Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 28, 2026

Deepfakes Explained: Types, Detection, and Defense

A practical guide to deepfake images, video, and audio: how they are made, how identity attacks use them, how layered detection works, and how to evaluate defenses.

By DiditUpdated
deepfakes-explained-types-detection-defense.png

A deepfake is synthetic or manipulated media created with machine-learning techniques to make a person appear to say, do, or present something that did not occur. Deepfakes can alter or generate images, video, and audio; in identity attacks, they can impersonate a real person, create a synthetic persona, modify identity evidence, or feed forged media into a remote verification flow.

Deepfake defense is not one detector. Reliable decisions combine media provenance, forensic analysis, trusted capture, presentation attack detection, identity linkage, device and network signals, transaction context, and an escalation process for uncertain cases.

Key takeaways

  • Deepfake is a media category, not one attack. Face swaps, reenactment, lip synchronization, voice cloning, fully generated people, and altered documents create different evidence and risks.
  • Presentation and injection attacks are different. A presentation attack shows an artefact to a real sensor; an injection attack inserts forged media after or instead of the sensor.
  • Human visual inspection is not a sufficient control. Compression and new generators erase familiar artefacts, while genuine media can also look unusual.
  • Detection scores are conditional. Results depend on the generator, attack, capture path, compression, population, threshold, and operating environment used in testing.
  • Verification is stronger than appearance alone. A high-risk request should be bound to an identity, device, authenticated channel, and independent approval process.

What is a deepfake?

The term combines “deep learning” and “fake.” It originally described face-swapped video, but common usage now includes realistic AI-generated or AI-manipulated images, video, and speech. The defining issue is not whether every pixel is generated. It is whether computational manipulation creates misleading evidence of identity, speech, behavior, or origin.

Deepfakes belong to the wider category of synthetic media. Synthetic media also has legitimate uses in film, accessibility, education, localization, privacy, and creative work. The security risk appears when media is used to make a false claim—especially a claim about who is present, who authorized an action, or where the media came from.

Deepfake, cheapfake, and synthetic identity

  • Deepfake: media generated or manipulated with machine-learning methods to imitate or fabricate a person, object, or event.
  • Cheapfake: misleading media produced with simpler editing, relabeling, speed changes, selective cropping, or reuse outside its original context.
  • Synthetic identity: an identity assembled from fabricated and real attributes. It may use deepfake media, but the identity record—not only the media—is the attack.
  • Face morph: one portrait blended from two or more people, often to make the result resemble multiple identities.
  • Replay: genuine or manipulated media played back to a capture system. The content may be real while the live-presence claim is false.

These categories can overlap. A fraudster may combine a stolen document, a morphed portrait, a real-time face swap, a residential proxy, and a compromised account in one attempt.

What types of deepfakes exist?

TypeWhat changesTypical identity riskUseful control layers
Face swapOne face is mapped onto another personImpersonation in onboarding, calls, or account recoveryTrusted capture, liveness, face comparison, injection checks
Facial reenactmentExpression, pose, or gaze is driven by another sourcePassing prompts or imitating live behaviorUnpredictable cues, temporal analysis, sensor integrity
Lip synchronizationMouth movement is altered to match new audioFabricated statements or call impersonationAudio-video consistency, provenance, independent confirmation
Voice cloneSpeech is synthesized in a target voicePayment or credential-reset social engineeringCallback, strong authentication, dual approval, audio analysis
Fully generated personImage or video depicts a person who does not existSynthetic accounts, fake profiles, mule recruitmentIdentity evidence, database checks, device and network analysis
Document manipulationPortrait, text, layout, or security features are alteredFalse identity evidenceDocument validation, live document capture, NFC or issuer checks
Face morphMultiple faces are blended into one portraitOne document may appear to match more than one personMorph detection, issuer-quality reference, human review

No row has a perfect single control. A face detector cannot establish document authenticity. Content provenance cannot prove the signer’s real-world identity. Liveness at the sensor does not automatically detect media injected downstream.

