don't have to worry about the fallibility of human memory.
My daughter's birth certificate could be reproduced 100% indistinguishably by a Fedex Office print shop. But it is backed up by a chain of people who, if necessary, will testify that it is authentic.
People think that testimony requires physical evidence to back it up (look at the reaction to Dr. Ford's accusations). But the legal reality is the opposite... physical evidence is only useful at trial to the extent that credible testimony can establish its authenticity and relevance.
So a deep fake video that looks exactly like a real video will only be useful at trial if it can be established as credible, by the testimony of credible witnesses.
All that said... there is more to life than the justice system. Forgeries have always taken in the gullible, so deep fakes will undoubtedly have a social impact, especially in the early days before the public is generally aware of the capabilities. This is undoubtedly one reason the press is starting to cover this technology so aggressively.
Also, a fake video of them tearing up a holy book can get them killed.
See the recent SCOTUS nominations for an example.
... and that's in a modern well-educated society.
In countries that are riven by sectarian and tribal rivalries, a convincing video can result in the deaths of millions.
Things will be fine, we'll have a few minor hiccups to resolve, but that will be it.
Some people really underestimate human ingenuity, do you really think that we won't be able to solve this issue in a manner of days if need be? Come on..
We're a few decades away from AI and immortality, and some people are worrying about fucking politics?
Think long term, and chill out.
But yeah, as others have said...I'm more worried about the political and social consequences of doctored videos. We already have a culture that is triggered at the slightest sign of perceived injustice. What if that injustice is a fabricated lie, architected by troll farms?
And that's not even considering what you can do without an actual forgery, just by messing with context e.g. https://www.buzzfeednews.com/article/meghara/we-had-to-stop-... https://www.nytimes.com/2018/04/21/world/asia/facebook-sri-l...
If "deep fakes" become easier to create than mis-contextified video, they can and will be used to spark conflict in areas with simmering tensions.
I say this as someone actively involved in avoiding the worst case scenarios; I wrote a piece here with more detail: https://www.washingtonpost.com/news/theworldpost/wp/2018/02/... (though HN is not the target audience).
[first paragraph repeated from another comment below]
If it's possible to fake HD video, it's also possible to fake grainy surveillance camera footage. If you prove the defendant was in a particular place, and you produce video purportedly from a surveillance camera in that place, a jury would believe it.
It sounds very much like complexity theory, where you definitely have problems that are easier to verify than solve (see NP hard).
(Otherwise I could do stuff like use a hash function to train a NN to compute input for hashes , for example, no?)
In theory, yes - you can. The training function could return a score - say the number of matching digits in the hash - and the NN will in theory learn what inputs produce the better output. If somehow, there is a weakness in the hash algorithm, it could stumble onto it - allowing it to get better at producing the right input to get the required output.
The simpler it is to deterministically manipulate, the easier it should be for a NN to learn to manipulate - even of the function is just returning a boolean or a "rating between 1 and 10". So yea, good hash functions are unlikely to be learned and solved, but photos and videos aren't designed to be hash functions.
(All that said, I'm willing to be bet the time and computing power you'd need to pour into this NN to break a good hash function is likely more than has ever existed in the sum of all past time + computing resources ;))
I think you mean NP. NP hard includes problems that are not in NP, such as the halting problem.
I'm not aware of any proof that photorealistic 3D rendering is in NP. If it is not, then verifying 3D cannot be said to be easy.
[1] https://en.wikipedia.org/wiki/P_versus_NP_problem#Reasons_to...
The main argument from your link is nobody has found an efficient algorithm for any of the 3,000+ studied problems after all this time.
And yet it’s also true that in the same span of time, nobody has been able to prove the that it’s not, either. No matter how hard they have tried.
“probably not” is just an opinion. I’ll wait for the formal proof. Till then it simply is not known whether or not.
if there was some score that would look at lighting etc, you probably could just tack it on to one of the loss functions somewhere and expect to see improvement.
maybe not enough to beat the system; or perhaps it would increase the lighting score but make the image obviously unrealistic in other ways we haven’t thought of.
basically at this point you would have a lot of if-else statements, like a "Expert System" AI in the 80s.
so much so that it would be better to use a NN to replace the loss/error/verification function instead of coding it by hand?
