Back to BlogTemp Mail Lab Journal

How to Spot Deepfakes and Cloned Voices

TempMailLab TeamJuly 29, 20268 min read
Deepfake concept showing a portrait, voice waveform, provenance record, and verification tools.

How deepfakes and cloned voices are created, what detectors and watermarks can prove, and why reliable verification needs several independent checks.

Deepfakes and Voice Cloning: What Detection Can and Cannot Tell You

A suspicious video does not have to contain an obvious mistake. The face may look right, the voice may sound familiar, and nothing about the timing may seem unusual. That is part of what makes synthetic media difficult to judge from appearance alone.

Audio creates a similar problem. A message can sound like a manager, relative, colleague, or public figure even though that person never recorded it. At the same time, completely genuine media can look suspicious after ordinary processing. A photo may lose metadata when it is resized or reposted. Compression can change the way small details look. A recording that has been forwarded several times may no longer resemble the original file exactly.

A single visual oddity is weak evidence. So is a single detector score.

Checking suspicious media usually means looking at several things separately: where the file came from, whether anything is known about its history, what automated analysis finds, and whether the identity or claim can be confirmed somewhere else.

No one check answers all of those questions.

What does "deepfake" actually mean?

The word deepfake is used pretty loosely.

In general, it describes media that has been generated or altered so that somebody appears to say or do something different from what actually happened.

There are several ways that can happen. A face swap can place one person's face over another person's performance. A lip-sync system can change mouth movements to match different speech. Voice-cloning software can produce audio that resembles a speaker after learning patterns from recordings.

Some synthetic media is generated almost entirely by a model. Other files begin with genuine photography, video, or audio and change only one part.

NIST terminology separates the question of whether media is synthetic or partially synthetic from the question of whether it is deceptive or a forgery.

That difference is easy to miss.

An edited image can be perfectly legitimate. Movies, advertising, accessibility tools, and ordinary creative work all involve editing. Meanwhile, an authentic photograph can be attached to the wrong date, location, or event and become misleading without a single pixel being altered.

For the same reason, unusual artifacts need context. A strange shadow, soft edge, missing metadata field, or unusual facial expression may be worth investigating. None of those things establishes that a file is fake.

Voice cloning weakens voice recognition as an identity check

A familiar voice has traditionally felt like strong evidence that you know who is speaking.

That assumption is less useful once a system can reproduce recognizable features of somebody's speech.

Voice-cloning systems can model pronunciation, timing, pitch, vocal texture, and other characteristics found in recordings. Depending on the source material and the system involved, the result may also contain pauses or other details listeners associate with a particular speaker.

The problem becomes more serious when the voice is being used to authorize something.

Suppose a call sounds like somebody you know and the speaker asks for an urgent payment. The voice may be convincing. That still does not establish who made the request.

For anything important, verify it somewhere else.

End the conversation and contact the person through a number or account you already know. Organizations can add their own controls: another employee may approve large transactions, certain requests may require written confirmation, and limits can be placed on actions that would be difficult to reverse.

A familiar voice can be one piece of evidence. It should not be the whole approval process.

The FTC has treated prevention and authentication as separate parts of the response to voice-cloning risks. It has also noted that no single intervention deals with the entire problem.

Different safeguards operate at different points. Platforms may restrict abuse. Watermarks may identify some generated content. Reporting systems help after something has happened. Authentication procedures make impersonation less useful in the first place.

Visible watermarks help identify a claimed source

A visible watermark may be a company name, publisher logo, creator mark, or label placed directly on an image or video.

It can be useful. Someone viewing the file can immediately see who appears to be claiming it, and the mark may discourage basic copying.

But the mark itself is not proof that the media is authentic.

It can be cropped out. It can be copied onto an altered image. Someone can place a familiar logo on a file that the organization behind that logo never created.

A watermark is information about attribution. Whether that attribution is genuine still has to be checked.

Invisible watermarks work differently

Visible and invisible image watermarks connected to a provenance record.

Invisible watermarks are designed for software rather than for the viewer.

A signal is embedded into pixels, audio samples, or another part of the media so that compatible software can attempt to detect it later. Depending on the system, that signal may identify a generator, a specific item of content, or a related record.

The signal does not necessarily survive every transformation.

Images get resized and compressed. People take screenshots. Audio is re-recorded. Video passes through platforms that encode it again. Editing can also change the information a watermark depends on.

That means the absence of a detectable watermark has a limited meaning.

It tells you that the detector did not find a supported watermark in the file it examined. It does not prove that a human created the media.

Content Credentials record provenance

Content Credentials approach the problem from the direction of provenance.

The C2PA standard allows signed information about digital media to be associated with an asset. A manifest can contain details about origin, edits, ingredients, or the involvement of an AI-enabled tool.

Cryptographic bindings allow a validator to check whether a credential belongs to the asset and whether the signed information has changed.

Metadata does not always stay attached to a file, though. Soft bindings, including fingerprints or invisible watermarking techniques, can help connect a copy with related provenance information after ordinary metadata has been separated from it.

This history can be extremely useful, but it answers a fairly specific question.

It describes parts of the file's origin or editing history.

It does not determine whether the event shown in the file is true.

A trusted camera can record something that was deliberately staged. The resulting file may have completely valid provenance. Someone can also take genuine media with an accurate editing history and attach a false caption to it later.

