[00:00.920 --> 00:03.020] Past, present predictions. [00:03.660 --> 00:10.460] How AI, deepfakes, and psyops will affect the upcoming election cycle with yours truly, BSI Lab. [00:11.160 --> 00:17.360] So first off, who am I and why am I the one here speaking to you today? [00:17.660 --> 00:19.720] I am a 17-year-old girl. [00:19.960 --> 00:22.900] I am a five-time speaker at DEF CON. [00:23.500 --> 00:29.380] And I am currently an intern for IBM's X-Force Red, which is their elite hacking team. [00:29.380 --> 00:39.000] I am also the founder and CEO of Girls Who Hack, my own non-for-profit teaching girls the skills of hacking so that they can change the future. [00:39.340 --> 00:44.440] I provide free online and in-person classes on all things intro to cybersecurity. [00:44.880 --> 00:51.540] I also have my own end-to-end election system that I've been working on called Secure Open Vote. [00:52.320 --> 00:55.780] Last year, for the first time ever, I was a DEF CON goon. [00:56.060 --> 00:59.000] And this year, I'm a DEF CON goon again. [00:59.000 --> 01:01.200] But not just doing that. [01:01.360 --> 01:06.600] I'm also running DC Next Gen, which is the new youth track at DEF CON. [01:06.900 --> 01:09.140] We have a ton of amazing things planned. [01:09.380 --> 01:12.600] We have badges, CTFs, classes. [01:13.060 --> 01:18.160] A ton of different villages are hosting different challenges and fun things at their places, too. [01:18.720 --> 01:21.340] So if you have youth, bring them to DEF CON. [01:21.480 --> 01:23.460] If you don't have a kid, borrow one for a day. [01:26.110 --> 01:27.950] Let's get straight into it. [01:28.310 --> 01:37.770] When talking about election security, it's important to put personal political beliefs and preferences aside to target the real issue. [01:37.770 --> 01:40.810] That's problematic to all parties. [01:40.990 --> 01:43.910] Which, of course, is disinformation. [01:44.970 --> 01:50.570] Disinformation used in a military or political setting is called PSYOPs. [01:50.570 --> 01:54.550] So let's start off with a definition and then a little history. [01:56.050 --> 01:59.250] PSYOPs is short for Psychological Warfare Operations. [01:59.750 --> 02:07.310] These are military operations usually aimed at influencing the enemy's state of mind through non-combative means. [02:07.710 --> 02:15.810] These techniques are used by military and political forces to influence the beliefs, emotions, and behaviors of citizens. [02:15.810 --> 02:19.430] At the end of the day, it's all marketing. [02:19.450 --> 02:23.110] But instead of a product, they are selling you an ideal. [02:23.850 --> 02:30.390] These PSYOPs operations play on the seven deadly sins. [02:30.690 --> 02:38.670] Which are lust, gluttony, pride, sloth, wrath, greed, and envy. [02:38.670 --> 02:44.170] These seven sins are the greatest desires known to humankind. [02:44.430 --> 02:47.790] So avoiding these feelings is virtually impossible. [02:48.630 --> 02:56.550] Additionally, they play on the strong human emotions of anger, fear, and hate. [02:57.050 --> 03:03.210] As I'm sure you already realize, these are the easiest emotions to stir up in an individual. [03:04.210 --> 03:09.190] To put all of this into practice, let's look at some past PSYOPs campaigns. [03:11.030 --> 03:16.250] In the times of World War I and World War II, you'd see propaganda everywhere. [03:16.250 --> 03:24.310] In many different forms, like billboard ads, radio ads, newspapers, and even posters. [03:24.310 --> 03:29.790] These posters included sayings such as, I want you for the U.S. [03:29.870 --> 03:32.270] Army, which plays on pride. [03:32.510 --> 03:38.710] And, he volunteered for submarine service, which obviously plays on lust. [03:39.770 --> 03:45.110] Next, let's look at a PSYOPs campaign from the Vietnam War. [03:46.410 --> 03:48.810] In the Vietnam War, the U.S. [03:49.030 --> 03:55.790] military played a soundtrack called Ghost Tape Number 10, as you can see here. [03:56.390 --> 04:03.190] They played this in the Vietnamese jungles at night to persuade all the Vietnamese troops to surrender. [04:05.430 --> 04:13.930] U.S. forces hoped that this operation, codenamed Wandering Soul, would prey on many of the fears of the Vietnamese. [04:14.870 --> 04:20.450] The Vietnamese culture includes beliefs and rituals that show respect for the dead. [04:21.010 --> 04:30.510] They believed if a person is not properly buried, they would wander the earth as a wandering soul, hence the name of the operation. [04:32.610 --> 04:38.890] So, let's do a little role play very quickly to see how this can affect the psychology in someone's brain. [04:39.630 --> 04:46.850] Picture yourself as a Vietnamese soldier walking through a dark, damp jungle in the middle of the night. [04:47.170 --> 04:54.290] You're tired, you're hungry, and you just want to go back home to see your family, who you haven't seen in ages. [04:55.590 --> 05:10.250] Suddenly, you hear the sounds of your fellow soldiers who have died, their souls wandering through the jungle forever, and the eerie sounds of Buddhist funeral music screaming, crying, and the sounds of ghosts and spirits. [05:10.990 --> 05:12.950] Let's take a listen to what they heard. [06:10.350 --> 06:11.430] Let's take a listen to what they heard. [06:19.550 --> 06:23.710] Let's move forward again, and talk about the Gulf War. [06:24.270 --> 06:26.550] At the time