Tech

Fooling deepfake detectors possible: American scientists

Deepfake creators who use 'adversarial examples' are able to thwart the vigilance of the most sophisticated detectors

Updated 5 years ago · Published on 12 Feb 2021 6:00PM

Fooling deepfake detectors possible: American scientists
By using 'adversarial examples' in each shot of the video, artificial intelligence could make a mistake and designate a deepfake video as true. – ETX Studio pic, February 12, 2021

DEEPFAKES still have a bright future ahead of them, it would seem. It is still possible to thwart the recognition of deepfakes by even the most highly developed detectors, according to scientists at the University of San Diego. By inserting "adversarial examples" into each frame, artificial intelligence can be fooled. An alarming observation for scientists who are pushing to improve detection systems to better detect these faked videos.

During the last WACV 2021 (Winter Conference on Applications of Computer Vision), which took place from January 5 to 9, scientists from the University of San Diego have demonstrated that deepfake detectors have a weak point. According to these professionals, by using "adversarial examples" in each shot of the video, artificial intelligence could make a mistake and designate a deepfake video as true. These "adversarial examples" are in fact slightly manipulated inputs that can cause the artificial intelligence to make mistakes. To recognize deepfakes, the detectors focus on facial features, especially eye movement like blinking, which is usually poorly reproduced in these fake videos.

This method can even be applied to videos that have been compressed, which until now has been able to remove these false elements, the American scientists said. Even without having access to the detector model, the deepfake creators who used these "adversarial examples" were able to thwart the vigilance of the most sophisticated detectors. This is the first time such actions have successfully attacked deepfake detectors, the scientists said.

Scientists are sounding an alarm and recommending improved training of the software to better detect these specific modifications and thus these new deepfakes: "To use these deepfake detectors in practice, we argue that it is essential to evaluate them against an adaptive adversary who is aware of these defenses and is intentionally trying to foil these defenses. We show that the current state of the art methods for deepfake detection can be easily bypassed if the adversary has complete or even partial knowledge of the detector," the researchers wrote. – ETX Studio, February 12, 2021

Related News

Events / 1mth

JCL Credit Leasing adopts AI voice agents to boost customer verification, debt collection

Malaysia / 2mth

Southeast Asia’s booming scam industry eyes Malaysia

Malaysia / 6mth

3 international, local drug syndicates crippled, value of seizures hit RM208.25 million

Malaysia / 11mth

International drug distribution syndicate busted; Nearly one tonne of fentanyl seized

Opinion / 1y

Malaysia's voice and role in the international stage

Business / 1y

German tech company confident US tariffs will not impact its exports

Spotlight

Malaysia

Myanmar hotel worker charged over alleged sexual assault of three-year-old Australian boy in Penang

Health

MOH weighs HFMD vaccine strategy as cases plunge 83%

World

Trump links Saudi nuclear deal to Israel recognition as pact heads to Congress

Malaysia

Shah Alam brawl turns deadly as car strikes man after machete attack (video)

Music

‘Queen of Country’, Dolly Parton dies at 80

Sports & Fitness

Global cricket legends urge Pakistan to honour court order on Imran Khan’s medical care

Malaysia

Should PH work with Bersama to defeat a common enemy?

Business

Nation’s economic outlook strengthens as leading index signals continued growth

You may be interested

Places

Overwhelming response for Penang’s reopened museum

By Ian McIntyre

Tech

Australia’s under-16 social media ban begins to show cracks as TikTok use rebounds

Health

MOH weighs HFMD vaccine strategy as cases plunge 83%