Deep fakes 1
Illustration: Ceasar Zeppelin, Material: stock.adobe.com / who is danny
2026-10-01 VDE dialog

Misinformation: Facts against fake news

As AI-generated content continues to evolve, users’ trust in what they see and hear is increasingly being shaken. Special tools can help detect deepfakes, for example. How they work and how reliable they are.

By Eva Wolfangel

If Günter Jauch recommends a crypto investment, it should be a legitimate investment. After all, the TV host is considered particularly trustworthy by many, and the video looks real. But it isn’t. Deepfake technologies make it possible to make celebrities such as Markus Lanz, Barbara Schöneberger, and Günter Jauch appear to endorse something they would actually never recommend – and to do so so convincingly that people repeatedly fall for it. No less serious than the potential financial loss is the resulting loss of trust. Photos, videos, and audio recordings are no longer automatically credible sources today. In recent years, the forgeries have become increasingly sophisticated. But the technologies that make manipulation possible are also part of the solution to the problem.

The best-known approach is to calculate probabilities as to whether something is genuine or was created by humans. This is how AI detectors such as Pangram work. The company became known because its software was used to supposedly prove that the speeches or guest articles of several politicians had been written by AI. “Supposedly” because such evidence is not conclusive. Instead of providing a definitive statement about an individual case, it merely produces a statistical probability. Comparable tools also exist for images and videos. Microsoft originally developed its Video Authenticator for the 2020 U.S. election campaign, during which targeted disinformation was a major issue. This tool is also based on probabilities: the program uses AI to identify patterns and detect typical problems associated with deepfakes, such as transitions between authentic and generated material or differences in image sharpness. The problem is that the AI systems generating content are becoming increasingly sophisticated, which also makes it more difficult to detect such characteristics.

The same applies to AI tools that ultimately do the same thing as humans: look for errors, such as six or seven fingers on a human hand. But things are no longer that simple today, and in many cases this is no longer possible at all.

For this reason, the industry is increasingly focusing on cryptographic evidence such as digital signatures or so-called hashes. In a sense,these are tamper-proof seals that can be verified technically. Ultimately, this is tried-and-tested, well-researched cryptography – the technology used, for example, in HTTPS certificates or signed software updates.

The C2PA standard forms the basis for one of the largest existing ecosystems for verifying the provenance and authenticity of digital content. Participants include Adobe, Microsoft, Sony, Leica, Nikon, the BBC, and the news agency AP. A camera can cryptographically sign images and videos directly at the time of capture in the form of a hash – a kind of digital fingerprint of the exact pixel data. Metadata such as the camera model, timestamp, or GPS data is also added. Every subsequent edit of an image is likewise signed and embedded in the image file, making it possible to verify the entire chain. To verify the provenance of images and videos, the public key of the certificate holder is used to check whether the signature matches the certificate.

However, there is a catch here, too: While the technology proves the cryptographic origin of a file, it does not prove that a camera actually photographed something real. It could also have been pointed at a screen displaying deepfakes. Moreover, this does not come close to covering all the cases in which people want information to be verified. This is especially true for events where no professional photographers with such state-of-the-art equipment are on site and material captured in real time on private smartphones is being shared via social media.


Videochat mit einem Mann

Wenn der Fake-Chef anruft
Videokonferenzen ermöglichen persönliche Gespräche und sich dabei in die Augen zu schauen über Städte und Länder hinweg. Doch auch dieser Kommunikationsweg ist nicht mehr sicher. Cyberkriminelle haben Videokonferenzen besonders in Unternehmen für eine neue Betrugsmasche entdeckt. Technologien können Bilder von Personen und deren Stimmen in Echtzeit so realistisch darstellen, dass ein Chef nicht erkennt, ob da wirklich seine Mitarbeitenden in der Leitung sind oder es sich um Deepfakes handelt. 
Vor diesem Zweig des Identitätsbetrugs warnt das Fraunhofer-Institut für Sichere Informationstechnologie SIT und macht auf einen starken Anstieg solcher Fälle aufmerksam. Im Rahmen eines Forschungsprojektes haben Fraunhofer-Forschende eine Software entwickelt, die Teilnehmenden bei sicherheitskritischen Calls kontinuierlich Hinweise geben soll, wie wahrscheinlich ein Deepfake ist. Wie andere Detektoren basiert das System auf dem Errechnen von Wahrscheinlichkeiten. Nach einer entsprechenden Warnung, so die Forschenden, sei dann immer noch der menschliche Teilnehmer gefragt, durch gezielte Fragen oder Rückruf auf einem anderen Kanal die Identität des Gegenübers zu verifzieren. Verfügbar ist das Programm derzeit noch nicht, es soll im nächsten Schritt mit Unternehmen und Videokonferenzanbietern erprobt werden.
 

| Illustration: Ceasar Zeppelin, Material: stock.adobe.com / thongden_studio, stock.adobe.com + tetiana

AI organizations also use C2PA in the opposite direction: ChatGPT, for example, embeds information about the provenance of AI-generated images in their metadata, which can be detected by platforms such as LinkedIn. When posted, the images then receive a small CR symbol indicating their provenance. However, taking a screenshot of an AI-generated image is enough to remove the indication. This shows that some technologies only work when the user also has an interest – in this case, in proving the provenance. The same applies to invisible watermarks such as Google’s SynthID.

Such approaches also require at least two important additions: a standard and verification of institutions or individuals. For different camera manufacturers, software tools, and platforms to be able to communicate with one another, there must be a common format as well as a common answer to the question of whose signature is considered trustworthy. C2PA is an industry standard developed by a private coalition with more than 6,000 members, meaning it is a voluntary agreement within the industry, but not yet an officially adopted set of rules. Since the end of 2024, the specification has been under review as ISO 22144 under the title “Authenticity of information – Content credentials.” The vote among ISO member countries is currently underway.

Secure digital identities are important for knowing who is behind a signature. Cryptography is also used here: an issuer, such as a government authority, cryptographically signs a credential that the individual stores in a digital wallet on their smartphone and can selectively share. It is also possible to confirm only a single attribute, such as “is of legal age” or “is an employee of news agency X.” In Europe, the EUDI Wallet (based on the eIDAS regulation) is the best-known example of this architecture.

What is missing are social media and other platforms that support such tools rather than removing the relevant metadata. Platforms that are also not interested in polarization because it generates clicks – and therefore money – but rather in democracy and truth. Initial approaches exist, for example, in the form of the decentralized Fediverse, which makes platforms decentralized rather than monopolistic and prevents a single company or billionaire from determining what happens – especially one who also profits from disinformation.

Contact
VDE dialog - the technology magazine