of the Gulf War, the U.S. [06:26.750 --> 06:36.010] sent out pamphlets to the Arabian soldiers, telling them that if they surrendered, they would be treated very well, and no harm would come to them. [06:36.010 --> 06:44.330] These pamphlets were so effective because they were designed with the help of cooperative Iraqi prisoners of war. [06:44.850 --> 06:52.290] They advised against using the color red and to feature the soldiers eating fruit, such as bananas. [06:52.710 --> 06:58.590] And bananas are a delicacy to the Arabians, so this played on the sins of greed and gluttony. [06:59.690 --> 07:04.650] Many troops surrendered, holding that pamphlet, as you can see right here. [07:07.310 --> 07:14.690] Let's jump ahead in time, and talk about a more modern PSYOPs case, concerning Cambridge Analytica. [07:15.250 --> 07:18.110] Who here has heard of Cambridge Analytica before? [07:18.110 --> 07:20.310] Okay, here we go. [07:20.550 --> 07:21.110] You know it. [07:21.870 --> 07:29.030] Cambridge Analytica was a political consulting firm that used large datasets to target and change the minds of voters. [07:29.710 --> 07:36.310] They used Facebook personality surveys to sort people into a few main categories. [07:36.310 --> 07:43.470] The survey, coupled with other Facebook data, created what is known as an ocean score. [07:44.570 --> 07:53.250] Ocean, also known as the Big Five, stands for openness, conscientiousness, extroversion, agreeableness, and neuroticism. [07:53.990 --> 07:59.770] Depending on your ocean score, they would determine if you are a persuadable. [08:00.830 --> 08:06.050] A.k.a. someone whose political views could be easily changed, or swayed, hence the name. [08:08.570 --> 08:15.250] Content farms, like Cambridge Analytica, make thousands of fake ads and articles. [08:15.870 --> 08:22.570] These are then amplified through fake accounts, which also comment on them, further fanning the flames. [08:24.150 --> 08:32.990] The lesson here is, if you tell a lie big enough and keep repeating it, people will eventually come to believe it. [08:34.290 --> 08:38.070] Okay, now you've had some history and some examples. [08:38.610 --> 08:44.610] Let's walk through a PsyOps campaign together to see how one is actually built and executed. [08:45.430 --> 08:49.150] There are six basic steps to any PsyOps campaign. [08:51.430 --> 09:00.930] Plan, target audience, series development, product design, dissemination, and, of course, at the end, evaluation of the operation. [09:01.430 --> 09:06.390] For our example, I will be combining some of these steps together just for the sake of time. [09:08.130 --> 09:10.010] First step is planning. [09:10.430 --> 09:15.230] In this phase, you determine your goal and who your target audience is. [09:16.410 --> 09:23.010] For our example, the objective will be convincing Bob that unicorns are real. [09:23.450 --> 09:27.010] So let's call this Operation Twilight. [09:28.030 --> 09:34.690] For any operation, it helps to give your target audience an individual identity. [09:34.690 --> 09:39.910] This makes series development and product design, the next steps, much easier. [09:40.230 --> 09:42.830] That's why we have created Bob. [09:45.530 --> 09:47.890] Next, we refine our target audience. [09:48.310 --> 09:52.010] We chose Bob, but who exactly is Bob? [09:52.170 --> 09:53.230] And why did we pick him? [09:53.830 --> 09:58.190] We picked Bob because he does many Facebook personality surveys. [09:58.190 --> 10:02.590] And from those, we determined that he is a persuadable. [10:02.990 --> 10:06.350] He's also very active online with his friends. [10:06.530 --> 10:11.270] And as you'll see later, this will be a force multiplier for our operation. [10:12.190 --> 10:20.610] Now that we have our objective and our target audience, let's move on to series development and product design. [10:21.370 --> 10:27.450] Again, I put these two together because they pretty much happen hand in hand in an actual operation. [10:28.230 --> 10:35.770] And though it seems logical, we can't just make an ad that says unicorns are real and be done. [10:36.330 --> 10:40.050] Much like you would Bob will just laugh and scroll past this. [10:40.210 --> 10:44.250] It looks ridiculous and it has nothing to do with his interests. [10:45.390 --> 10:55.370] This is why we need to pull Bob through a series of targeted psyops to convince him that unicorns are in fact real. [10:57.270 --> 11:05.790] First, we'll send out some articles from our fake AI-generated online newspaper that is made to look like a legitimate popular site. [11:07.050 --> 11:18.030] The article talks about how scientists have managed to splice the DNA of a narwhal with the DNA of a horse, allowing horses to start growing horns. [11:20.010 --> 11:33.290] This article will also have links to our AI-generated journal with more articles on how the DNA splicing works, complete with a case study of the unicorn gene splicing. [11:33.290 --> 11:38.050] We can also add legitimate-sounding scientists' names and quotes. [11:38.650 --> 11:42.210] I'll let you read the first sentence of that and read over the names. [11:42.950 --> 11:44.610] Seems pretty smart, huh? [11:52.200 --> 11:55.980] Soon after these, similar articles will be posted. [11:56.440 --> 12:07.160] One being on how scientists have managed to manipulate the horn DNA to determine its length, giving our unicorns a more realistic-looking