AI Leadership Insights: The Rise of AI-Powered Deepfakes with Ofer Friedman
In this Techstrong.ai video interview, Ofer Friedman, chief business development officer for AU10TIX, explains why deep fakes created using artificial intelligence (AI) technologies are becoming more difficult to detect now that professional criminals are building them.
Transcript
Hello, and among the latest edition of the Techstrong AI video series, I'm your host, Mike Va. Today we're with Offer Freeman, who is chief business Development Officer for all 10 ticks. And we're talking about all these deep fakes that are now applying for jobs out there and HR departments are getting full left, right and center offer.
Welcome to the show. Thank you, Michael. Thank you for having me.
How is all this happening? You wouldn't think that the deep fakes are that good, but it seems to become a much more pressing problem. Almost every day.
You're hearing about somebody had some sort of incident. So what's going on here? Well, um, there are the defects, you know, and the defects.
You might not because those you hear about are those that have been detected and those that are, are being written about. Problem is that there is the, the, uh, normal world and there is the underworld of deep fake, and I mean more professional crime and the level of tools and the intensity of usage and the effectiveness of it are out of the scale of most detection systems. Is this more something of a organized crime phenomenon and what, what is the ultimate purpose here?
Is it just to steal payroll or how, what's the ill-gotten gain When you're talking about, uh, generative ai and particularly the one known as, uh, deepfake, you are talking about media as you may know it, and as a media, it's not just for applying for a job, it's also your news and it's also your, um, basically media communication, et cetera. So it touches virtually the basic fabric of society as we know it. It's time to doubt what your senses are saying.
So all these deep fakes essentially become insiders inside these organizations, and then they know what's gonna happen, and then they share that with people who might be trying to make, uh, or manipulate stock prices, for example. Um, what else can they do with all that information? Well, um, first of all, when let's differentiate between amateurs and professionals.
So the average amateur would probably want to open an account somewhere, withdraw some money somewhere. They will be using off the cheff tools of one kind of another, probably combining, uh, d fake IE generative ai, but also injection because I'm now talking to you, so I need to respond to you. It's not just me sending some kind of video.
So the amateur might do it once. It'll be, uh, by large detectable. What's worrying is what professionals are doing and professionals are, let's say at least, uh, three types of them.
You have those, uh, people who basically group together in order to do that. Uh, they are producing some volumes of attacks and the level should be, uh, much better than the average because they know how to use a combination of tools in order to produce it. Then you have organized crime level of, uh, DeepFakes.
And I think that, um, I've already been interviewed a couple of times about, uh, what's now rapidly becoming, um, deep fake fraud as a service, which means it's not just in my ability to now create some kind of, um, response to you over a streaming video. It is an ability to launch a coordinated attack in big numbers. And by big numbers, I mean, our biggest sketch of last year was 20,000 attacks, each one of them using ai, not just to replicate the attack, but also to make changes of it.
So you never repeat yourself and as a service, it means that I could show you, but I don't want to give people wrong ideas. Uh, you already have, uh, tools online available. It won't cost you that much.
That enables you to tell to say, I want to be this and that person in terms of the details. I want this and that phase, and I want to attack company X, company Y, company Z. All you have to do is bring it all in and the entire onboarding and identification process is done for you.
You don't have to talk to me now, it's already being done because professionals even know which technologies are protecting which companies, and obviously it's not every company. It's usually those who are worthwhile attacking like companies in crypto and debt of the thing. Now, once you are nearing election time, obviously there is the political aspect of it.
So now you're talking presumably about, uh, government led or government sponsored, or whatever you want to call it, usage of deep fake in order now to basically engineer mindsets. How sophisticated does the organization have to be to launch these types of attacks? I mean, is it gonna be the same people who that we see building ransomware as a service kind of platforms, or is this a special type of entity?
First of all, um, I'm kind of would not be much surprised if some of them have already been working for companies who are supposed to be detecting fraud. So the mode of operation and the tools used are familiar to them. And um, secondly, you do need skills in order for this to pass, and not once, but multiple times, you have to have tools which basically are a kind of CRM for fraud, and there must be combining if possible, uh, seamlessly the production of the deepfake, but also the insertion of the deepfake and the response to whatever you're being required to do on the other side.
Now, now it's now a little bit talked about in terms of, uh, job seeking because, um, more and more of it is being done remotely. Obviously in a situation where I'm sitting in front of you in the same office works less, but more and more, uh, you see those international platforms where like gig economy, et cetera, where people are selling their services or applying not necessarily in your office. And then, uh, what plays into the hands of frauds is basically, uh, types of biases, cognitive biases that could not exist until the fake came into play.