1) computationally intractable to forge. (e.g. requires simulating trillions of photons)
2) computationally tractable to verify
Sadly, my immediate gut intuition is that there is not such a problem, for a variety of reasons; but hopefully I'm wrong!
You can't solve the travelling salesman problem in polynomial time just by throwing machine learning at it...
On a mathematical level you can prove that machine learning will do a bad job for certain things, and this is what the parent talked about.
https://www.cc.gatech.edu/~lsong/papers/arxiv_rl_combopt.pdf
It does at least respectably well against the Concorde TSP solver although (unsurprisingly) doesn't beat it. Note that this also isn't a neural network that just maps a graph to a TSP solution; instead, the neural network function is a heuristic that guides the greedy construction of a solution one vertex at a time.
For instance one fundamental of forensic accounting is Benford's law [1]. Even in peripherally related with artistry it stands out. one of my never off the ground webcomic attempts with digital art I tried making backgrounds with perspective and I calculated the pixel spacing completely evenly - it stood out as unnaturally regular compared to doing it with just a straight-edge and a ruler on a cheap Wacom tablet.
Anyway I'm not sure that you can conclude that just because convolutions are 2D that deep neural networks are unable to understand 3D relations. For example this network seems to have a pretty good understanding of the 3D world:
https://deepmind.com/blog/neural-scene-representation-and-re...
Or more likely these NN-generated video fake the poor quality video and audio. The fake video author claims it was captured by hidden camera and faked person admit the fake illegal act.
This is the technique I'm thinking about https://www.youtube.com/watch?v=e9ASH8IBJ2U
Perhaps you need a high framerate in order for this to work?
That seems iffy. The problem with any automated system is that it can be used as an input into the training process. Things like matching weather reports to lighting sound more promising, because they'd require the manipulator to be more detailed in the data they collect, but that kind of thing also sounds a lot less reliable as an indicator.
"So", you might suggest, "let's keep the classifiers secret and only reveal specific classifications to the public! The learning rate at one example of day would be terrible." Sure, this approach would stop adversarial classifiers acting as training aides, but such a thing would be socially useless, since nobody would have a reason to trust your pronouncements.
I don't think there's a way anyone wins here. The end game is that we return to an almost 19th century model in which recorded media takes on a faded secondary role relative to in-person experience and trusted commentary. (And don't expect anyone to agree on who's "trusted".)
This has always been the case. I personally have issues with almost every major news outlet recently. Not just bias but blatant one-sided partisan reporting by nearly every actor. Not taking a side (nobody even remotely spoke to my values or concience) this election really opened my eyes. Both sides hatefully attacking each other for being hateful, and using that to justify further hate (of hate, so its cool, we arent all bigots right? Right!?) of the other 'side'. Neither side will even give the benefit of a doubt that what the other side does is in good faith with their values. It was kinda funny when drunk sports fans duked it out over forgone alegences to groups that don't know they exist, but its happening in casual social situations more and more. How much more of this before our own beerhall putsch moments begin? I digress...
Trust is already a fickle beast. Bloomberg is wrestling with it now, no matter their rigour. Personally, I think it might be a choice, by prompting either a culture of verification and lockdown (modern china), or implied common trust in an ideal but uncertainty (i.e. early usa). Both have huge advantages, injustices, and liabilities. It seems we have approached a middle ground with few of the perks of either and many of the disadvantages to both. Perhaps there is a better way moving forward. I am personally partial to 'dangerous' freedom, over 'safe' subjugation, in all cases. As such, my values my differ may from the mean. Such a system implies personal agency, which is rejected by the popular dogmatic fatalism of 'post-meritocracy'.
Documents are forgeable, but we generally believe documentary evidence. (Well, in courts we need a person to vouch for a document, but we already also need that for video too-it's a very testimonial system.)
When two people dispute authenticity (outside of courts), we reflexively gauge the credibility and perceived motives of those involved.
It's a rough system, prone to error, but my point is we navigate these things socially without assuming bad faith for all documents.
It's like how home locks offer close to zero protection, but they are still a normal part of our world.
We can't be sure a document is real, can't be sure a lock will matter, but we are all busy, so we shrug and go on with our day in most cases.
https://www.snopes.com/fact-check/emma-gonzalez-ripping-up-c...