horn. [12:07.560 --> 12:09.080] And you know what I just realized? [12:09.280 --> 12:16.320] For any of you who just walked in a minute ago, just hearing me talk about unicorn DNA must be really weird and out of place. [12:16.480 --> 12:17.880] But you'll catch on soon enough. [12:19.880 --> 12:25.380] We will also use AI to generate realistic photos of unicorns. [12:25.480 --> 12:37.220] And since Bob is a bit of a conspiracy nut, like the best of us, we will make them look as if the pictures come from surveillance camera footage and hidden camera shots. [12:37.760 --> 12:42.000] Bob will love this and share these photos with his friends. [12:42.000 --> 12:46.400] His friends will be like, that's obviously fake. [12:46.640 --> 12:53.580] But that's when he's going to pull out all of our articles as well as our scientific journals and be like, look at this. [12:53.660 --> 12:57.620] And all his friends will be like, huh, Bob, I guess unicorns are real. [12:57.780 --> 12:59.920] Turning them into unicorn converts too. [13:00.180 --> 13:05.320] And eventually they will also send the articles to their friends, hence force multiplier. [13:08.310 --> 13:11.030] Step number five, dissemination. [13:12.230 --> 13:17.290] Dissemination has been happening through Facebook ads that look like legitimate news articles. [13:17.670 --> 13:24.550] We can also create a scientific podcast interviewing the scientists that made the unicorn. [13:24.990 --> 13:32.410] This podcast will be supported by numerous fake Twitter and Instagram accounts we are using to spread the photos of this unicorn. [13:35.120 --> 13:39.140] Finally, step six, we evaluate our operation. [13:39.480 --> 13:42.240] Turns out, no surprise, it worked. [13:42.240 --> 13:47.920] Not only did we convince Bob that unicorns are real, we convinced his friends too. [13:48.220 --> 13:53.960] As a bonus, Bob even started a blog about unicorns, further spreading our message. [13:55.820 --> 14:00.520] This operation has obviously taken on a life of its own. [14:00.720 --> 14:06.540] And if we wanted to, we could create some more surveillance footage of an alicorn in our lab. [14:06.540 --> 14:12.480] And for those of you who are not unicorn experts like me, an alicorn is a unicorn with wings. [14:12.880 --> 14:15.660] A horse with just wings is a pegasus. [14:15.880 --> 14:16.960] Just so you know. [14:18.540 --> 14:29.100] If we wanted to keep this whole charade going, we would revisit all the steps we just talked about to expand our operation and include more and more people. [14:29.100 --> 14:32.660] But I think we've done enough damage for one day. [14:32.880 --> 14:34.900] And Bob will take it from here. [14:35.380 --> 14:43.400] If you notice, we were able to do this with all just free tools and maybe a month worth of work just by ourselves. [14:44.040 --> 14:50.940] Imagine what adversary groups or a bad actor is able to do with more time, resources, money and experience. [14:50.940 --> 14:52.520] Pretty crazy, huh? [14:56.930 --> 14:58.330] Y'all excited already? [14:59.790 --> 15:02.990] Let's look at some real-world psyops now. [15:03.670 --> 15:10.230] Also, through this talk, try to identify some of the operation steps that we just went over as well. [15:11.410 --> 15:22.310] As I'm sure you know, Twitter, X, whatever we're calling it nowadays, is being used by adversary groups to sow disinformation into the American populace. [15:22.310 --> 15:26.690] Many using the same techniques that have been used on Facebook. [15:27.630 --> 15:33.170] One big problem with Twitter X is the very low bar for entry. [15:33.530 --> 15:38.350] This allows groups to use tools that create many bot accounts very quickly. [15:38.690 --> 15:43.450] If you use social media, I'm sure you've seen tons of bots before anyways. [15:44.570 --> 15:49.010] These accounts then go and tweet the same exact things. [15:49.010 --> 15:56.290] And once a bot gets caught and blocked, they simply create a new batch of bot accounts. [15:56.530 --> 15:57.670] That's kind of a tongue twister. [15:59.770 --> 16:08.050] These bot accounts also frequently feature beautiful young women because the target audience is primarily male voters. [16:08.050 --> 16:10.190] Take this, for example. [16:10.570 --> 16:15.770] This photo was stolen off of a Colombian Instagram influencer's account. [16:16.630 --> 16:18.030] Not that great, huh? [16:19.230 --> 16:26.450] The Twitter bots also retweet other bot tweets, as is shown in this beautiful graphic by Daniel Gallagher. [16:28.230 --> 16:34.650] Now let's switch gears and look at some deep fakes and how they are used in a PsyOps campaign. [16:35.870 --> 16:37.950] Who here has heard of Cameo before? [16:38.890 --> 16:39.790] Okay, quite a few of you. [16:39.950 --> 16:42.430] Who has ever ordered a video off of Cameo? [16:42.530 --> 16:42.890] I'm just curious. [16:43.530 --> 16:44.990] Okay, okay, a few of you. [16:45.110 --> 16:45.290] Cool. [16:45.290 --> 16:57.550] So for those of you who don't really know what Cameo is, Cameo is an app where you can pay for personal private messages from a lot of different celebrities, including... [16:58.690 --> 16:59.890] Tom Felton. [17:00.570 --> 17:06.990] So the Harry Potter lover in your life can pay Draco Malfoy to say happy birthday to them. [17:06.990 --> 17:13.870] And side note, I find it funny how 0.3% of people didn't like him. [17:14.070 --> 17:23.170] And that's probably the fans who don't realize time has passed since the movies were filmed, and Draco looks like he had one too many butterbeers. [17:23.630 --> 17:25.850] Just a side note. [17:26.670 --> 17:34.290] All jokes aside though, bad actors have found ways to use Cameo for their malicious intents. [17:34.290 --> 17:42.090] For example, a bad actor targeted a video to Maya Sandu, who is the president of Moldova. [17:42.330 --> 17:47.250] And with her being pro-Ukrainian, she's subject to these pro-Russian attacks. [17:49.750 --> 17:57.570] This bad actor hired a few celebrities to make happy birthday videos for his friend Sandu. [17:57.790 --> 18:00.950] And of course, the celebrities didn't know any better. [18:00.950 --> 18:07.850] After the videos were recorded, he used AI to alter what they said and how they said it. [18:08.210 --> 18:13.310] The celebrities now said, let's get rid of Sandu in Russian. [18:13.870 --> 18:21.650] The top caption of the video being, We Hollywood stars support the people of Moldova in their desire to overthrow you, Sandu. [18:21.990 --> 18:22.950] Pretty scary. [18:22.950 --> 18:25.830] I'm gonna show you a video next. [18:26.150 --> 18:29.690] The first video is the original cameos that were ordered. [18:29.970 --> 18:40.570] The second part of the video after the cut is the edited versions that Maya Sandu saw, as well as all the people of Moldova and a ton of people over the Internet. [18:41.070 --> 18:44.830] Just look how crazy realistic the second part looks. [18:44.830 --> 18:54.150] The bad actor even took the time to make it look as if these celebrities couldn't really speak Russian well, making it even more realistic. [18:58.050 --> 19:00.650] And a message for Sandu. [19:00.890 --> 19:02.590] Hi Sandu, it's Lindsay Lohan. [19:02.810 --> 19:04.210] Hello Sandu! [19:05.090 --> 19:05.730] Sandu! [19:06.050 --> 19:06.390] Hi! [19:07.190 --> 19:09.430] Robert's coming to you from the Paramount Studios. [19:09.790 --> 19:10.370] Sandu! [19:10.590 --> 19:11.710] Eric Robert's here. [19:11.810 --> 19:12.290] Sandu! [19:12.670 --> 19:13.210] Aloha! [19:14.030 --> 19:14.970] Marta Kaskos here. [19:15.510 --> 19:16.670] Hello Sandu! [19:17.690 --> 19:19.150] This is Michael Manson. [19:19.450 --> 19:21.190] Yo, that was Mr. X to the Z exhibit. [19:21.410 --> 19:22.110] This is for Sandu. [19:22.290 --> 19:22.650] Sandu! [19:22.650 --> 19:30.610] And say hello to you and your office from, well from, from Hollywood or from Colorado. [19:30.610 --> 19:33.410] I'm, I'm in Colorado right now. [19:35.710 --> 19:37.430] Now the Russian version. [19:39.490 --> 19:40.530] Ladies and gentlemen. [19:40.870 --> 19:41.490] Oh, that's right. [19:41.490 --> 19:44.310] Dava et skei nem sandu! [19:44.690 --> 19:47.630] Dava et skei nem sandu! [19:48.290 --> 19:51.690] Dava et skei nem sandu! [19:54.410 --> 19:56.770] Dava et skei nem sandu! [19:57.110 --> 20:01.330] Dava et skei nem sandu! [20:01.430 --> 20:04.250] Dava et skei nem sandu! [20:04.330 --> 20:07.730] Dava et skei nem sandu! [20:08.210 --> 20:11.510] Dava et skei nem sandu! [20:11.990 --> 20:15.430] Dava et skei nem sandu! [20:15.570 --> 20:17.970] Dava et skei nem sandu! [20:18.790 --> 20:19.670] Dava et skei nem sandu! [20:19.670 --> 20:21.670] Dava et skei nem sandu! [20:45.370 --> 20:46.610] Nice. [20:48.310 --> 20:50.590] I must break you. [20:53.840 --> 20:57.360] You have to admit, that was pretty darn scary. [20:57.680 --> 21:02.220] I mean, I was looking at most of you during this time and your mouths were open. [21:02.500 --> 21:04.860] Like, what even is going on here? [21:05.040 --> 21:06.180] Pretty scary, huh? [21:08.540 --> 21:19.520] Surprisingly, AI isn't a new threat, but it can help make existing threats easier to produce and more effective. [21:19.520 --> 21:35.200] As Director of the Elections in Government Program at Brenham Center for Justice at New York University School of Law said, we don't really think of AI as a freestanding threat, but more as a threat amplifier. [21:36.580 --> 21:52.580] FISA itself also addressed this concern in the Risk and Focus report in Generative AI and the Election Cycle, stating, AI will likely not introduce new risks, but they may amplify existing risks to election infrastructure. [21:54.460 --> 22:01.440] Not too long ago, adult content of Taylor Swift took Twitter and the Internet by storm. [22:02.560 --> 22:07.120] Deepfakes of celebrities have been around for a while now, and this is nothing new. [22:07.120 --> 22:17.220] But it took these AI images of Taylor Swift for the government to finally take some action when it comes to AI images and such. [22:17.760 --> 22:21.060] The White House urged Congress to act. [22:21.380 --> 22:31.800] And Representative Joe Morrell renewed efforts to make non-consensual sharing of explicit images of federal crime, with jail time and fines. [22:33.860 --> 22:34.660] Okay. [22:35.340 --> 22:43.500] Especially since most of you work in cybersecurity, I'm sure it's easy for you to believe that you can spot AI content. [22:43.900 --> 22:51.900] But a few studies, including this one that I'm going to talk about, show that might not be the case. [22:51.900 --> 22:59.560] In fact, most people believe AI faces look more real than real faces do. [23:00.180 --> 23:06.520] This study is part of Psychological Science, Volume 34, Issue 12, published in 2023. [23:07.060 --> 23:08.900] So this is very new research. [23:09.220 --> 23:19.920] And out of the 610 people that took this test, more people thought the AI photos were real than actual photos. [23:20.700 --> 23:21.260] Okay. [23:21.720 --> 23:24.780] Think you are smarter than all those participants? [23:25.180 --> 23:26.720] Let's test you out. [23:28.240 --> 23:29.880] I'm going to show you a photo. [23:30.060 --> 23:33.820] And if you think it is an AI image, I want you to raise your hand. [23:34.000 --> 23:36.560] If you think it's real, keep your hand down. [23:36.960 --> 23:38.920] Is this real or AI? [23:40.380 --> 23:43.720] Come on, be brave and don't let other people influence you. [23:44.320 --> 23:45.620] Really think about it yourself. [23:46.340 --> 23:49.120] This image is AI. [23:49.120 --> 23:49.420] AI. [23:49.680 --> 23:50.400] Okay. [23:51.240 --> 23:52.140] Next one. [23:52.420 --> 23:55.380] Is this a real person or is this an AI image? [23:57.460 --> 23:58.180] Okay. [23:58.660 --> 23:59.520] We have some hands. [24:01.260 --> 24:01.980] AI. [24:03.480 --> 24:04.840] How about this one? [24:05.080 --> 24:07.640] Is this guy real or AI? [24:11.460 --> 24:12.800] He is real. [24:13.180 --> 24:13.800] Okay. [24:14.400 --> 24:15.440] You're doing pretty good. [24:15.440 --> 24:15.540] Good. [24:16.360 --> 24:17.300] How about this guy? [24:17.480 --> 24:17.780] How about this guy? [24:17.780 --> 24:18.960] Is he real or AI? [24:21.990 --> 24:22.950] He's real. [24:25.250 --> 24:25.890] Okay. [24:26.430 --> 24:27.910] How about this guy? [24:28.230 --> 24:29.150] Real or AI? [24:30.670 --> 24:32.070] He is AI. [24:33.130 --> 24:34.350] How about this one? [24:36.150 --> 24:36.790] Real. [24:38.450 --> 24:40.030] Those are a bunch of guys. [24:40.450 --> 24:41.790] Let's try some woman. [24:47.050 --> 24:48.010] He's real. [24:48.630 --> 24:49.270] He's real. [24:49.630 --> 24:50.270] He's real. [24:50.770 --> 24:51.650] How about this woman? [24:51.810 --> 24:52.830] Pretty easy, huh? [24:54.790 --> 24:55.730] He's real. [24:56.570 --> 24:56.670] He's real. [24:56.710 --> 24:58.470] This is the hardest one yet. [24:58.870 --> 25:00.130] Real or AI? [25:03.460 --> 25:04.400] Obviously AI. [25:06.720 --> 25:07.260] Okay. [25:07.840 --> 25:12.660] I'm just curious to know, how many of you got all of them correct? [25:14.600 --> 25:15.140] Anyone? [25:16.480 --> 25:17.020] Yeah. [25:17.240 --> 25:19.700] You felt pretty confident at the start of this, didn't you? [25:20.760 --> 25:22.860] Did anyone get all of them wrong? [25:23.980 --> 25:25.880] Yeah, quite a few of you. [25:29.850 --> 25:37.290] This chart here shows what people look for the most when identifying if an image could be AI or not. [25:37.770 --> 25:46.830] The main categories shown here, of course, being image quality, specific facial features, skin and wrinkles, symmetry, and lighting. [25:47.030 --> 25:48.690] Did you guys look for those things too? [25:49.290 --> 25:49.930] Probably. [25:50.690 --> 25:54.770] If this test stumped you even a bit, you're obviously not alone. [25:54.770 --> 26:06.710] But I want you to imagine how much harder it would be for an older person or an unaware person who's not even looking out for AI to spot if an image could be fake or not. [26:10.210 --> 26:11.370] Switching gears a bit. [26:11.850 --> 26:17.090] We all know that spreading disinformation is ethically wrong. [26:17.410 --> 26:20.570] But how unlawful is it? [26:21.430 --> 26:27.290] Let's take a look at the U.S. legal code covering the imparting or conveying of false information. [26:28.330 --> 26:32.090] This is a lot of words and I'll break it down, but I want you to read through it first. [26:50.340 --> 26:51.900] Yep, quite a lot of words. [26:52.080 --> 26:52.780] Let's break it down. [26:55.420 --> 27:00.480] At the end of the code, you can see that blah blah blah blah blah blah blah blah. [27:00.860 --> 27:21.740] It says, whoever willfully and maliciously or with reckless disregard for the safety of human life imparts or conveys false information, knowing the information to be false concerning an attempt to be made to do any act which would be a crime prohibited by this chapter of this title shall be fined [27:21.740 --> 27:24.780] under this title or imprisoned, not more than five years. [27:25.680 --> 27:35.260] You can tell that this code has a lot of leeway for bad actors to play the, but sir, I didn't know any better card. [27:35.760 --> 27:47.480] Since it states with reckless disregard for the safety of human life, a person on trial can state that the disinformation they're spreading is not physically harming anyone. [27:48.660 --> 27:54.520] The other key parts here that I underlined are willfully and knowing the information to be false. [27:56.100 --> 28:02.860] This way, someone spreading disinformation could just say, I didn't know the information I was spreading was false. [28:03.060 --> 28:03.960] I thought it was true. [28:04.440 --> 28:05.400] Freedom of speech. [28:19.520 --> 28:26.400] Freedom of speech. [28:26.400 --> 28:40.580] The family of a man who died in a Tesla car crash filed a lawsuit against the company, referencing a video of Elon Musk saying the cars can drive autonomously with greater safety than a person. [28:41.220 --> 28:56.100] The Tesla lawyers then stated, Like many public figures, Elon is subject to many of these deep fake videos and audio