How are deepfakes created?

Modern deepfakes can be produced with several model families. The technical details differ, but the practical workflow usually includes source collection, representation learning, generation, compositing, and post-processing.

1. Source material is collected

The attacker gathers images, video, or voice recordings of the target. Public interviews, social profiles, video meetings, leaked documents, and prior verification captures can all become source material. For fully generated identities, the model creates a new subject rather than copying one person.

2. The model learns or preserves identity features

Face-swap systems encode facial structure and appearance, then render the target identity over a source performer. Reenactment systems transfer pose or expression. Voice systems learn speaker characteristics and generate speech from text or another voice.

3. Synthetic content is generated

Generative adversarial networks, autoencoders, diffusion models, and neural rendering systems can all contribute. The model family alone does not tell defenders which artefact will remain; different training data and post-processing produce different traces.

4. The result is composited and corrected

Blending, color correction, relighting, audio cleanup, frame interpolation, and lip synchronization make the output more coherent. A fraudster can deliberately add blur or compression to hide generator traces.

5. The media is delivered

Delivery determines the attack surface. A file may be uploaded, shown on a screen, printed, played during a video call, routed through a virtual camera, or injected between the capture component and the server.

That final step is why a purely forensic definition is not enough for identity systems. The same generated face creates a different threat when it is posted publicly, shown to a camera, or injected into a verification SDK.

How are deepfakes used in identity attacks?

Presentation attack

The attacker presents a photo, screen, printed mask, replay, or other artefact to the legitimate camera or biometric sensor. ISO/IEC 30107 calls the control at this capture boundary Presentation Attack Detection (PAD). Liveness detection is one subset of PAD.

Injection attack

The attacker bypasses or interferes with expected capture and feeds forged media into the processing path. Examples include virtual cameras, emulators, hooks, modified SDKs, manipulated network requests, or server-side file substitution.

NIST SP 800-63A-4 treats injection prevention and forged-media detection as distinct requirements. It notes that biometric comparison alone does not prevent injected media and recommends controls that increase confidence in the capture sensor and protected channel.

Impersonation and social engineering

A voice or video clone can make an urgent request appear to come from an executive, employee, customer, vendor, or family member. The objective may be a payment, credential reset, disclosure, or policy exception. Here the best defense may be process adherence—such as a known callback path or dual approval—rather than trying to judge pixels in real time.

The OWASP deepfake response guidance emphasizes durable security processes, financial controls, verification procedures, awareness, and incident response over a narrow focus on spotting visual defects.

Synthetic account creation

Generated portraits, fabricated attributes, altered evidence, disposable contact points, and obfuscated network connections can be combined to create accounts that do not correspond to one genuine person. The media is only one signal in a wider identity and behavior graph.

Account recovery and re-binding

If a recovery flow relies on a selfie or video call, synthetic media may be used to take over an existing account or bind a new authenticator. Recovery often deserves stronger assurance than routine login because it can replace the controls that normally protect the account.

How does deepfake detection work?

Deepfake detection asks whether media was generated or manipulated. Identity verification asks whether a person is who they claim to be. Those questions overlap, but neither fully contains the other.

Provenance and content credentials

Provenance records information about how media was created and changed. The C2PA Content Credentials specification defines a tamper-evident structure that can bind origin and edit assertions to an asset.

Valid provenance can increase confidence in the media history and signer. Missing provenance is not proof of manipulation, and valid provenance does not guarantee that the depicted claim is true. Provenance is a positive signal, not a universal detector.

Spatial forensic analysis

Image models can inspect texture, blending boundaries, lighting, reflections, frequency patterns, noise, geometry, and generator artefacts. These features may work well on known attack families and degrade when the model, camera, or compression changes.

Temporal and audiovisual analysis

Video analysis can examine consistency across frames, motion, pose, optical flow, facial landmarks, speech timing, and audio-video alignment. Voice analysis can inspect spectral, prosodic, and generation traces. Real-time use adds strict latency and quality constraints.

