Society is on the verge of an era where reality can be manipulated, truth can be distorted, and trust can be shattered. Deepfake technologies pose a grave and imminent threat to national security. There are a variety of deepfake technologies available today, with differing degrees of complexity and ease of use. Some commonly used deepfake tools include Face SwappingFootnote 120 , Lip SyncingFootnote 121 , Voice CloningFootnote 122 , and GAN-based deepfakesFootnote 123 .
Adversaries, whether state actors, criminals, or clandestine organizations, are continuously working to refine their skills in the art of public manipulation. Deepfakes can further enable these adversaries to achieve their goals of exploiting vulnerabilities, sowing discord amongst the public, and/or undermining the very essence of democracy.
This paper provides an overview of the capacity, impact, and underestimated dangers of deepfakes while recognizing the urgent need for robust and holistic mitigation strategies in the face of this rapidly evolving and highly sophisticated threat.
Implications, Scenarios, and ConsequencesFootnote 124
The capacity for deepfakes to demolish reputations in a single instant exemplifies their insidious nature. Strategic dissemination of a single fabricated video can cause public indignation, financial losses, and irreparable harm to individuals and organizations. Consider a deepfake video in which a prominent corporate CEO makes racist comments. The repercussions of such a planned assault could result in a catastrophic drop in the company's stock price, eroding not only its financial stability but also its credibility in the eyes of investors and stakeholders. Deepfake pornography has already caused harm; a 2019 study found that 96 per cent of the 14,000 deepfake videos found online were pornographic, a number which is infinitesimally small compared to the current landscape featuring non-consensual pornography depicting high-profile individuals such as journalists and celebritiesFootnote 125 .
The malicious potential of deepfakes extends beyond external threats; so-called ‘insiders’ can provide the ultimate advantage to adversaries and/or bad actors. An employee with access to sensitive information can utilize deepfakes to facilitate the leaking of classified data or engage in other illicit activities, thereby compromising national security, jeopardizing the organization’s integrity, putting other employees at risk, and/or causing substantial financial losses. Robust employee screening and monitoring protocols must therefore be implemented to identify and address potential insider threats. Moreover, the development of advanced deepfake detection technology tailored specifically for insider threat prevention is imperative. Those who exploit their positions of trust must face severe penalties to deter others from doing so.
Deepfakes can be incorporated into social engineering campaigns in order to manipulate individuals and organizations for malicious purposes. A deepfake video claiming to show a loved one in peril and/or requesting a large sum of money, for instance, can result in significant financial loss for the target. Increasing awareness of social engineering that deepfakes can facilitate, developing effective detection and response protocols, and nurturing cooperation between law enforcement agencies are essential mitigation strategies.
The economic implications of deepfakes extend beyond reputational damage, as they have also emerged as an effective tool for economic espionage. Adversarial entities can exploit deepfakes to target businesses or industries, aiming to gain a competitive advantage or disrupt critical sectors of the economy. Mitigation strategies include implementing effective deepfake detection technology for business communications, enhancing media literacy for business leaders, and establishing clear protocols for responding to deepfake-related economic espionage. Further, deepfakes can be used to facilitate financial fraud by impersonating individuals with access to sensitive financial information. Implementing multi-factor authentication for sensitive financial transactions is an effective mitigation strategy.
Deepfakes have the potential to penetrate a nation’s most critical, and secure systems, which poses a grave threat to cybersecurity. For example, criminals can exploit deepfake technology to bypass biometric authentication systems, gaining unauthorized access to secure facilities and sensitive personal information. The consequences of such breaches are far-reaching, jeopardizing not only individuals' privacy and also threatening national security. To counter this, anti-spoofing measures for biometric authentication systems must be implemented, ensuring that digital fortresses remain impenetrable.
Deepfakes have also emerged as clandestine weapons, allowing covert operations to be carried out undetected. False evidence can be fabricated or surveillance footage manipulated, undermining confidence in visual records, and impeding intelligence operations. To preserve the integrity of intelligence operations and bolster national security, forensic techniques that can detect deepfakes in video evidence are indispensable.
National Security and Intelligence Implications
Increasing awareness of deepfake threats and mitigation strategies among individuals and organizations at high-risk of extortion or coercion, as well as developing effective cybersecurity protocols, are crucial for preventing and/or mitigating deepfake-related breaches.
As deepfakes are capable of fabricating fraudulent evidence or manipulating public perception, they can lead to a distortion of the truth. Increasing transparency and accountability in the use of deepfake-related evidence, developing detection and verification systems, and promoting fact-checking and verification procedures in media reporting are essential for addressing this challenge.
Disruptions of critical infrastructure or government agencies, can have severe consequences. As such, implementing effective cybersecurity protocols, raising public awareness of deepfake-related threats, and conducting regular deepfake detection and response training exercises for government agencies are key mitigation strategies.
Deepfakes can be utilized as part of cyber warfare campaigns to target critical infrastructure, disrupt government operations, and/or create havoc in financial markets. Increasing awareness of deepfake-related cyber warfare threats among government agencies and critical infrastructure providers, developing effective detection and response protocols, and fostering international cooperation are crucial for preventing deepfake-related cyber attacks. Deepfakes can likewise damage diplomatic relations and/or delay treaty negotiations. Mitigation strategies include developing effective deepfake detection technology for diplomatic communications, increasing media literacy for diplomats and government officials, and establishing clear communication channels for responding to deepfake-related diplomatic incidents.