Nothing about the provenance necessarily becomes invalid in either case. The misleading part exists somewhere else.

Credentials can also be missing for ordinary reasons. The tool that created the media may not support them. A platform may remove metadata. Another editing program may fail to preserve the existing record.

Missing provenance is not evidence of manipulation by itself.

There is a separate privacy issue too. Genuine images can expose location information, device details, or other clues their owner did not intend to share. Our guide to what a photo can reveal looks at that problem in more detail.

Authenticity and privacy overlap, but they are different questions.

How media detectors reach a result

Synthetic media review pipeline treating detection output as a signal followed by human review.

Automated detectors generally examine characteristics of the media and return a classification, probability, or other signal.

The details depend on what is being analyzed.

An image system might examine relationships between pixels, edges, lighting, skin texture, or compression patterns. Video analysis can include motion, facial landmarks, or changes between frames. Audio systems may consider timing, spectral patterns, background noise, or artifacts associated with synthesis and replay.

There is no single method used by every detector.

This also makes detection different from provenance validation.

A provenance validator checks whether a credential or manifest is associated with a file and whether that information remains valid.

A detector is looking at the media itself and comparing what it finds with patterns learned or defined by the system.

A result from one should not be treated as a result from the other.

Detector scores need context for the same reason.

A score is produced by a particular model, using a particular threshold, after receiving a particular version of the media. It does not identify the creator. It does not establish intent. It does not show that somebody appearing in a video is lying, and it cannot by itself determine whether the event shown actually happened.

NIST's work on synthetic content treats detection, provenance, labeling, and testing as related but separate approaches.

Detector performance can also change depending on the input. A system trained on output from one generation technique may behave differently with another. Cropping, recompression, or other changes to the file can affect the patterns available for analysis.

This does not make detection useless. It just puts the result in the right place: one piece of evidence rather than the final judgment.

Identity verification has a different job

Layered identity verification with liveness, document, face match, voice challenge, and human review.

Identity verification systems often combine several checks.

A service may try to confirm that a camera is seeing a live person. It may read an identity document, compare a selfie with the portrait on that document, or ask the person to perform a short challenge.

Some systems also use device, account, or session information. Cases close to a decision threshold may be reviewed by a person instead of being decided automatically.

Each step covers a different question.

Face matching is a good example. A high similarity score may indicate that two images contain faces with similar characteristics. It does not prove that the person owns the account being accessed. It does not establish that the document was presented willingly. It does not show that the person has permission to complete a transaction.

Manipulated media can also affect different checks in different ways.

A replayed video is not the same problem as a synthetic face. A morphed document image raises another set of concerns. NIST has discussed morph detection specifically because a blended image may interfere with face-recognition systems by resembling more than one person.

There is also a privacy tradeoff.

A selfie, voice sample, or identity document can contain sensitive information. People should be able to understand why the service needs it, how long it will be kept, and who can access it.

Automated systems can make mistakes as well. For important decisions, a verification process should provide some way to examine an uncertain result rather than turning a weak signal into a permanent decision with no meaningful review.

Checking suspicious media in practice

It often makes sense to begin with the source rather than with a detector.

Who uploaded the media? Is that the earliest copy you can find? Is there a longer recording? Has a reliable source described the same event?

A short clip can omit context without containing any synthetic content at all.

If you are authorized to keep the original file, preserve it. A screenshot, messaging-app copy, or social-media download may not contain all of the information that existed in the original. Platforms can change compression or remove metadata during upload.

Then look for provenance that is actually available.

Content Credentials or a known publisher record may help establish part of the file's history. Missing credentials do not prove anything on their own.

The surrounding claim should also be checked independently.

Look for another recording of the same event, reliable reporting, or confirmation from the person involved. In many cases that evidence is more useful than submitting the same compressed clip to several different detectors.

Requests involving money, login credentials, confidential files, or unusual secrecy deserve more caution. If a voice or video claims to be somebody you know, contact that person through another trusted channel before acting.

Automated detection can still be added to the process.

Keep track of which service produced the result and which copy of the file it analyzed. A score from the original media and a score from a compressed social-media copy are not necessarily equivalent.

For an important decision, the evidence should be explainable. A reviewer needs more than an unexplained percentage on a screen.

The detector itself is also worth checking.

Uploading a private identity document, confidential video, or intimate recording to an unknown website may expose information that did not otherwise need to leave your device.

A verification attempt should not create a second privacy problem.

There is no single test for "real"

Several separate questions can hide behind the simple question "Is this real?"

Was the file generated?

Was part of it edited?

Where did it come from?

Does it have a recorded history?

Does the person match the claimed identity?

Did the event itself actually happen?

Is the description attached to the media accurate?

Different evidence helps with different parts of that list.

A watermark may point toward a source or tool. Content Credentials can preserve provenance. A detector can analyze characteristics of the media. Identity verification can compare a person with documents or other evidence. Independent reporting or direct confirmation may establish what happened around the file.

Those methods are most useful when their roles stay separate.

Provenance can tell you about history. Detection provides a technical signal about the media. Identity verification evaluates a different set of evidence about a person or account.

None of them is a universal test of truth.

CybersecurityOnline PrivacyAI Privacy