Computer tool spots deepfakes via tiny reflections in the eyes
newatlas.com
newatlas.com
We stop treating video as if its some perfect representation of reality that's inherently trustworthy, and learn from confronting similar issues with other media earlier in history.
Focus on media literacy, critical thinking and digital literacy.
That is just another arms race. I think it naïve to assume that people can be educated out of this problem. Some people can be, but large numbers will always fall for a good hoax. What we need is laws and policies to address the problem. The good news is that this problem is nothing new. The laws are already on the books.
Imho this is something that the law can manage so long as the legal system is allowed to run its course. People publishing true deepfakes, not parodies but actual attempts to fool people, should face the same slander and defamation charges that previous fakes have for centuries. Even copyright law has tests to draw lines between legitimate parody and improper fakery. Hustler v. Falwell (the Larry Flint case) was about a literary deepfake, a sham interview in a porn magazine. Those who take deepfake too far, or republish such material, open themselves to legal attack. Let the lawyers do their thing.
Law has its place, but we also need detection techniques to prevent the quick consequences that rumors and fake media can bring - 'doxing', public shaming, mob lynching, etc.
But what if we saturated the media with convincing deep fakes. I feel like there's an inflection point, where people are exposed to so much believable but contradictory fake news, that they might develop a natural distrust of anything presented to them. Believing that the media is for the most part true, sets you up to be manipulated or misled when the media gets it wrong.
And laws have retroactive impact via e.g. police and courts. Education would have a preventive impact.
1. That is not the easy solution for the politicians
2. That is not the easy solution for the individual (needs to question himself)
= Not gonna happen
I believe “The hard way” does only appeal to a small minority (maybe not in HN :D )
But for yourself, it is becoming more and more important to really think through what is being presented to you in whatever media form and analyze whether it is credible.
The print form of a deep fake is plain old well constructed word-lies, which is why we have had the phrase "don't believe everything you read on the internet" for awhile. There are people who do, but we live better lives if we don't.
Deep fakes aren't really a new problem, they are just a different form of an old problem.
And then of course the keys to the watermarking will be leaked :)
Deep fakes won’t be any worse for the world than photoshop ever was. Until we have any reason to believe that deep fakes are actively misleading anyone in ways that actually matter I think it’s fine to ignore the problem.
We should measure harm and then fine the businesses that spread the harm. It’s very similar to pollution.
We should measure harm and then fine the businesses that spread the harm.
Maybe, but this has nothing to do with deepfakes, and can be generalized.Societies should teach people to recognize and deal with mis- and disinformation, rather than provide them faulty assumptions upon which to base their trust.
Add in biases and people are all to willing to discount the truth they dislike as propaganda etc.
It requires teaching people the tools to evaluate arguments, statements and media.
I don't claim anything wrt objective truth (though I tend to think there is one, but whether we're able to directly observe it and/or agree on it is another matter) – I'm claiming we have tools (knowledge, cognitive ability) to weed out obviously incoherent, illogical, biased, untrustworthy or otherwise bad thought.
Essentially, you can train people to deal with poor execution, but that’s not enough when the subtle stuff is equally if not more important.
However, bias can show up in what’s not reported just as easily and in that case their is nothing to detect.
You're right about not knowing what you don't know.But that doesn't mean that you should blindly trust some discriminator system (which we know can't make any technical guarantees, and comes with additional risks) instead of learning to reason about these things.
Regarding media literacy, while it's important in general I don't think it will help much in the short run. (Because it takes a long time and becuase it needs the cooperation of those who are actually sometimes willingly deceive themselves.)
I expect digital signature and timestamped fingerprinting to appear in videos that want to prove that they are legit and from that point on you just don't believe anything that's not treated that way. This will eliminate all deep fakes other than the ones that claim to be a leak/recorded without the consent of the faked person.
Deep fakes will in the end make (real) hidden camera and leaked recordings lose a lot of their credibility and power, which is sad.
We've had some of the tools needed to distinguish good from bad thinking for millennia, so I find it kind of weird there hasn't been more focus on this in basic education earlier.
Digital signature and timestamped fingerprinting will also have errors, and they don't solve the social side of this issue. It still leads us to a faulty thought-process; We cannot inherently trust content on the basis of its medium.
The society is a complex system, politics is complex (you have to calculate what all those pesky voters say they want, think they want and actually want) and there are a lot of issues. No one in their right mind can be serious about trying to manipulate future elections through carefully crafting education for that purpose. Dictators do that, for sure. They can stay around long enough to benefit, but they rarely participate in fair elections.
Or where books are stricken from reading lists or curriculums for fear they make kids question authority [1] – where or Harry Potter's inclusion in school libraries is challenged for their focus on magic (often based on claims that the novels contain occult or Satanic subtexts) [2].
[0]: https://en.wikipedia.org/wiki/Creation_and_evolution_in_publ...
[1]: https://www.theguardian.com/books/2014/jun/10/cory-doctorow-...
[2]: https://web.archive.org/web/20071230201312/http://www.ala.or...
And we're talking about a very specific issue here, not simply whether we trust information in general based solely on the medium. Were talking about deep fakes. Whether politician X Y said a specific thing on TV or not. (And not e.g. whether a specific general claim is true or not because that person said it.)
Yes with adequate literacy you can sometimes deduct that you are seeing a deep fake because e.g. Barack Obama or Tom Cruise could have not said it in front of the cameras, but it can be solved with technology and sometimes you will be wrong anyway. (And lets not forget that all of the information you can acquire comes through some media source and in the end you do trust some of them. This includes your teachers. It's just that if you have solid foundations then you are harder to attack. E.g. because no one can go back in time and hack your teachers and school books. But in theory it's still possible. Just think hod dictators do it over the long run.)