recordings that purport to show him saying and doing things he never actually said or did. [28:56.860 --> 28:58.500] Quite a claim to be made. [28:58.800 --> 29:17.620] But thankfully, the court did not buy this argument, stating their position is that because Mr. Musk is famous and might be more of a target for deep fakes, that his public statements are immune, which obviously should not be the case. [29:18.000 --> 29:25.420] In other words, Mr. Musk and others in his position can simply say whatever they like in public domain. [29:25.420 --> 29:31.460] Then hide behind the potential that what they said was a deep fake. [29:32.900 --> 29:42.720] As another example, two people on trial after the January 6th riot also tried claiming the videos of them were created by AI. [29:43.160 --> 29:45.760] Thankfully, the court did not buy that either. [29:46.480 --> 29:50.380] And if you're going to do something like that, you might as well own up to it. [29:51.900 --> 30:03.480] With more people claiming evidence to be deep faked, courts may now need to require more and more proof that the evidence shown to them is actually real. [30:04.240 --> 30:15.880] This is an example of what is known as the CSI effect, where the potential of evidence tampering leads jurors to want more and more evidence. [30:15.880 --> 30:18.160] This sounds like a good thing, right? [30:18.460 --> 30:20.380] More evidence, more likely to be true. [30:20.600 --> 30:33.240] But if you think about it, not everyone has the money, time or ability to hire experts who can gather more evidence or prove that the existing examples given are real. [30:33.240 --> 30:43.240] This will also slow our judicial process even more, meaning cases will require more time and more resources as well. [30:45.080 --> 30:54.220] With the mass production of malicious AI, lawmakers are now scrambling to make decisions regarding AI regulation. [30:54.220 --> 31:02.900] The European Union was the first to take action as they put into place their AI act. [31:03.320 --> 31:09.780] This act puts regulations on the use of AI tools and on the tools themselves. [31:10.500 --> 31:11.200] Pretty good, huh? [31:12.840 --> 31:22.700] The act's restrictions are very influential because these companies don't want to make and manage multiple models of the same product. [31:23.580 --> 31:36.680] Meaning that if I was a company making an AI tool that I was going to both market in Europe and the U.S., I would want to abide by these European standards so I wouldn't have to make two models. [31:36.680 --> 31:40.680] One for my U.S. demographic and one for my European demographic. [31:40.980 --> 31:48.660] Meaning the U.S. and other nations get the same benefits of the security standards provided by the European Union. [31:50.340 --> 31:54.540] However, there is also a big issue when it comes to lawmaking. [31:54.760 --> 31:57.640] And that, of course, is its speed. [31:57.640 --> 32:06.840] Especially in the U.S., where laws literally take months of altering and voting in order to be approved. [32:07.060 --> 32:09.600] Let alone be put into act. [32:10.320 --> 32:18.320] Worst part is, when something is eventually passed, the technology has changed, grown and adapted. [32:18.720 --> 32:21.580] Requiring even more new laws to be passed. [32:21.760 --> 32:22.900] And so on and so forth. [32:22.900 --> 32:30.600] This is why only 12 states in the U.S. have any form of AI information regulation. [32:31.100 --> 32:32.300] 12 out of 50. [32:32.520 --> 32:34.080] I don't like that ratio. [32:37.950 --> 32:43.710] This year, at the Munich Security Conference, they held a tech discussion. [32:43.710 --> 32:57.010] Where many representatives and heads from major companies came together to create an accord on combating deceptive use of AI in the upcoming 2024 election. [32:57.410 --> 32:58.750] Sounds pretty great, right? [32:59.430 --> 33:01.110] What was their main goal? [33:01.930 --> 33:02.810] Awareness. [33:03.030 --> 33:10.890] They wanted to develop AI detection and create better AI education and informational resources. [33:10.890 --> 33:18.710] I want you to keep in mind that this accord only covers deceptive election content. [33:19.110 --> 33:21.830] Not all deceptive content in general. [33:23.230 --> 33:25.730] Who signed this tech accord? [33:26.490 --> 33:28.730] You can read over some of the names now. [33:29.930 --> 33:30.870] Amazon. [33:30.910 --> 33:31.250] Amazon. [33:31.950 --> 33:32.390] Google. [33:33.130 --> 33:33.850] IBM. [33:34.370 --> 33:34.530] LinkedIn. [33:35.890 --> 33:36.950] Open AI. [33:37.930 --> 33:38.650] TikTok. [33:39.310 --> 33:39.870] TruePic. [33:40.250 --> 33:40.530] X. [33:42.310 --> 33:44.050] Quite a few companies. [33:44.870 --> 33:48.410] This accord covers all AI content. [33:48.750 --> 33:52.330] That means written, video, audio, photo, and more. [33:52.330 --> 33:58.990] Let's read over some of the promises these signers you just saw committed to. [34:00.490 --> 34:08.150] There's developing and implementing technology to mitigate risks related to deceptive AI election content. [34:08.330 --> 34:08.770] That's good. [34:12.090 --> 34:16.270] Seeking to detect the distribution of this content on their platforms. [34:16.270 --> 34:17.630] Good luck with that. [34:20.210 --> 34:24.550] Fostering cross-industry resilience to deceptive AI election content. [34:25.090 --> 34:27.810] How are they