[ Web Proxy ]
URL:
Viewing: https://www.wired.com/story/these-new-tricks-can-outsmart-deepfake-videosfor-now/ [Back]  [Original]

These New Tricks Can Outsmart Deepfake Videosfor Now | WIRED
Skip to main content
Oct 17, 2018 7:00 AM

These New Tricks Can Outsmart Deepfake Videosfor Now

We'll soon find it hard to know with our own eyes if a video is real or generated by AI, but new algorithms are staying one or two steps ahead of the fakers.
Save StorySave this story
Save StorySave this story

For weeks, computer scientist Siwei Lyu had watched his teams deepfake videos with a gnawing sense of unease. Created by a machine learning algorithm, these falsified films showed celebrities doing things they'd never done. They felt eerie to him, and not just because he knew theyd been ginned up. They dont look right, he recalls thinking, but its very hard to pinpoint where that feeling comes from.

Finally, one day, a childhood memory bubbled up into his brain. He, like many kids, had held staring contests with his open-eyed peers. I always lost those games, he says, because when I watch their faces and they dont blink, it makes me very uncomfortable.

These lab-spun deepfakes, he realized, were needling him with the same discomfort: He was losing the staring contest with these film stars, who didn't open and close their eyes at the rates typical of actual humans.

To find out why, Lyu, a professor at the University of Albany, and his team dug into every step in the software, called DeepFake, that had created them.

Deepfake programs pull in lots of images of a particular personyou, your ex-girlfriend, Kim Jong-unto catch them at different angles, with different expressions, saying different words. The algorithms learn what this character looks like, and then synthesize that knowledge into a video showing that person doing something he or she never did. Make porn. Make Stephen Colbert spout words actually uttered by John Oliver. Provide a presidential meta-warning about fake videos.

These fakes, while convincing if you watch a few seconds on a phone screen, arent perfect (yet). They contain tells, like creepily ever-open eyes, from flaws in their creation process. In looking into DeepFakes guts, Lyu realized that the images that the program learned from didnt include many with closed eyes (after all, you wouldnt keep a selfie where you were blinking, would you?). This becomes a bias, he says. The neural network doesnt get blinking. Programs also might miss other physiological signals intrinsic to human beings, says Lyus paper on the phenomenon, such as breathing at a normal rate, or having a pulse. (Autonomic signs of constant existential distress are not listed.) While this research focused specifically on videos created with this particular software, it is a truth universally acknowledged that even a large set of snapshots might not adequately capture the physical human experience, and so any software trained on those images may be found lacking.

Lyu's blinking revelation revealed a lot of fakes. But a few weeks after his team put a draft of their paper online, they got anonymous emails with links to deeply faked YouTube videos whose stars opened and closed their eyes more normally. The fake content creators had evolved.

Of course they had. As Lyu noted in a piece for The Conversation, blinking can be added to deepfake videos by including face images with closed eyes or using video sequences for training. Once you know what your tell is, avoiding it is "just" a technological problem. Which means deepfakes will likely become (or stay) an arms race between the creators and the detectors. But research like Lyus can at least make life harder for the fake-makers. We are trying to raise the bar, he says. We want to make the process more difficult, more time-consuming.

Because right now? It's pretty easy. You download the software. You Google Hillary Clinton. You get tens of thousands of images. You funnel them into the deepfake pipeline. It metabolizes them, learns from them. And while it's not totally self-sufficient, with a little help, it gestates and gives birth to something new, something sufficiently real.

It is really blurry, says Lyu. He doesn't mean the images. The line between what is true and what is false, he clarifies.

Thats as concerning as it is unsurprising to anyone whos been alive and on the internet lately. But its of particular concern to the military and intelligence communities. And thats part of why Lyus research is funded, along with others' work, by a Darpa program called MediForMedia Forensics.

MediFor started in 2016 when the agency saw the fakery game leveling up. The project aims to create an automated system that looks at three levels of tells, fuses them, and comes up with an integrity score for an image or video. The first level involves searching for dirty digital fingerprints, like noise that's characteristic of a particular camera model, or compression artifacts. The second level is physical: Maybe the lighting on someone's face is wrong, or a reflection isn't the way it should be given where the lamp is. Lastly, they get down to the semantic level: comparing the media to things they know are true. So if, say, a video of a soccer game claims to come from Central Park at 2 pm on Tuesday, October 9, 2018, does the state of the sky match the archival weather report? Stack all those levels, and voila: integrity score. By the end of MediFor, Darpa hopes to have prototype systems it can test at scale.

