I don't know how/what form this should take, but an older analogy might be how colour photocopier manufacturers imbed microdots into each reproduction so counterfeit bills can be traced to the equipment that produced them.
I don't know how/what form this should take, but an older analogy might be how colour photocopier manufacturers imbed microdots into each reproduction so counterfeit bills can be traced to the equipment that produced them.
On the other hand, there is a reasonable amount of active research on both detecting current faking-techniques, and methods of adding cryptographic attestation from point-of-recording.
I don't believe "detection" can win in the end, as widespread detection-technology can generally be used to tune better fabrications.
So ultimately we'll have to rely on: "do we trust the specific chain-of-people-and-sensors-and-relays that brought this evidence to our purview?" And various kinds of constantly-applied cryptographic signing & timestamping can help with that, though interpreting the challenging cases will require a lot of abstract expertise. (So again, for most people, it may reduce to: "who do you choose to trust?")
We just won't be able to trust anyone is actually saying anything except after confirmation via non-repudiable channels.
I'm from a rural community in Canada, and of course we answer the phone.
Just floors me to visit my mother-in-law in Texas; when we visited eight years ago, she'd answer the phone; now she doesn't answer her cell or her home phone unless it makes a distinctive ring. I'd hate to need to get ahold of her using someone else's phone.
They'll be used on people who are already perfectly happy to believe fake printed quotes from obviously unreliable sources. When challenged, they'll refer to conventional partisan media citing those sources as proof. Ordinarily showing video would increase their certainty, but they're already absolutely certain. It'll just be a more entertaining way of delivering it to them.
Detection, no matter how definitive, can't deter that. They're already perfectly happy with their trusted sources.
It was recognized by law makers that drones could be used for nefarious purposes and needed some form of regulation.
I'm not saying that drone registration thwarts illegal use, but at least something was done by regulators.
That's an example of the politician's fallacy. Doing something can be much worse than doing nothing. Did drone registration actually improve anything?
Either way these regulations don't help much when people just don't care, as can be seen with all the drones flying too close to airports.
When the recreational/commercial models got range and mass enough to get in the way of aircraft, that's when the first round of "whoa!" kicked in.
Still going to take more work to figure out reasonable controls.
Drone regulation has done precisely nothing to thwart illegal use, while imposing substantial cost and inconvenience on legitimate actors. The laws don't stop me from buying a heavy-lift drone from China, nor do they stop me from doing something nefarious with it. At best, the regulations have slightly reduced the risk of inadvertent airprox incidents, but they have been utterly useless in addressing the sorts of risks they were supposed to combat.
"Ryzen 3950x" is just a scary new word for "z80" or "6502".
Deepfakes don't provide any fundamentally new capability, but they do reduce the cost and time required to create a convincing fake video by multiple orders of magnitude. That completely changes the threat model, from "our propaganda rival occasionally releases a fake video that we have to debunk" to "our propaganda rival is producing thousands of fake videos every day and we can't even keep track of them".
I'm not sure this is entirely true, although your larger point is quite good.
People have been faking video since the dawn of video, yes. But for several decades, a clear, high-res video of a specific person has been pretty much inviolate. Faking a steady closeup of a president or famous actress would have been unthinkable - no VFX hoax ever convincingly impersonated Nixon. As a result, bad actors had to resort to deceptive editing, low-quality "covert" footage, or very rarely an exceptional look-alike. Even Hollywood had to rely on old footage and rewrites when an actor died.
Today, we're right on the edge of changing that. MIT can revive the President, but not perfectly, and only to the standards of a 70s news video. Lucasfilms can revive Carrie Fisher, but not well enough to fool an alert viewer, and not in a natural/unedited setting. Within a few years, we might hit a level that tricks even the most acute viewer, and is only caught by forensic analysis. We've been there with photographs for years, but it's new ground for video.
Because nobody really cares about Nixon. People fake UFO videos because they're clickbait. You can hit and run and make $10,000 on YouTube revenue before someone debunks you.
