Skip to content

Deepfakes, Detection, and the Misinformation Landscape

Speaker: Hany Farid
Venue: UC Berkeley
Year: 2026
Video ID: AOJ0-u_IH2g

TL;DR

Generative AI has moved from nascent to commodity in just 18 months; text-to-image, text-to-video, and real-time interactive deepfakes are now trivial to create. Humans are bad at detecting them (performing ~60% accuracy on trained tasks vs. 50% chance). Farid outlines concrete detection techniques exploiting the gap between AI's statistical nature and physics (perspective geometry, shadow consistency, mannerism temporal coherence), then catalogs weaponization: non-consensual intimate imagery, financial fraud ($25M wire transfers via CFO impersonation), North Korean infiltration of US companies, and geopolitical video deepfakes (fake calls between world leaders). The core insight: we need layered solutions—individual literacy, platform responsibility, AI company safety measures, supply-chain regulation (cutting financing), and national policy—because detection alone cannot scale to billions of uploads.

Key claims

Generative AI capabilities have accelerated radically: What seemed 5–10 years away two years ago is now trivial. Photorealistic images, indistinguishable videos, and real-time interactive AI agents are all publicly available, often for free, requiring only a laptop and internet connection.

Humans are perceptually blind to synthetic media: Perceptual studies across images, audio, and video show people achieve 55–68% accuracy—barely above chance (50%). Our visual and auditory systems did not evolve to discriminate synthetic from real; we have high confidence despite poor performance.

The detector must work at scale; reactive forensics cannot. The asymmetry favors the attacker: billions of uploads daily, detection must be reliable on any content, and forensic analysis is time-consuming. Passive (reactive) detection after-the-fact, while scientifically rigorous, does not scale to protecting the general public.

Generative AI is statistically sophisticated but physics-naive: Models learn billion-parameter distributions but lack knowledge of 3D geometry, optics, dynamics, or shadow physics. This asymmetry is exploitable: real images must obey constraints (vanishing points from perspective, shadow-light relationships); AI images often violate them, and human eyes don't notice the violation.

Weaponization is already widespread and escalating: Non-consensual intimate imagery (nudification) is rampant; $25M wire-transfer fraud via CFO deepfakes has occurred; North Korean state actors are using deepfake-masked identities to infiltrate US companies and steal IP; fake videos of government officials on calls with foreign leaders have already occurred (mayors of Madrid, Berlin, Vienna fake-called about NATO).

Speech synthesis and voice cloning now happen in real-time: Interactive deepfake agents (e.g., via Zoom-like interfaces) listen, formulate responses, generate audio, and synthesize video in <0.5 second latency. They are commercially available and poised to displace human customer support, doctors, lawyers.

The problem is structural, not technical alone: Creation is cheap and easy; detection is expensive and hard. Misinformation works because it's profitable and there's little consequence. The solution requires action upstream (AI companies, regulators, platforms) and downstream (literacy, individual skepticism), not just better detection.

Humans are responsible; so are platforms, AI companies, and regulators. Individuals must stop treating social media as a news source; platforms must take safety seriously; AI companies must implement safety guardrails; and governments must regulate (as the UK, EU, and Australia have begun doing). The US has, to date, chosen not to regulate, and that is a choice with real consequences.

Detection techniques discussed

1. Perspective geometry (vanishing points): Parallel lines in the physical world (tile edges, architectural lines) must converge at a single vanishing point under linear perspective. AI models generate content statistically and often violate this constraint. By annotating parallel lines and checking whether they intersect at a common point, deviations from physical plausibility can be identified.

2. Shadow physics: A shadow is a line in 3D space from an object point through the shadow point to the light source. If a dominant light source is present (e.g., the sun outdoors), all shadows must be consistent with it. AI models often generate multiple, inconsistent light sources or shadows that don't align with the objects casting them. Measuring these constraints reveals physical implausibility.

3. Lip-sync detection (audio-visual consistency): Deepfakes often replace mouth movements while leaving the rest of the face unchanged. Automatic lip-reading (from visual lip motion) and audio-to-text transcription are independently computed; real speech shows small distance between them, while lip-sync deepfakes show large divergence. This signal is robust because it exploits the human sensory-integration illusion: we hear the audio and don't consciously notice the mouth is saying something different.

4. Behavioral biometrics (mannerism clustering): Individuals have distinctive, consistent mannerisms: head movements, eye gaze, facial action units, hand gestures, and correlated patterns (e.g., smiling correlates with head-up tilt in Obama's videos). AI synthesis engines work frame-by-frame and cannot hold 10-second temporal windows in memory. By extracting these mannerism patterns over long temporal windows (300 frames at 30 fps = 10 seconds), one can build a one-class detector for individuals. Deepfakes violate the mannerism patterns, even if individual frames look photorealistic.

Why detection is hard: Generative AI is improving rapidly; each advance closes detection gaps. However, a key asymmetry remains: synthesis must happen in real-time (for video calls) or preserve long temporal coherence (for offline video), while detection can wait. Thus, mannerism-based detection has a structural advantage—adversaries face massive computational burden to synthesize 10-second coherent mannerism sequences.