But the clock is ticking (or is that just a repetitive sound generated by an AI trained on timekeeping data?). What you might see in a few years time is things like fabrication of events, says Darpa program manager Matt Turek. Not just a single image or video thats manipulated but a set of images or videos that are trying to convey a consistent message.

Over at Los Alamos National Lab, cyber scientist Juston Moores visions of potential futures are a little more vivid. Like this one: Tell an algorithm you want a picture of Moore robbing a drugstore; implant it in that establishments security footage; send him to jail. In other words, he's worried that if evidentiary standards dont (or cant) evolve with the fabricated times, people could easily be framed. And if courts don't think they can rely on visual data, they might also throw out legitimate evidence.

Taken to its logical conclusion, that could mean our pictures end up worth zero words. It could be that you dont trust any photographic evidence anymore, he says, which is not a world I want to live in.

That world isnt totally implausible. And the problem, says Moore, goes far beyond swapping one visage for another. "The algorithms can create images of faces that don't belong to real people, and they can translate images in strange ways, such as turning a horse into a zebra," says Moore. They can "imagine away" parts of pictures, and delete foreground objects from videos.

Maybe we cant combat fakes as fast as people can make better ones. But maybe we can, and that possibility motivates Moores team's digital forensics research. Los Alamoss programwhich combines expertise from its cyber systems, information systems, and theoretical biology and biophysics departmentsis younger than Darpas, just about a year old. One approach focuses on compressibility," or times when there's not as as much information in an image as there seems to be. Basically we start with the idea that all of these AI generators of images have a limited set of things they can generate, Moore says. So even if an image looks really complex to you or me just looking at it, theres some pretty repeatable structure. When pixels are recycled, it means theres not as much there there.

Theyre also using sparse coding algorithms to play a kind of matching game. Say you have two collections: a bunch of real pictures, and a bunch of made-up representations from a particular AI. The algorithm pores over them, building up what Moore calls a dictionary of visual elements, namely what the fictional pics have in common with each other and what the nonfictional shots uniquely share. If Moores friend retweets a picture of Obama, and Moore thinks maybe it's from that AI, he can run it through the program to see which of the two dictionariesthe real or the fakebest defines it.

Los Alamos, which has one of the worlds most powerful supercomputers, isn't pouring resources into this program just because someone might want to frame Moore for a robbery. The labs mission is to solve national security challenges through scientific excellence. And its core focus is nuclear securitymaking sure bombs dont explode when theyre not supposed to, and do when they are (please no), and aiding in nonproliferation. That all requires general expertise in machine learning, because it helps with, as Moore says, making powerful inferences from small datasets.

But beyond that, places like Los Alamos need to be able to believeor, to be more realistic, to know when not to believetheir eyes. Because what if you see satellite images of a country mobilizing or testing nuclear weapons? What if someone synthesized sensor measurements?

That's a scary future, one that work like Moore's and Lyu's will ideally circumvent. But in that lost-cause world, seeing is not believing, and seemingly concrete measurements are mere creations. Anything digital is in doubt.

But maybe in doubt is the wrong phrase. Many people will take fakes at face value (remember that picture of a shark in Houston?), especially if its content meshes with what they already think. People will believe whatever theyre inclined to believe, says Moore.

Thats likely more true in the casual news-consuming public than in the national security sphere. And to help halt the spread of misinformation among us dopes, Darpa is open to future partnerships with social media platforms, to help users determine that that video of Kim Jong-un doing the macarena has low integrity. Social media can also, Turek points out, spread a story debunking a given video as quickly as it spreads the video itself.

Will it, though? Debunking is complicated (though not as ineffective as the lore suggests). And people have to actually engage with the facts before they can change their minds about the fictions.

But even if no one could change the masses' minds about a video's veracity, it's important that the people making political and legal decisionsabout who's moving missiles or murdering someonetry to machine a way to tell the difference between waking reality and an AI dream.


More Great WIRED Stories
WIRED is obsessed with what comes next. Through rigorous investigations and game-changing reporting, we tell stories that dont just reflect the momentthey help create it. When you look back in 10, 20, even 50 years, WIRED will be the publication that led the story of the present, mapped the people, products, and ideas defining it, and explained how those forces forged the future. WIRED: For Future Reference.

2026 Cond Nast. All rights reserved. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Cond Nast. Ad Choices


Web Proxy Viewer  |  New URL  |  Original Page