I'd rather not teach people to trust AUTHENTIC VIDEO™ (that can't guarantee authenticity), but to learn to deal with the fact that there's Photoshop for video now.
Besides this, you people should be aware that technically any video could be faked. But you only have so much time and attention during a single day and if you can offload some of the checks to machines, which can do it reasonably well, then why don't? (Esp. taking into account that however I'd like too, you can't educate everyone. It will just not stick with a lot of them.)
The fact that there is an arms-race doesn't mean that it's a dead end; it's possible that one side has a fundamental mathematical advantage. Consider discrete log problems: as computational power increases, it's possible to brute force smaller key spaces, but the same CPU will always be far, far better at the efficient solution than the brute one.
Similarly, it's plausible that deepfakes will always be far easier for computers to detect than to generate.
Why not learn to how to deal with the fact that we can't trust any information at face value, rather than keep making cognitive shortcuts based on assumptions?
But I think that tech to tell them apart is useful.
You're assuming that people want to spot the fake, but it's pretty clear by now that they don't.
This is why we have the American College of Pediatricians and the American Academy of Pediatrics.
ACP is a fringe group who spend time attacking LGTB+ rights. AAP is a mainstream respected group of pediatricians.
If you're a news editor and you want science you'd go to AAP, but editors often don't want science. They want a sound bite, and they'll get that from ACP.
This is why we have the American College of Pediatricians and the American Academy of Pediatrics.
Seems to me like strengthening consumer rights and/or striking down on fake marketing and quacks in regulation could solve at least some of this.A non insignificant portion of the USA/World still sees doctored photographs in tabloids and takes them as fact. It feels easy to write them all off but that is a lot of people. Take the average intelligence. Half of the people in the world are less intelligence than that.
So is it really realistic to train everyone on the areas you mentioned?
I could imagine fake footage that would cause market impacts, riots, etc. before anyone could get in front of it, and even after official corrections come from Upon High many would believe the explanations themselves are the lies (not the faked footage). This would not be assisted by media organizations saying "allegedly", "can't confirm", and of course the words of anonymous sources that totally would never lie, right?
Training a GAN can be thought about as a proof-of-work type job, where you need to recover the best Generator from the SOTA Discriminator, or vice versa.
So the proof of work chain looks like D-G-D-G-D-G. As long as the good actors continue to dedicate more compute to tackling deepfakes than bad actors, I think it should help mitigate the issue.
Also a multi-front defence seems sensible. Agree with points below that the law needs to catch up on this front, but is not mutually exclusive to efforts in improving detection.
In the near future, I believe it will be possible to construct essentially-undetectable DF.
I think benign, newsworthy DF hoaxes should be played to educate the media and the public.
I'd rather not teach people to trust AUTHENTIC VIDEO™ (that can't guarantee authenticity), but to learn to deal with the fact that there's Photoshop for video now.
So interesting idea but really easy for the "deepfakers creators" to fix it
Or even yet, couldn’t this also be part of the training of the deepfake models? So that when it’s learning it’ll try to achieve a high realism score as judged by the algorithm that they use in this other tool?
Be vary once reCAPTCHA asks you to 'spot the fake'.
There, they use two strategies to prevent that:
1) Do not tell the counterfeiters how you discriminate their products from the real ones.
2) Keep the technology you use out of the hands of the counterfeiters.
For this problem, for 2), I think the cat is out of the bag. A with money, keeping tech out of the hands of government-size entities is impossible, but keeping it out of the hands of small players is doable. Here, doing that that would require locking down all computers in the hands of small players to the level iOS does it. Not impossible, but won’t happen overnight, and I don’t think we want to go there.
That leaves 1). That’s a bit at odds with “publish or perish”, but I guess the likes of NSA personnel aren’t in that rat race, so it might be possible for the NSA to provide an online “fake or real?” tool. Of course, that would mean the likes of the NSA could lie when asked whether their fake was real and when asked whether a real image they don’t want to be known as real was real, so we would need multiple, independent such parties.
Otherwise you can just feed whatever video you have in mind into the first stage of that chain you’ve created and say you were there when it happened.
You could then use that internal state as a private key to sign what you want and only keep the corresponding public key and a signed date+time to proof the veracity. The public keys themselves would need to form a blockchain in the traditional sense, so you can verify their integrity without the previous internal states.
If you wanted to go all-in with the verification, you'd probably also want to show something containing the date+time in the video, together with some complicated physical effects that are hard to fake.
Well, just thinking out loud here, but it seems like it might work :D
It seems like this trivially works better with a centralized database especially since you don't necessarily want to make all of this data public. The general public needs to know that this is a true and accurate photo that hasn't been edited taken on such and such a date. The authorities with a warrant might well need to know that it was taken by a device owned by bob.
We can't inherently trust content on the basis of its medium.
Then ultimately it’s going to be left as a confidence value which humans are going to be free to override based on their own assessment of the content.
But you can hinder it's use quite easily if you have a private/commercial implementation by just not doing realtime detection.
For those unfamiliar: https://en.wikipedia.org/wiki/Generative_adversarial_network
This might not defend against all deep fakes, but at least it could in certain cases with more...official videos. I'm not sure how this could defend e.g. a person from a deep fake someone made of them without their knowledge. But I'd like to hear what people who are more knowledgable than me think.
An example of this is training neutral networks to emulate the hydrodynamic equations of motion. The emulator temperature profile may look like the real thing, but it could also grossly violate total conservation of energy.
I’m curious if we can apply such “physics tests” to deep fakes to search for violations.
Im not sure what the solutions are to the societal problem it opens up. Media will get a lot stranger.
The interesting place this could take us to is one within which video evidence of a crime is no longer sufficient evidence to convict, making charges like police brutality and domestic abuse even harder to consistently prove than they are now.