The reason political campaigns aren't using VFX to make their opponents look bad is because someone would eventually figure it out and the backlash would be immense. Additionally, it's not even necessary. People do fine planting conspiracy theories and taking advantage of people's disinterest in fact checking to say whatever they want, all without investing any effort in video production.
I predict that deepfakes will be nothing but a series of amusing "I can't believe they thought they could get away with that" stories.
Creating convincing deepfake videos is still a lot of work, but a couple years ago altering one's face in live streams took also much more effort than pressing a button in a free mobile app.
It's well understood that quantity -- and availability to the masses -- has a quality all its own.
I do believe we're facing an arms race, in which purveyors of synthesized bullshit will likely fight the defenders of truth to a draw at best, and more likely win. No disrespect intended but I don't agree that your Photoshop analogy is valid.
So people learned that we shouldn't trust a photo of Martians, or a sound clip of the President confessing to murder, but should hold out for video. When footage of Rob Ford doing crack cocaine shows up, we believe it's real. And when an investigative reporter wants a verifiable record of something, they resort to a high-quality video.
Even if video deepfakes aren't any more realistic than image or audio fakes have been, they're important because there's no fallback. With perfect-accuracy photo and audio fakes, we'd have to be more skeptical. But with perfect-accuracy photo, audio, and video fakes, we'd suddenly be back to the pre-photography era when there was essentially no way for an untrusted source to convince you that something had happened. Deepfakes aren't flawless, we're not at that point, but the specifics of video are less important than the impact of having some medium which can't be convincingly faked.
Faking a clear, unbroken closeup of a recognizable person has never been a serious option before this. Even when Hollywood had likeness rights and massive budgets, it resorted to rewrites and old B-roll footage when actors died mid-shoot. When people wanted to slander politicians, even state actors with Cold War budgets, they edited photos, faked audio recordings, or staged candid, hard-to-see footage. In the modern era of CGI and digital video editing, bad actors still resorted to misleading edits and out-of-context clips. This, though, is 20 seconds of clear, closeup video of an incredibly famous face. And the fake was good enough that even placed in an art exhibition centered on something that never happened, some viewers thought it was real footage.
I don't share the popular paranoia that deepfakes of politicians are going to start upending democracy; there have always been plenty of people fervently convinced by manipulative video, altered pictures, or simple "somebody said so" lies. What's new is the increasing difficulty of proving truth in the most trusted contexts. Validating even a very narrow claim like "at some point in the past, for some reason, the President said this exact sentence in front of a video camera" is increasingly difficult.
The business model works on "most" people, but not all of them. You can't fight a Fox News with an Air America. It's been tried, more than once. When deepfake material comes to light at the expense of a Democratic president, rest assured, most people aren't going to bother demanding the White House's public key.
All they'll know is what they heard from the talking heads on their news channel of choice: "Well, I don't know, Sean, but a lot of people are saying it's real."
We do. Even today, very little of what you see in media is entirely real. The alterations are hardly ever as overt as Trotskyites being airbrushed out of Party publicity photos, but that doesn't mean they aren't being done.
Maybe an African-American person ends up looking a little blacker than they really are if they're being accused of a crime, or a little whiter if they're running for office. Maybe they just sound a little more or less "ethnic" depending on whether the press wants them in office or in jail. Or a video is sped up and slowed down at just the right moments to turn a journalist's uncomfortable question into an unprofessional partisan attack.
IMHO we can expect more of these cognitive shenanigans as the technology improves. Manipulation will be performed not just on the subjects in question, but on the contexts in which they appear.
Ability is what interests me most. Faking this sort of content - a continuous, closeup shot of the President saying something - has basically never been possible before. If a total stranger had showed you this video in 1969, it would have been clearly authentic. Not clearly truthful, you wouldn't trust that the landing had really failed as opposed to e.g. Nixon recording speeches for both outcomes. But you could be pretty sure it wasn't an imposter or an edit or anything except the real Nixon on camera.
Deepfakes challenge that ability, but I don't think they'll destroy it. Official sources will sign video. Untrusted sources will use verified timestamping and other methods to prove specific claims about their footage.
