DF-Captcha: A Deepfake Captcha for Preventing Fake Calls
Yisroel Mirsky

TL;DR
This paper introduces DF-Captcha, a lightweight challenge-response system designed to detect deepfake-based social engineering attacks, effectively exposing attackers by exploiting deepfake limitations and avoiding heavy, easily evaded defenses.
Contribution
The paper presents a novel, lightweight deepfake CAPTCHA that leverages the technical constraints of deepfake technology to prevent impersonation-based social engineering attacks.
Findings
Effective in exposing deepfake attackers
Lightweight and easy to deploy
Breaks the reactive arms race in deepfake detection
Abstract
Social engineering (SE) is a form of deception that aims to trick people into giving access to data, information, networks and even money. For decades SE has been a key method for attackers to gain access to an organization, virtually skipping all lines of defense. Attackers also regularly use SE to scam innocent people by making threatening phone calls which impersonate an authority or by sending infected emails which look like they have been sent from a loved one. SE attacks will likely remain a top attack vector for criminals because humans are the weakest link in cyber security. Unfortunately, the threat will only get worse now that a new technology called deepfakes as arrived. A deepfake is believable media (e.g., videos) created by an AI. Although the technology has mostly been used to swap the faces of celebrities, it can also be used to `puppet' different personas. Recently,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Internet Traffic Analysis and Secure E-voting · Spam and Phishing Detection
