The library.
Everything we publish in one place: white papers, articles, and short notes. Search by keyword or filter by topic and format.
11 results
Detectors collapse from near-perfect to near-random.
An initial benchmark and robustness re-evaluation of leading open-source deepfake detectors, stratified across generators, platform degradations, and demographic groups.
When a 15-dollar AI ID passed a live exchange KYC check.
The OnlyFake case is the cleanest documented example of an automated control being beaten by generative AI: a synthetic passport image cleared a crypto exchange's document verification.
A cloned voice that said the password, and the bank let it in.
Reporters cloned their own voices and passed bank voiceprint authentication. Researchers defeated it with up to 99 percent success in six tries. The industry now concedes the control is beaten.
The engineer a security firm hired was a North Korean operative.
A North Korean operative cleared a security firm's background check, reference checks, and four video interviews using a stolen identity and an AI-augmented photo. The verification that failed was remote identity screening, and it fails at industrial scale.
Two deepfake CEOs, two executives who did not fall for it.
A cloned voice of Ferrari's CEO and a deepfake of WPP's CEO both failed, and neither was stopped by a detector. Each was stopped by a person verifying something the impostor could not supply.
Meta's Muse watermark, and what it does not do for deepfake detection.
Meta's Content Seal watermark labels the content Meta itself generates. That is useful, and it is not the same as detecting the deepfakes an attacker actually makes.
The deepfake that opened real bank accounts, and the call that did not.
A Hong Kong ring used face-swap deepfakes to pass remote bank onboarding and open real accounts. Contrast it with the famous 25-million-dollar video call, which bypassed a person, not a control.
Why an AUC near 1.0 is usually a confound, not a result.
When a detector scores almost perfectly on a single dataset, the likeliest explanation is that it learned the dataset, not the attack.
Report the worst group, not the average.
Why a pooled accuracy number hides the subgroup failures that matter most for fraud and fairness.
The deepfake-hiring pipeline, and what detectors miss.
How synthetic candidates clear interviews, and where the detection layer tends to break.
What a detector sees, and why compression fools it.
A plain-language look at how platform re-encoding erases the very artifacts a detector relies on.
Field notes
Quarterly changes in attacker tooling, in your inbox.
A short briefing on shifts in attacker tooling, four times a year.