Actual knowledge, on the other hand, can't be destroyed by deepfakes because we already don't have it. There are a hundred ways to lie to people - with photoshopped images, deceptive editing, or just lying and having people trust that the evidence exists somewhere. People who aren't easily fooled today will become skeptical about video footage too. People who are easily fooled are already fooled, have been fooled since before photography straight through to the present, and will just stay that way.
"Banning political deepfakes" or anything similar is not just a case of closing the barn door after the horses have left, but without ever getting the horses into the barn.
Nope, it'll just give well-executed fakes a veneer of legitimacy. A state-level actor will have easy access to the signing keys. Non-state-level actors could potentially extract them from a device or bribe an engineer at a third-tier Chinese OEM. A reasonably competent hardware hacker could desolder the CCD from a signed device and feed whatever video signal they like into it.
Which "enemy" do you envision would use deep fakes for a nefarious purpose, yet will stop short once they realize there are - gasp! - regulations around them? And as far as I'm aware, at least in the United States, there are no regulations requiring the use of microdots in printers or copiers, they're done of the manufacturers' own accord to aid law enforcement.
The idea that we should have ill-informed, knee-jerk regulations in reaction to every mildly upsetting technological fad is antithetical to everything the vast majority of technologists believe in and stand for.
Current laws that put microdot detection in color scanners will not deter huge resources to counterfeiting like state backed operations. But they do prevent the local meth junkie down the road from making a bunch of fake 20's to get his next fix.
At the sametime, the paper that we use is also highly regulated. Its not impossible to get something that is similar, but its not easy. (and not cheap).
The points of all these layers, is to prevent the casual and common crimes. By doing that, you can spend your resources on the larger operations.
1. Origin tracing. This is the microdot example: it's not meant to catch deepfakes, but link nefarious instances to their source. But the existing technical options here seem to be a mix of privacy-eroding (printers are dumb compared to phones/computers, and you'd have to prevent or ban sharing non-marked media) and ineffective (bulk color copying requires physical access to a device that's hard to make or modify; deepfakes can be constructed on a server in another country, or have their identifiers scrubbed after the fact).
2. Reactive, general verification. This is just an arms race between fakers and observers, like catching art forgers. Existing fakes have tells like a modified 'halo' around faces. Right now we only see manual checks, but major content hosts like Youtube could flag "suspected deepfake" like they do "music copyright strike". (Or hopefully better than that...) But it depends on staying ahead of fakers, and once the tells are too subtle to simply watch for it will only work when hosts or viewers choose to validate content.
3. Proactive, general verification. This corresponds to hard-to-implement, easy-to-verify security features like UV watermarks on money or prescriptions. But those rely on controlled supply, and decades of DRM failures tell us that digital fakes are much easier to make and safer to pass than physical ones. I don't expect this to expand beyond closed groups like news orgs giving out auto-watermarking cameras.
4. Specific authentication: not eradicating fakes but proving certain videos are legitimate. This is the most plausible, interesting category. We can't even prevent manipulative photo edits today, so we're unlikely to prevent manipulative deepfakes, but today we can prove specific aspects of specific images are legitimate. People will still believe fakes and lack proof of some real events, but this prevents a more fundamental transition to a "post-truth" era; we'll still have known-good records of key events.
We've had low-tech authentication since the dawn of photography - think of hostage photos taken with a daily newspaper to prove "this image is newer than this day". As photo editing emerged, steganography developed to catch out altered elements. Cryptographic signing took that further, allowing us to prove that an image is unaltered from a specific keyholder. We even have the reverse of the old newspaper photo; publishing a hash or encrypted file lets us date an image back to a specific time without having to actually release it.
Proving that a file is authentic to the world, not just an owner, is trickier. But we already have some steps: deepfakes take time, so any livestreamed video is not being edited that way after the fact. Authenticating something time-specific like a Presidential speech would only require combining that rapid turnaround with proof that the video wasn't prepared in advance; until on-the-wire editing becomes convincing a newspaper in the background would suffice. Quite likely we'll see more complex arrangements eventually, like trusted hosts that issue random values and demand their use in rapid responses.
None of this is going to stop people from believing fakes, but nothing ever has. What's more significant is whether we maintain the ability to create records which can be verified and trusted.