going to do that across millions of accounts? [34:28.730 --> 34:30.650] Ooh, the last one is good. [34:31.150 --> 34:37.110] Supporting efforts to foster public awareness, media literacy, and all of society resilience. [34:38.210 --> 34:39.050] Okay. [34:39.430 --> 34:47.010] As you can see, the commitments are very broad, and broad rules lead to broad commitment. [34:47.550 --> 34:56.570] I want you to notice how these companies promise to mark harmful content, but not outright ban it. [34:57.010 --> 35:03.090] As you saw, most of the companies who signed are mainly AI and social media companies. [35:04.950 --> 35:07.610] Misinformation is their moneymaker. [35:07.990 --> 35:09.910] Why would they want to go against that? [35:11.150 --> 35:17.590] Labeling their content as bad is like cigarette companies labeling their products as hazardous. [35:18.130 --> 35:22.350] They know their content is harmful, but they won't stop you from consuming it. [35:24.820 --> 35:28.280] Let's look back quickly at who signed the accord. [35:28.280 --> 35:34.560] One of these companies that I just so conveniently underlined is Eleven Labs. [35:34.980 --> 35:37.960] Out of curiosity, who has heard of Eleven Labs? [35:38.760 --> 35:40.300] Okay, a few of you. [35:40.460 --> 35:42.960] Not as many as other things, but that's fine. [35:43.780 --> 35:48.260] Eleven Labs is a voice AI research and deployment company. [35:48.260 --> 36:07.580] On their website, it states, Eleven Labs creates the most realistic, versatile, and contextually aware AI audio, providing the ability to generate speech in hundreds of new and existing voices in 29 languages. [36:07.960 --> 36:08.580] Pretty impressive. [36:09.040 --> 36:15.400] As a technology research company, Eleven Labs is at the forefront of developing new cutting edge voice AI. [36:17.540 --> 36:27.560] One bad actor was able to use this tool to their advantage during the recent primary election in New Hampshire. [36:27.980 --> 36:34.540] Voters got a call from Joe Biden, urging them not to vote. [36:35.580 --> 36:42.060] Eventually, word of this awfully suspicious call came to the Attorney General's office. [36:42.060 --> 36:50.060] And of course, they sent it off to Bloomberg News for testing, to test and see if this call is AI or not. [36:50.900 --> 36:56.640] Their tests show the call only had a 2% likelihood of being AI. [36:57.140 --> 36:58.900] But that can't be right. [37:00.140 --> 37:04.400] What detection tool did Bloomberg use to test this call? [37:05.260 --> 37:09.040] Eleven Labs' own speech classifier tool. [37:11.000 --> 37:14.320] Obviously not satisfied with their results. [37:14.560 --> 37:17.900] The office then sent it to Pindrop Security, Inc. [37:18.380 --> 37:21.240] They are a voice fraud detection company. [37:21.960 --> 37:33.960] They were able to figure out that the audio clip was created with Eleven Labs and traced it back to one specific user, who thankfully is now in jail. [37:33.960 --> 37:44.560] To figure this out, they removed the background audio from the clip you're also going to hear and cut the recording into 155 segments. [37:45.020 --> 37:46.540] Why did they do this? [37:46.860 --> 38:02.680] They did that because they wanted to take these 250 millisecond long clips and do a deep analysis of each one, comparing it to files of Joe Biden's real voice and other fake versions of his voice to test. [38:04.120 --> 38:07.680] But why didn't the Eleven Labs tool work? [38:07.840 --> 38:14.240] Especially since this voice clip that they tested was made with Eleven Labs in the first place. [38:14.800 --> 38:21.200] This is because their tool only works if you analyze the raw file of an audio. [38:21.640 --> 38:25.600] But I doubt bad actors will give us their raw files to test. [38:28.780 --> 38:43.120] Only when Eleven Labs was called out for letting one of their users create this content that made it past their own detection software, did they suspend this bad actor from their site. [38:43.920 --> 38:46.200] Not expel, suspend. [38:46.200 --> 38:46.980] Yeah. [38:47.740 --> 39:08.640] This is because on their website, they say they will allow voice clones of big public speakers, including politicians, yes, including politicians, if it is used to express humor or mockery in a way that is clear to the listener that what they are hearing is a parody. [39:08.640 --> 39:16.640] But like we learned earlier, not everyone can tell if it's AI or not, or is even looking out for it. [39:16.640 --> 39:35.440] I also want you to keep in mind that Eleven Labs, the same people who couldn't detect it, and the same people who let an adversary use their tool to create a false audio of Joe Biden, also signed the tech accord from earlier on election security. [39:35.980 --> 39:36.340] Yay! [39:37.660 --> 39:41.580] How about we listen to this voice message together? [39:42.780 --> 39:44.420] What a bunch of malarkey. [39:44.860 --> 39:48.260] We know the value of voting Democratic when our votes count. [39:48.400 --> 39:51.340] It's important that you save your vote for the November election. [39:51.900 --> 39:55.320] We'll need your help in electing Democrats up and down the ticket. [39:55.940 --> 40:02.320] Voting this Tuesday only enables the Republicans in their quest to elect Donald Trump again. [40:02.800 --> 40:06.040] Your vote makes a difference in November, not this Tuesday. [40:06.380 --> 40:10.440] If you