Weaponization examples

Non-consensual intimate imagery (NCII): Grok AI and other tools allowed users to upload images (primarily of women and children) and generate nudified versions. These were hosted on X (Twitter) and spread widely. The term "deepfake" itself originated from a Reddit user who applied this technology. NCII is now rampant globally—school children, adults, cyber criminals all participate; victims face extortion, harassment, and platform exile.

Financial market manipulation: A fake image of the Pentagon being bombed was posted online ~90 seconds after stock market open. The stock market dropped $0.5 trillion in 90 seconds before people realized there was no actual attack. Evidence suggests AI-generated image → human reaction → AI trading bot reaction → cascade. This demonstrates the potential for coordinated spoofing attacks around earnings, IPOs, and other market events.

Enterprise fraud: A $25M wire-transfer fraud occurred when a CFO received a video call from what appeared to be their boss. The video was an AI-generated deepfake (face and voice). The attacker persuaded them to wire $25M for a deal; the money was lost before discovery. Multiple reports have documented tens of millions in losses across Fortune 500 companies, with many incidents unreported due to embarrassment.

Supply-chain infiltration (North Korean actors): North Korea has deployed state actors to apply for US IT jobs using deepfake identities (masked voice, masked face, masked location). They pass interviews, get hired, collect paychecks sent to the state, and simultaneously steal IP, install malware, or install viruses. A US defense contractor had five North Korean state actors on staff; every Fortune 5 company has been similarly targeted. This is state-sponsored labor arbitrage and espionage.

Geopolitical deception (fake government calls): Early in the Russian invasion of Ukraine, the mayors of Madrid, Berlin, and Vienna were on calls they believed were with Kyiv's mayor, but were actually Russian intelligence extracting NATO movement information. Members of US Senate Foreign Relations and the White House have received calls from what appeared to be foreign officials but were actually Russians. This demonstrates real-time interactive deepfakes used for intelligence gathering.

Responsibility and solutions

Individual responsibility: Stop getting news from social media. Read from established outlets (NYT, BBC, NPR, WSJ, Reuters) and cross-check across multiple sources. Be skeptical on social media—it was not designed for news and is bad at it. Individuals share and click on misinformation, making them part of the problem.

Platform responsibility: Social media platforms (Facebook, TikTok, YouTube, Instagram) have taken a "cavalier attitude" to online safety for 25 years and profited handsomely. They must implement safety measures and enforce them.

AI company responsibility: Generative AI companies are commercializing tools without adequate safety guardrails. They know their tools generate NCII, child sexual abuse material, market-manipulation images, and geopolitical disinformation, yet they do little to prevent it.

Regulatory responsibility (upstream interventions): Rather than detecting misinformation at the consumer level, regulation should target choke points. For NCII and illegal content, regulators can cut off monetization: Visa, Mastercard, American Express, and PayPal (the four card networks) and Google (which controls ~80% of ad serving). When Nicholas Kristof published his exposé of Pornhub hosting CSAM, these institutions terminated relationships overnight, and Pornhub was forced to restructure. Cutting financial incentives works.

For broader content policy, infrastructure providers (Cloudflare, Amazon, Google, ISPs) are also potential leverage points. This approach goes upstream and doesn't require perfect detection—it targets the economic model.

Media authentication (C2PA and active forensics): C2PA (Coalition for Content Provenance and Authenticity) is a standard allowing devices (cameras, phones) to cryptographically sign media at the point of capture with timestamps, location, and identity. When shared with the world or law enforcement, authenticity can be verified. This works at scale if deployed to billions of devices. Leica and Sony high-end cameras currently support it; penetration is low, but deployment could accelerate as desperation increases. If Apple and Samsung adopted it overnight, the infrastructure would transform.

Connections

Notes

This talk is valuable for its comprehensive landscape overview—spanning technical detection methods, weaponization case studies, and policy solutions. Farid is explicit that detection alone will not solve the problem; the talk pivots to upstream interventions (supply-chain financing, regulatory frameworks, platform responsibility) and downstream ones (literacy, individual skepticism).

The observation that AI is "very good but physics-naive" is pedagogically powerful and explains why physics-based forensics work: there is no adversarial pressure on AI companies to implement 3D rendering and real-time geometric consistency (because consumers don't perceive the violations). This changes if adversaries specifically target Farid's techniques, but the current incentive structure favors detection.

The mannerism-detection approach is particularly elegant: it leverages the temporal asymmetry between synthesis (frame-by-frame, real-time constraint) and analysis (can wait 10 seconds), making it robust against incremental AI improvements. This is a principled example of exploiting an attacker's operational constraint rather than trying to close a purely statistical gap.

The talk also emphasizes the human perceptual failures documented in controlled studies—a needed corrective to the assumption that "obvious fakes" are preventive. At 55–68% accuracy on trained tasks, humans are worse than coin-flip at detecting synthetic media. This is not a gap that education or "visual training" can realistically close.

Finally, Farid's framing of responsibility—individuals, platforms, AI companies, and governments all have roles—avoids the false choice between "technology will fix this" and "we're doomed." It's a mature policy analysis grounded in both technical insight and institutional understanding.