How do we go about detecting any of this then? I mean, is there some way to go after this or do we just have to be extra vigilant on everybody we deal with? I wish we could be extra vigilant.
You can say the same about detecting viruses attacking you. Please be extra vigilant and let's see how much it helps you. No, it is, it is no longer the, the question of vi vigilance, although vigilance obviously would be recommended.
It's a question of tools. And here some gaps already appear in the market because at least two generations of deep fake and talking now only about deep fake, not about the injection, at least two generations of detection exist in the market. The most prevalent of it of them would be, uh, having learned big data which you generated or got, um, otherwise to teach them, uh, into a system.
And then the system should be able to detect the fake. Now, this obviously is very short term because the assumption of simple deep learning or, uh, is that, um, once there is a generated, uh, deep defect, that's what defects look like so they don't get better. So if you have, uh, a big pool of those to learn on, you are good.
Problem is the defect changes. It improves the rate that I don't think any other method of fraud has been, uh, improving so fast. And here, by the way, talking about the job seeking or job interview market, it's even more problematic to detect because you have at least two types of defect happening at the right, at the, at the same time challenging your senses, which is, uh, if it's a job interview like this, you are seeing me, I'm responding to you, but you also hear me.
So at least two of your senses are saying that's real. In any other setting you can think about, which is not sitting in front of you, you either see what I wrote or you see something I sent you. Now too many sensors are are telling you this is me.
So the detection of it becomes a little bit more complicated and the good old way of let's get a big chunk of, of big data of samples generated or otherwise and learn them, it doesn't hold water. We see changing so fast that you'll have to keep on generating those and presuming that you, uh, can generate even the newly coming types of, uh, of tools and frauds, which doesn't make sense. In other words, the strategy that probably makes the most sense, and I think companies like, um, reality defender is one of the foreign runners of is multiple engines.
Instead of trying to detect the fraud because something in the picture or the video should be wrong, you are looking for the footprint or fingerprint or the DNA of an engine that creates them. It's kind of a way, if you want, if you will, a kind of fast forward to what happened at the world of, uh, virus detection. If you remember at the beginning they would detect a virus, then they would create some kind of, uh, detection method from it.
So a new come one comes, a new one has to be analyzed, et cetera. Obviously there's so many of them, there's no way to do it. That's why the strategy, um, switched to the detection of anomalies without necessarily knowing what that particular virus is doing.
And the same thing needs to happen also in, um, defect detection. As we kind of think this through for a minute, this is gonna get worse before it gets better, I think because the large language models that are being used to create the deep fakes have more advanced reasoning capabilities. Am I correct?
First of all, let, let's say this, first of all, in order to create a good convincing deepfake, and let's say year, a year ago, you needed a couple of tools. So first thing to do is combine all those different elements like lip syncing and picture, et cetera, et cetera, et cetera, into one. Uh, then comes, uh, the issue of uh, um, how to do it in real time because now I'm talking to you, you don't want to reach the conclusion that I'm not me at the end of it or after application.
So it has to to happen in real time. So what I'm saying is that, um, it's a different ball game then fraud detection as anyone knew it Will. We have to find some way to actually authenticate people where I can know that some maybe through some multi-factor approach that, um, multiple people that I know vouched that you are who you are and we can have devices that confirm that you are where you are.
I mean, uh, can we use any of our existing tools to help with this? Well, uh, as, as you probably know, the world is supposedly fast moving into the, into the generation of, uh, digital ideas IE IDs that are not paper plastic, but are on your mobile. They are supposed to and are obviously much safer because they are based on asymmetric keys that are extremely difficult to break if you are, if you don't have a quantum computer.
And by the way, you will have in let's say a decade, but until then it's supposed to be safe. But what happening is that not just fraud is changing, but also the methodology is changing. Since it's more difficult to break my code, it is not my point of onboarding that it will not be compromised.
It's when I am calling you, I'm already a client, I can pretend to be a client you already have. So I'm pre verified. So what is happening?
Is that true? You can defend the identity source in a way, but not necessarily the other vulnerabilities that exist along the pipeline. So instead of fraud now concentrated so much on the point of customer onboarding, it'll be more on, uh, pretending to be you when you are already a customer.
So if I know which bank you are working with, I'm sure you'll tell me shortly and I have the basic details. I can be you without any problem. And normally, I mean, how many times will I need to undergo a complete verification if I'm already a client?