Forgeries are hugely risky for legitimate organizations; if discovered, the backlash can hurt them quite a bit.
Fringe, extremist, criminal elements have used forgeries to further their goals, and they will do so with "deep fake" videos too.
But our society is dominated by organizations that run on trust. And those organizations will have to quickly learn (indeed, they are learning now) how to distinguish and filter out the deep fakes. Just like they did with fake letters, fake signatures, and fake photos.
Exhibit 1: https://www.huffingtonpost.co.uk/entry/fake-news-trump-flood...
Exhibit 2: https://www.cnn.com/2018/03/26/us/emma-gonzalez-photo-doctor...
I'd say that was a pretty big deal (Russians providing a "satellite image" showing a Ukrainian fighter plane shooting down a commercial airliner).
Bad actors use this kind of technology whenever they think they can get away with it. As someone else mentioned, they've used video game footage and pretended it was actual combat footage.
however, there are tons of gullible and/or wilfully stupid people who respond to photoshopped pictures on social media as if they are real.
especially when these images are politically charged, some of them probably believe it and some “believe” because it fits their world view and makes them feel righteous.
You're not paying attention then. Here's just one example.
https://www.google.com/amp/s/globalnews.ca/news/4333499/indi...
but it's not really the public sphere -- there is no nationwide uncertainty about these videos. the police understand perfectly that they are fake, for instance.
It will become even more apparent when the population is primed to believe it, pick your hot button issue of the day and some significant portion of the population would absolutely believe a fake video depicting the opposing party doing something horrible, without pausing to reflect.
Even seemingly harmless caricatures, like Tina Fey's infamous SNL skit of Sarah Palin ("I can see Russia from my house"), have a long term affect on people's perception of reality: http://eprints.lse.ac.uk/59838/1/USAPP_Blog_In_politics_cari...
In that paper a survey found that 7 in 10 Americans believed that Palin actually said that.
The mass production of deep fakes will have a deep and profound impact on society. I'm not keen on where this is heading.
But it definitely depends on the news source and how thorough they are with verifying stories.
Photoshopped images are a sort of "trial balloon" which has already proven that the system is pretty dang robust, that's my thesis.
what if you see satellite images of a country mobilizing or testing nuclear weapons? What if someone synthesized sensor measurements?
Another example I could think of is a highly sophisticated spearphising attack. What if someone impersonated a boss's voice over the phone? What kind social engineering/manipulation could that type of adversary get away with?
Thinking on this I feel like the future might require that we record our every move via some sort of verified GPS service so that you can corroborate your whereabouts. Maybe their service comes with a video recording device that can show no, 'at this date + time client was at a McDonalds drive through at 41°24'12.2"N 2°10'26.5"E here is a 452 second video of their engagement' which would overlap the supposed Deepfake timeline/video
Thoughts?
I imagine if the service is publicly trusted/credible then it would not need to expose the actual details of the client's whereabouts, it could just issue a true/false verification on a Deepfake based on the data held privately.
Ie, the end of "trusting" videos from unknown sources with unknown reputations and agendas.
Depending on how divergent the algorithms are and how 'hand-done' they are I think a good intermediary measure would be to attempt to replicate it from scratch from other sources as itself a proof of insufficient proof. If you can take a DMV driver's license photo or other publicly available footage of your client, a scene of a robbery from a surveillance camera and put together something that looks exactly like the supposed evidence made by someone who was given only a loose description of the event you basically have proof that it is either fake or easily frameable in the same sense that a random diary that says "I am the zodiac killer - Ted Cruz" isn't admissible evidence.
We fight this by having less partisanship and stronger free press.
Really wish we could find a solution that didn't involve trust... rather, cryptographic proof.
Then, when a questionable event happens, the video of all participants and anyone nearby can be replayed. Then, all videos of participants can be replayed to make sure they match up, and the video of the time leading up to the event could be scrutinized. Furthermore any one who visited that area in the recent past could be checked to make sure they didn't create some sort of hologram or something that the participants watched rather than the real thing.
Having cryptography without trust in some form of desire for teamwork in your fellow humans defeats the whole purpose of cryptography... But I admit this is more about my ideology and reasonable people can disagree about it.
Possibly could involve some kind of blockchain tech similar to https://proofofexistence.com. It doesn't solve all of the problems but at least we can begin establishing a record of source. The point is, something needs to be done to augment the trust we have in journalists because it's easy to trick or buy people out.