Presentation attack detection and liveness

PAD looks for an attempt to fool the capture sensor. Passive liveness can analyze a capture without asking the user to perform an explicit action. Active liveness asks for a response to a prompt or challenge.

PAD is scoped to the capture boundary. ISO/IEC 30107-3 explicitly treats attacks outside the biometric capture device as out of scope. A vendor claiming PAD coverage should separately explain injection, virtual-camera, emulator, and channel controls.

Capture integrity and device attestation

Capture controls try to establish that media came from the expected sensor, application, device state, and protected channel. Signals can include SDK integrity, device attestation, emulator or virtual-camera detection, signed capture events, anti-tampering measures, and server-side replay protection.

No device signal is infallible. The goal is to make forged delivery harder, detectable, and costly while preserving a recovery path for genuine users on unusual devices.

Identity and evidence linkage

Face comparison can link a live capture to a trusted portrait; document validation can test the evidence itself; database validation can corroborate attributes. These controls do not classify all synthetic media, but they reduce the value of a convincing face that lacks a defensible identity anchor.

Contextual and behavioral risk

Device reuse, IP and location inconsistency, impossible travel, repeated attempts, velocity, account history, transaction context, and relationship graphs can expose patterns that media analysis misses. A deepfake score should contribute to a risk decision rather than erase the other evidence.

Human review and independent verification

Reviewers need original media, detector outputs, reason codes, capture details, customer history, and a defined playbook. For high-impact actions, an independent trusted channel—such as a callback to a known number or approval in an authenticated system—can be more reliable than a visual judgment.

What can deepfake detectors get wrong?

False negative

The detector classifies manipulated media as genuine. This is the security failure that allows an attack through.

False positive

The detector classifies genuine media as manipulated. This can block a real customer, trigger unnecessary review, or disproportionately affect certain devices and populations.

Domain shift

The production environment differs from the test set: new generators, camera pipelines, codecs, lighting, languages, demographics, or attack behavior. NIST’s GenAI deepfake evaluation program focuses on adversarial and operationally relevant testing precisely because academic benchmark performance may not transfer cleanly to deployment.

Threshold mismatch

Every score becomes a decision only after applying a threshold. A threshold tuned for forensic triage may be wrong for instant account opening. Security, user friction, manual-review capacity, and downstream loss all influence the operating point.

Scope confusion

A detector evaluated on uploaded face images may say nothing about audio clones, real-time virtual cameras, document morphs, or replay. Product labels should be replaced with an attack-by-attack coverage matrix.

How should teams evaluate deepfake defenses?

Define the threat model first

List the protected action, attacker capability, media type, delivery path, expected devices, available identity anchors, and consequence of error. “Detect deepfakes” is not a testable requirement.

Demand an attack coverage matrix

Ask whether testing includes face swaps, reenactment, lip sync, fully generated faces, voice clones, morphs, printed and screen replays, virtual cameras, emulators, SDK tampering, and API injection. Record which control owns each attack.

Inspect the test data

Look for unseen generators, multiple attack tools, genuine users, demographic coverage, different cameras, compression, network degradation, and production-like capture. Separate development, validation, and test sets. Ask how often evaluation is refreshed.

Review both error rates

Obtain false-positive and false-negative behavior at the operating threshold, not only an accuracy headline. Ask for confidence intervals, sample counts, per-attack results, subgroup analysis, and no-response rates.

Test the whole journey

Evaluate the capture SDK, transport, backend, decision engine, webhooks, retry behavior, manual review, and account state. A strong media classifier can still sit behind a replayable request or an unsafe recovery flow.

Run a shadow deployment

Before blocking customers, score production-like traffic in shadow mode. Compare detector outcomes with reviewer findings, confirmed fraud, user retries, support cases, and downstream losses. Then set graduated actions such as allow, step up, review, rate-limit, or decline.

Plan for drift

Define ownership for new attack ingestion, red-team exercises, model updates, threshold review, incident response, and rollback. A one-time vendor test cannot cover a changing generator ecosystem.