Terrorist organizations surely recognize the potential of employing deepfakes in the spread of propaganda and coordination of attacks. Even in the absence of deepfakes, terrorism jeopardizes the safety of innocent lives and the stability of critical infrastructure. Therefore, heightened awareness of deepfake-related terrorist threats among law enforcement and intelligence agencies, the development of effective detection and response protocols, and a resolute dedication to international cooperation are vital for countering this nefarious use of deepfakes.
Deepfakes can also spread disinformation specific to military capabilities or movements, potentially resulting in military conflicts. Raising awareness of deepfake-related military disinformation threats among military and intelligence agencies, developing effective detection and response protocols, and promoting international cooperation are essential for preventing deepfake-related military conflicts.
Implications for Democracy
The use of deepfakes to spread false information or propaganda can result in confusion and distrust amongst the public. Developing advanced deepfake detection technology, increasing media literacy education, and enforcing penalties for the spread of malicious deepfakes are crucial in combating misinformation.
Deepfakes can interfere with the democratic process through the manipulation of public opinion, which can impact and/or sway election results. To raise awareness of deepfakes and online disinformation and encourage political parties to work together to prevent deepfakes from impacting the 2019 UK election, advocacy group Future Advocacy created and disseminated a video in which candidates Boris Johnson and Jeremy Corbyn endorsed each otherFootnote 126 . Developing effective deepfake detection technology for political campaigns, increasing media literacy education for voters, and enforcing penalties for the spread of malicious deepfakes during elections are important mitigation strategies.
Deepfakes can easily spread disinformation targeted against specific government officials or departments, which can lead to public distrust and legal action. Implementing effective deepfake detection technology for government communications, increasing media literacy for government officials, and establishing clear protocols for responding to deepfake-related disinformation campaigns are essential.
Deepfakes can be used to create convincing propaganda videos for the purpose of influencing and/or swaying public opinion. Increasing transparency, and funding for election commissions to investigate, and prevent the spread of deepfakes is critical. Similarly, in the context of influence operations, developing robust fact-checking processes, educating the public about the risks of deepfakes, and promoting critical thinking are crucial.
In addition, deepfakes can manipulate (or create) evidence in criminal investigations or legal proceedings, which can lead to wrongful convictions. Therefore, there is a need to develop guidelines for the use of digital evidence and establish procedures for the verification of video evidence in legal proceedings.
Containment and Mitigation Strategies
Containment and mitigation strategies can be technological, legal, and/or societal in nature, and depend on collaboration and responsible governance.
Deepfake detection technologies need to be developed and enhanced. Machine learning algorithms can be used to detect inconsistencies in videos, audio, or images. Blockchain technology could also be used to create immutable records of media content, making them difficult to tamper with.
Legal approaches that will criminalize the creation and dissemination of deepfakes for malicious purposes (beyond the legal repercussion of “fraud”) require consideration. Such laws should provide protections for individuals whose reputations have been damaged by deepfakes.
Media literacy and critical thinking need to be fostered and promoted amongst the public. Public education on the identification of deepfakes and the associated potential risks and impacts would be of value. Journalists and media outlets that fact-check and verify their content before publication should also be supported.
International partnerships and collaborations need to be established in order to combat deepfakes. Such partnerships can facilitate the sharing of knowledge, resources, and expertise, as well as provide a coordinated response to deepfake threats.
Finally, technology companies need to take responsibility for the content on their platforms. For example, they can invest in developing and deploying deepfake detection technologies and make it easier for users to report and remove deepfakes.
Conclusion
The looming spectre of deepfakes presents an unprecedented threat to national security. The rapid evolution and proliferation of this technology demands nothing short of a resolute and comprehensive response.
To safeguard democratic nations, governments must invest in cutting-edge deepfake detection technologies that can unmask digital imposters and expose malicious intent. Simultaneously, legal frameworks must be fortified, criminalizing the creation and dissemination of deepfakes while also providing robust protections for those whose reputations are vulnerable.
The battle against deepfakes cannot be won through technology and legislation alone. Citizens must be armed with the power of critical thinking and media literacy, thereby empowering them to discern truth from fabrication. By fostering a society that is professionally skeptical, informed, and resilient, governments can build a shield against the corrosive effects of deepfakes.
This fight transcends borders and requires global solidarity. Collaborative efforts between nations to share knowledge, resources, and expertise will be the cornerstone of defence. Together, an international alliance against deepfakes that is resilient and unwavering to preserving the integrity of collective societies can be forged.
Furthermore, technology companies must be held accountable. These companies wield immense power and influence, and as such, should prioritize the development and implementation of deepfake detection technologies in order to create user-friendly reporting mechanisms and swiftly remove deepfakes from their platforms. In doing so, technology companies can become defenders of national security.
Deepfakes pose a formidable challenge, but democratic governments and allies must stand united and vigilant against this challenge, as well as resolute in their commitments to protect democratic, diplomatic, and economic security.