And as mentioned in the above comments, it does not help with analog loopholes and trust in the person being photographed.
> And as mentioned in the above comments, it does not help with analog loopholes and trust in the person being photographed.
Like I said in my above comment, it doesn't solve all of the problems but at least we can begin establishing a record of source.
I realize that people all the time try to say "Blockchain would be great for ____" so you're probably a little hypersensitive and I get that, but the suggestion of a blockchain was arbitrary and tangential to the real point of my post, so I don't really feel like getting into it right now.
Their direct incentives are getting sales (and now clicks), which doesn't appear to be highly correlated with accuracy. Additionally, my experience in college was that it wasn't the best and the brightest going into that field, though I deeply hope that it was a skewed sample, and believe that there are many deeply intelligent people working there.
However, I think it likely that many people are not drawn to the field for the pursuit of pure objective truth, but because they have a particular agenda and want to enlighten the world with it.
There is a quote about a logical fallacy that I can't quite remember, it goes along the lines of the following: You read an article about something with which you are deeply familiar. You laugh to yourself at the childish misconceptions of the journalist. You then turn the page to something you know little about, and assume that everything that is written is true. That doesn't make sense.
Beyond that, I'm not sure stereotypes of any large group of human beings are worth addressing, other than to point them out for what they are.
And I partially agree! But do not throw out the baby with the bathwater! I am a physicist myself and have seen how the Gell-Mann effect has become less problematic over time, especially in respected journals that want to be taken seriously by scientists: Just make a decisive effort to 1) go out of your bubble and 2) learn about logical fallacies.
Do these journalists work for large mainstream media corporations that are all owned by a shockingly small number of partisans, by any chance?
Do you have a complaint different from "It is not perfect so I do not believe in any of it"?
Sure, if you go back to the Watergate investigation.
Their track record in recent years is abysmal. They are basically the pseudo-official mouthpiece of the U.S. Democratic Party, and somewhere between the New York Times and the Huffington Post in terms of seriousness.
When facts aling with a policy idea this makes the policy good, not the facts wrong (and we should applaud both parties when they do it). I do not read every single article in WaPo but their front page and push notifications are most of the time fact based.
That party hated Bernie Sanders (who is plenty “liberal”[1]) nearly as much as it hated Trump, and both were covered very negatively by the Washington Post.
I don’t know why you assume I’m criticizing the Post from a right-wing perspective. Perhaps you are too steeped in the two-sided U.S. political culture, where disliking one party must mean liking the other?
By the way, reporting objectively correct facts does not make a publication unbiased or serious. Even if everything TMZ reports about celebrity relationships is true, do you consider them a serious news source? Deciding which facts to emphasize is just as important as telling the truth.
[1] To head off in advance any off-topic responses: this is true regardless of whether you mean “liberal” in the American or European sense.
- While I like Senator Sanders, reasonable people (I would like to believe I am one) can have stuff to dislike about his policies. This is how I view the non "alt right" complaints about him.
- Being more to the center than someone else, does not make you a mouthpiece for the centrist party.
Edit: I misread your comment again. I deleted an unrelated response.
Signing it only proves that they approved of it not that it is fundamentally accurate in any way.
The fakes will stand out. We'll all get more interesting celebrities. The celebrities will have more fun. Everybody wins... for a while. :)
I tried to prove my ideas by created a "vfx at the last mile" pipeline with a small investment round, enabling media agencies to create ad with you in the Domino's pizza or rental car advertisement. It worked, feature film quality. Still they did not believe, or hyper-focused on porn.
I went bankrupt, closed, and went to work in Facial Recognition, where my skills are recognized. The personal one-to-one treatment I received when pitching to entertainment studios versus that of silicon valley VCs is worthy of a book; I have zero respect for VC now: of hundreds of personal interactions, one and only one was not a social climbing, rich parents moron.
Link to examples, otherwise your comment just reads like crankery.
By the way, I googled "Automated Actor Replacement in Filmed Media" and I couldn't find your Master's thesis. I could only find posts by you on HN, Quora, and other sites.
Ah yes, feature film quality. For values of 'feature film' that approximately equal 'late-night comedy show where moving lips are overlaid on a still image'.