Common deepfake-defense mistakes

Training users to look for visual glitches

Blinking, hands, teeth, lip sync, and edge artefacts can be clues, but they are neither necessary nor sufficient. Normal video can look strange after compression, and new generators can remove yesterday’s tell.

Buying one “deepfake score”

One score rarely covers every medium and delivery path. Require evidence about model scope, attack coverage, test conditions, thresholds, and error tradeoffs.

Assuming liveness stops injection

Liveness can help at the sensor boundary. Injection attacks target the path around or after that boundary, so they require capture-integrity and channel controls as well.

Treating missing provenance as proof of fraud

Many genuine assets have no content credentials. Absence means the provenance signal is unavailable, not that the media is fake.

Auto-declining every uncertain result

Ambiguous cases need risk-based step-up or review. A detector’s uncertainty should not become an unexplained permanent denial.

Ignoring non-media controls

Payment approvals, account recovery, credential changes, and data disclosure should have controls that survive a perfect imitation. Strong authentication, separation of duties, trusted callbacks, limits, and delay can reduce impact even when detection fails.

A layered defense model

LayerQuestionExample outcome
ProvenanceIs there a valid, trusted history for this asset?Verified credential, missing credential, invalid binding
Media forensicsDoes the media show manipulation or generation evidence?Risk score with attack-family evidence
Capture integrityDid media come from the expected sensor and application?Attested capture, virtual camera, replay, unknown
PAD and livenessIs a bona fide person present at the sensor?Bona fide, presentation attack, retry
Identity linkageDoes the person match trusted identity evidence?Match, non-match, insufficient quality
ContextDo device, network, account, and behavior agree?Normal, inconsistent, high velocity, linked abuse
ProcessIs the requested action independently authorized?Allow, step up, dual approval, hold

The layers should produce explainable evidence and bounded actions. A high-risk result can trigger a stronger capture, a different factor, manual review, or an independent confirmation rather than an immediate irreversible outcome.

Where Didit fits

Didit offers Passive Liveness at $0.10 and Active Liveness at $0.15, and its certifications include iBeta Level 1 PAD. These presentation controls can be paired with ID Verification, Liveness Detection, Face Match, and Device & IP Analysis in a risk-based workflow.

Each control has a boundary. Teams should map the PAD result to presentation attacks, evaluate capture and injection protections separately, and retain their own decision and review logic. Published module rates are available on the pricing page.

Frequently asked questions

Are all AI-generated images deepfakes?

Not necessarily. “Deepfake” usually implies synthetic or manipulated media that fabricates identity, speech, behavior, or an event. A clearly labeled generated illustration is synthetic media without necessarily being deceptive.

Can people reliably spot deepfakes by eye?

No. Visual clues can support triage, but reliability changes with the generator, media quality, compression, and viewer. High-impact decisions need technical and procedural verification.

What is the difference between a presentation attack and an injection attack?

A presentation attack places an artefact in front of the expected sensor. An injection attack inserts forged media into the processing path, bypassing or interfering with expected capture.

Does liveness detection stop every deepfake?

No. Liveness is a capture-focused control. Its coverage depends on the method and testing, and it does not automatically cover audio, documents, content provenance, or downstream injection.

Are content credentials proof that media is true?

They can provide tamper-evident provenance about origin and edits when the signer and binding are trusted. They do not make a value judgment about whether the depicted claim is true.

What metrics matter for a deepfake detector?

False-negative and false-positive behavior at the deployment threshold, broken down by attack type, generator, capture condition, device, and relevant population. Teams should also measure no-response rates, latency, review load, and downstream fraud.

What should happen when a detector is uncertain?

Use a graduated response: request a new trusted capture, require another authenticator, verify through an independent channel, place the action on hold, or route the case to trained review.

Primary references

Deepfake resilience comes from asking several narrower questions instead of trusting one broad score. Verify the media history, the capture path, the living person, the identity evidence, the surrounding context, and the authorization process—then decide according to risk.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page