Discovering deepfakes, in a world where even reality is suspect

Last February, a Tomahawk cruise missile hit an Iranian elementary school, killing more than 150 people, mostly children. President Trump initially suggested it was someone else’s tomahawk: “Whether it’s Iran or someone else, the fact that a tomahawk — a tomahawk is very generic, it’s sold to other countries, but that’s being investigated now,” he said.

When the Iran video emerged as proof that it was a US missile, Hany Farid, one of the world’s leading experts on deepfakes, was contacted by several media outlets to determine whether it was genuine or fake.

A professor at Dartmouth College, Farid is also co-founder of GetReal Security, a cyber security company. “What was difficult in this case was that you had very little to work with,” he said. “We had very grainy, shaky video. The missile is extremely small. And we had to think about the physical plausibility of that missile hitting the ground.”

Study a Tomahawk missile video.

CBS news


But he also had several aspects that he could study scientifically, with the speed of sound, the speed of light and the size of the rocket: “And those three things were enough to tell us that this is physically plausible,” he said. “And this is the important part: all the evidence led us to believe that the video was authentic, and there was no denial.”

But this is the world we live in: reality itself, so perfectly mimicked by artificial intelligence that even reality is suspect.

Farid said: “Here’s the thing that drives me a little crazy, especially as a scientist: I don’t think you should be able to go into a court of law and say, ‘Here’s some evidence that’s damn enough to kill this person,’ and then the judge says, ‘Well, how do you know it’s real?’ And I say: ‘Well, because the computer told me so.’ This is not an answer

“And if I can’t explain to you, a judge, and a jury, what’s going on here— because the lighting, because the shadows, because the geometry, whatever it is – that’s what we have to do.”

A case in point: Alex Pretti, who was killed by an ICE agent in Minnesota. If you remember the scene last January 24, it was chaotic. Several ICE agents with guns surrounded Pretti.

Farid showed us a blurry photo of Pretti taken from the original video. “Someone took this and ‘improved’ it,” he said. According to Farid, the crispness of this “enhanced” image makes the scene “more real, but what it also did is when it enhanced it, it seemed to use a weapon [Pretti’s] hand If you go back to this video, the camera pans a little bit and what happened is there is a shadow behind his hand on the road. And what the AI ​​did is it hallucinated this.

ai-hallucination-of-gun-in-Alex-pretti-killing.jpg

An artificial intelligence “expansion” of a video frame of the murder of Alex Pretti hallucinates a gun in the hand of the victim.

CBS news


Farid says the artificial intelligence has learned: “When you see photos like this with three men with guns, everyone got a gun.” And now, when you do a Google search for events like Pretti’s murder, it shows the “enhanced” image.

Farid’s estimate is that half of the content widely viewed on the Internet is fake, basically a coin. Much of it has its own slop label: “AI slop.” Footage of planes skidding on the tarmac, babies doing a two-step dance, Elvis. “AI slop is a broad term that defines people who generate content with AI just to grab eyeballs, video after video after video driving engagement,” Farid said.

For the most part, Farid limits his exams to the really serious stuff, the deepfakes. Still, he is overwhelmed. He said: “We’re seeing deepfakes being weaponized in many, many different ways, from creating child sexual abuse material, to non-consensual intimate imagery, to full-on state-sponsored disinformation campaigns, to what the North Koreans have done. [which] is their IT worker interview for remote jobs. And they hide their accent with AI. They can hide their identity with a deepfake, where they change their identity from eyebrow to chin, cheek to cheek, in real time via a video call. They can hide their geolocation. And they interview for jobs. I will tell you, just about every single Fortune 500 company has one or more of these employed, whether they know it or not.

“And now, the question you want to ask yourself is, what’s next? Well, so one CEO said, “Okay. No more virtual interviews. No more remote work. That’s crazy. … are we going to start flying people across the country? That cannot be the answer. I think it’s exhausting. Let’s be honest. I mean, if we’re always looking over our shoulder over every email, every text message, every voicemail, every phone call, every video call? It is exhausting. i am exhausted, and I do this for a living.”

Asked if he has nightmares about deepfakes, Farid replied: “I look at content all day long. And usually the things I look at are not pleasant. I look at bad things that involve terrible crimes, and when you watch these things over and over again, they sit with you and you can’t get them out of your head.”

‘And number two is, I don’t want to be wrong. And five years ago, I felt much more confident about our ability to distinguish real from fake. It has become more difficult. And then I fear more. I feel like the ground is constantly shifting,” he said.

It builds – the stress, the pressure. After seven years on the West Coast, Farid returned to Dartmouth College, where he previously spent 20 years on the faculty. His wife, Emily Cooper, is also a professor there. The two of them bought a rural property in neighboring Vermont, where Farid mows acres of meadows and cuts enough wood to feed their stoves through the winter. There is enough mowing and cutting to flush away some of those disturbing images. It’s isolated—there’s no mail delivery, no trash pickup—but it’s peaceful.

Certain work-related issues remain. Social media? Farid loathes it: “You can look on social media, on online platforms and say that there is measurable harm to young children, adults, seniors, across the board. And I think we’re so fascinated by these products that, by design, are thought to be addictive.

“I think we’ve done an experiment on a whole generation of these young kids who are coming up, putting these devices in their hands. And now we’re waking up and we’re like, ‘Oh, my God.’ This is terrible. This generation currently has lower learning outcomes than any generation in history. Go to Palo Alto and the best private schools where all the tech billionaires send their kids. There are no devices in those classrooms. They know.”

That $17 billion settlement that Meta reached a few weeks back includes some security measures, such as a two-hour time limit for users under 18. Farid believes that is a start, but not nearly enough.

“The darkest vision I have is that everyone lives in their own information ecosystem, and no one knows how to talk to each other anymore,” he said.

On platforms where algorithms prefer fake to real content, Farid believes we should all stay off social media, or at least take those apps off our phones, to resist the temptation. Regarding the websites that promise to detect AI fakes, he says, it is not so easy: “Here is what I think is next (and by saying next, I mean in the next year), that is most of the deepfakes that we have seen today a human somewhere in the process. Everyone’s hands are on the keyboard. There is still a human in the loop.

And what is an AI agent? “An agent just has more autonomy, and what we’ve started to see is if you give it a problem to solve, it will find creative ways to do it, including creating a false identity to interact with a human to get a human to do something and then it will lie,” he said.

AI agents have been in the news recently for failing to test well the global debate on AI security in the the entire course of mankind. These are issues that Hany Farid struggles with every day.

“I think there’s a near future where people have an AI agent that they grow up with,” he said, “and it’s going to know them better than anyone they know. And I think this thing can live forever.”

“My wife and I talked about this,” he said. “She’s younger than me. We talked about, should we and an AI agent learn my voice, my likeness, how I think, how I speak, the kind of questions I ask her in the morning, how I react to her when she’s sad, how I react to her when she’s happy? Do I think AI can mimic that to near perfection? Yes.

Asked if – should Farid be hit by a truck – an AI agent of his could be an adequate replication of him for his wife, Farid said: “I think for my generation the answer is probably no. But the next generation, the generation after that, who think differently about these things? I don’t know.


Story produced by Deirdre Cohen. Editor: Ed Givnish.


See more:

Leave a Comment