If Günter Jauch recommends a crypto investment, it should be a legitimate investment. After all, the TV host is considered particularly trustworthy by many, and the video looks real. But it isn’t. Deepfake technologies make it possible to make celebrities such as Markus Lanz, Barbara Schöneberger, and Günter Jauch appear to endorse something they would actually never recommend – and to do so so convincingly that people repeatedly fall for it. No less serious than the potential financial loss is the resulting loss of trust. Photos, videos, and audio recordings are no longer automatically credible sources today. In recent years, the forgeries have become increasingly sophisticated. But the technologies that make manipulation possible are also part of the solution to the problem.
The best-known approach is to calculate probabilities as to whether something is genuine or was created by humans. This is how AI detectors such as Pangram work. The company became known because its software was used to supposedly prove that the speeches or guest articles of several politicians had been written by AI. “Supposedly” because such evidence is not conclusive. Instead of providing a definitive statement about an individual case, it merely produces a statistical probability. Comparable tools also exist for images and videos. Microsoft originally developed its Video Authenticator for the 2020 U.S. election campaign, during which targeted disinformation was a major issue. This tool is also based on probabilities: the program uses AI to identify patterns and detect typical problems associated with deepfakes, such as transitions between authentic and generated material or differences in image sharpness. The problem is that the AI systems generating content are becoming increasingly sophisticated, which also makes it more difficult to detect such characteristics.
The same applies to AI tools that ultimately do the same thing as humans: look for errors, such as six or seven fingers on a human hand. But things are no longer that simple today, and in many cases this is no longer possible at all.
For this reason, the industry is increasingly focusing on cryptographic evidence such as digital signatures or so-called hashes. In a sense,these are tamper-proof seals that can be verified technically. Ultimately, this is tried-and-tested, well-researched cryptography – the technology used, for example, in HTTPS certificates or signed software updates.
The C2PA standard forms the basis for one of the largest existing ecosystems for verifying the provenance and authenticity of digital content. Participants include Adobe, Microsoft, Sony, Leica, Nikon, the BBC, and the news agency AP. A camera can cryptographically sign images and videos directly at the time of capture in the form of a hash – a kind of digital fingerprint of the exact pixel data. Metadata such as the camera model, timestamp, or GPS data is also added. Every subsequent edit of an image is likewise signed and embedded in the image file, making it possible to verify the entire chain. To verify the provenance of images and videos, the public key of the certificate holder is used to check whether the signature matches the certificate.
However, there is a catch here, too: While the technology proves the cryptographic origin of a file, it does not prove that a camera actually photographed something real. It could also have been pointed at a screen displaying deepfakes. Moreover, this does not come close to covering all the cases in which people want information to be verified. This is especially true for events where no professional photographers with such state-of-the-art equipment are on site and material captured in real time on private smartphones is being shared via social media.
Wenn der Fake-Chef anruft
Videokonferenzen ermöglichen persönliche Gespräche und sich dabei in die Augen zu schauen über Städte und Länder hinweg. Doch auch dieser Kommunikationsweg ist nicht mehr sicher. Cyberkriminelle haben Videokonferenzen besonders in Unternehmen für eine neue Betrugsmasche entdeckt. Technologien können Bilder von Personen und deren Stimmen in Echtzeit so realistisch darstellen, dass ein Chef nicht erkennt, ob da wirklich seine Mitarbeitenden in der Leitung sind oder es sich um Deepfakes handelt.
Vor diesem Zweig des Identitätsbetrugs warnt das Fraunhofer-Institut für Sichere Informationstechnologie SIT und macht auf einen starken Anstieg solcher Fälle aufmerksam. Im Rahmen eines Forschungsprojektes haben Fraunhofer-Forschende eine Software entwickelt, die Teilnehmenden bei sicherheitskritischen Calls kontinuierlich Hinweise geben soll, wie wahrscheinlich ein Deepfake ist. Wie andere Detektoren basiert das System auf dem Errechnen von Wahrscheinlichkeiten. Nach einer entsprechenden Warnung, so die Forschenden, sei dann immer noch der menschliche Teilnehmer gefragt, durch gezielte Fragen oder Rückruf auf einem anderen Kanal die Identität des Gegenübers zu verifzieren. Verfügbar ist das Programm derzeit noch nicht, es soll im nächsten Schritt mit Unternehmen und Videokonferenzanbietern erprobt werden.