would like to be removed from future calls, please press 2 now. [40:11.740 --> 40:13.500] Sounds pretty darn real. [40:13.780 --> 40:24.660] If you're not looking out for it, if you don't even know deepfakes like this are possible or AI is possible, then how would you ever be able to tell that it's fake? [40:26.680 --> 40:41.840] Okay, with influential attacks like this and others we have talked about constantly happening, it can be so hard to escape this doom mentality we have all been holding onto for quite a while now. [40:41.840 --> 40:55.800] The idea that the news you are consuming is more than likely to be biased or untrue has probably led you and many others to lose the desire to stay in the loop. [40:55.800 --> 41:02.060] I mean, if you open social media or the news right now, you're probably going to feel some dread and not uplifted at all. [41:02.380 --> 41:04.980] I'm sure most of you have even lost some hope. [41:05.660 --> 41:18.620] And though it can be hard and tedious to verify sources, it is now more essential than ever to verify and check information to see if it's false or not. [41:18.620 --> 41:22.680] And you might be saying, well, easier said than done, Bia. [41:22.840 --> 41:28.280] You just showed me a bunch of fake stuff and I was tricked by those AI images too. [41:29.080 --> 41:38.080] So let's look over some tips and tricks you can use and teach to others on spotting fake or loaded content. [41:39.820 --> 41:42.180] And this can be applied to political news. [41:42.260 --> 41:45.700] This can be applied to any kind of news or any kind of information. [41:46.720 --> 41:51.820] First off, when you read an article, look out for adjective dumping. [41:52.300 --> 41:55.200] This is a form of loaded language. [41:55.580 --> 42:04.820] The more adjective an author is using, the more likely they are trying to convince you of something rather than just state facts. [42:05.180 --> 42:06.600] Let's look at an example. [42:07.240 --> 42:11.920] First off, this is an unbiased piece of news. [42:13.600 --> 42:17.040] That's obviously fake for the sake of this talk, but still. [42:17.460 --> 42:21.540] This 2024 election, Taylor Swift will be running for president. [42:21.880 --> 42:27.520] Her plan to win this election is by giving out free tickets to her fans. [42:28.700 --> 42:29.940] Pretty unbiased. [42:30.960 --> 42:35.760] Let's look at a bias piece that is made to make Taylor Swift look bad. [42:35.760 --> 42:41.460] This 2024 election, the infamous Taylor Swift will be running for president. [42:41.920 --> 42:48.660] Her sly plan to win this election is by only giving out free tickets to her fans. [42:49.060 --> 42:50.760] Makes her sound pretty bad. [42:51.340 --> 42:56.580] Keep in mind, news can also be biased to make a politician look good. [42:56.580 --> 43:02.180] This 2024 election, the beloved Taylor Swift will be running for president. [43:02.540 --> 43:08.380] Her generous plan to win the election is by kindly giving out free tickets to her fans. [43:08.740 --> 43:10.880] Paints a very different picture, doesn't it? [43:12.980 --> 43:15.320] Some quick other checks you can do. [43:15.320 --> 43:19.120] It's always good to do a background check on the author. [43:19.920 --> 43:22.580] Do they work in the field they are discussing? [43:23.000 --> 43:24.560] What else have they written on? [43:24.900 --> 43:29.340] If you can't find any information on them, probably not a good sign. [43:30.220 --> 43:36.740] One thing my English professor has always told us is that the more effective... [43:36.740 --> 43:41.960] the more evidence an author brings, the more effective their piece is. [43:42.200 --> 43:46.880] And the more they back up their claims, the more effective it is as well. [43:47.360 --> 43:50.800] With this in mind, see if they list sources. [43:51.240 --> 44:00.360] And also check those original sources, because not only can those be false, but things can be taken out of context as well. [44:01.460 --> 44:09.980] If the article is on a website, it's always good to also check what other types of content this website is pushing. [44:10.480 --> 44:13.900] Like, do they only talk about one political party? [44:14.380 --> 44:17.940] Do they talk about that political party in a bad way or in a good way? [44:18.180 --> 44:19.520] How biased do they seem? [44:20.540 --> 44:26.420] Then, of course, you should always check if other news sources are talking about the same topic as well. [44:26.680 --> 44:36.160] Because if a ton of different news sources who cover both parties or one certain party is talking about the same topic, then it's more likely to actually be happening. [44:38.740 --> 44:46.160] Our parents were lying to us when they said, sticks and stones may break my bones, but words can never hurt me. [44:47.260 --> 44:51.820] Information, whether true or not, holds a lot of power. [44:51.940 --> 44:53.920] It has a ton of impact. [44:54.600 --> 45:01.620] This is why it is essential to not only watch out for yourself, but share what you learned here today with others. [45:02.520 --> 45:08.860] The Internet, like the world, is a very scary place, as I'm sure we all know. [45:09.760 --> 45:18.620] But if we work together, we can use it for its original intention, which is to collaborate, share, and learn together. [45:18.960 --> 45:21.620] With that, happy election season, everyone. [45:21.760 --> 45:21.780] Bye.