And more so if I'm a client with a digital id, I'm pre verified, you don't need a plastic ID anymore. So breaking into mobiles will be a good idea to get, uh, convincing, uh, convincing, uh, IDs and then using them in conjunction with d defect and injection. So look, it's, it's a, it's an arm's base.
There is no antidote and that's it. Everyone is good. Are HR teams aware of this now and what's your best advice for them?
'cause I would assume they need some help from their cybersecurity teams. Well, first of all, cybersecurity and identity verification that used to be kind of different domains are actually converging. They're, they're supposed to be doing similar things if not copying methodologies and eventually coordinate like, uh, um, cooperating and coordinating.
So yes, you do need, basically, and I think you mentioned it, it's obviously a question of, uh, multi-layer defense. The more hurdles you put in front of someone, the more you, let's say increase the chances of, uh, removing not the mafia perhaps, but most of the others. And in terms of volume until now, it's the mafia doesn't constitute most of the attacks, by the way.
The problem now is with automation, the share of professional attacks are increasing because of the ability to launch multiple ones. So you'll see more professional attacks in comparison to amateur and attacks. So, uh, the second thing is you need probably to check what kind of defense you have, because defect detection is no longer just defect detection, and that's it.
You need to see what is the methodology, a multi-engine detection? Is the methodology just learning, uh, based on AI learning of, um, of, uh, of, uh, samples of defects? Is it, uh, based on, uh, generating your own samples in order to do your own training?
Or is it an algorithmic way to do that? So you kind of have to go a little bit more professional in order to ask the question questions. And the issue is that the market doesn't know it yet.
The vast majority of companies is not aware of it. And my assumption is that, uh, slowly it will sink in for a simple reason because all the social media and the news media, or media as you know, it will incorporate such capabilities, uh, in it. So expect the expectation to have some kind of deep fake detection methodology will be common knowledge.
Everyone would expect it. And the only question would be once, you know, you have to do that check on the box is to check what exactly is being sold to you. Uh, it's, I mean, I, I'll be happy to advise anyone, but if not, you have to kind of do your learning and at least start by understanding what kind of defects are there and what kind of methodologies can serve you.
How patient will these attackers be? 'cause I can imagine, uh, a scenario where they create a deep fake and the deep fake goes to work for some company and they could be in there like a mole for multiple years, and then they get a job somewhere else based on the fact that they have a history of employment somewhere, and then they turn out to be a deep fake. So my question is, is are are deep fakes essentially, you know, gonna become moles over time that, you know, may be operating for years?
Uh, Look, they already are. The problem with, uh, identity, uh, verification or identity fraud is that once you got in, by definition, you're good. Okay?
And until now, there was no way to go back to your database and say, Hey, we have x, y, Z number of, uh, people who actually are not real people. But now there are a, there, there's actually the technology to do that, at least we have, uh, which is not based on the common, uh, case level analysis. Uh, there is a picture of an ID and there is a picture of a face and there was some kind of, uh, liveness detection done on it because this already have been done, they're already in.
So there is actually a methodology to go back into your database and flush those Trojan horses out, because if you don't, we are actually going into an era where confidence in your identity is going to increase or not decrease because of the digital IDs. Everyone is being taught that they are, if not flawless, they're so, so, so strong that they will curb the vast majority of fraud. Unfortunately, that's not the situation.
So the, the, the long story short is the A there already molds in especially the lucrative companies, the cryptos, the money transfers those who are typically being attacked and they will be waking up and, and and activating at a certain point in time. And B, um, let's say in the US many states are now moving into the real id and you are supposed to actually physically go to some, uh, DMV and issue your, but what you have to show in order to be cleared and verified are the good old means you've been showing before. So that's the heyday of whitewashing, if you will, fake IDs, reinventing yourself and getting the stamp.
So now it'll be just another plastic, real ID safer, it'll have a micro print, it'll have whatever, which obviously will not, will not help you that much in a remote online situation. Mm-hmm. But shortly and already there are states that are issuing, uh, it's, I'm referring to the years, although it exists worldwide.
Digital IDs on, uh, on mobiles. Once you are verified, no one will ask for you for, for, for anything else because there is no plastic anymore. It's all non immobile Folks, you heard it here.
Deep fakes are getting more insidious. And just when, just when you think you might have a handle on it, turns out these things are gonna become deep moles inside of your organization. Hey, offer thanks for being on the show.
Thank you. All right. And thank you all for watching the latest episode of the Techstrong AI video series.
You can watch this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.