South Minneapolis News

collapse
Home / Daily News Analysis / Think you can spot fake AI photos? They’re now a security risk

Think you can spot fake AI photos? They’re now a security risk

Jul 21, 2026  Twila Rosenbaum  8 views
Think you can spot fake AI photos? They’re now a security risk

AI-generated images and videos have become a significant security concern. In the past, it was relatively easy to spot fakes by looking for obvious flaws like extra fingers or unnatural skin textures. But generative AI has improved so rapidly that even experts struggle to tell real from synthetic content. This is not just a curiosity—it has real-world consequences. Scammers now use deepfakes to impersonate friends, family members, or company executives to trick victims into transferring money or sharing login credentials.

One of the most telling signs of the difficulty came from public quizzes. In December, an NPR quiz asked participants to identify AI-generated videos, and many failed. Shortly after, the BBC published a quiz focused on AI-generated faces. Even after learning new techniques—such as examining facial symmetry, eye reflections, and skin texture—participants still found themselves uncertain. Researchers discovered that detection accuracy could rise from 40% to 80% after just an hour of training with real and fake images combined with expert tips. However, the rapid pace of AI development means these clues may soon become obsolete.

The security implications are severe. According to the Federal Trade Commission, deepfake scams have led to losses in the millions. A common scam involves a caller using a cloned voice of a loved one to demand emergency money. Another is the fake video of a CEO authorizing a fraudulent wire transfer. As AI becomes more accessible, the barrier to create convincing fakes lowers every month. Tools like Midjourney and DALL-E now allow anyone to generate photorealistic images with minimal effort. This democratization of AI is a double-edged sword: it helps creatives but also arms criminals.

Detecting these fakes fully cannot yet be automated. Many deepfake detection tools are based on machine learning models that can themselves be fooled by adversarial inputs. A recent study at MIT found that the best commercial detectors had an accuracy rate of only 70% against state-of-the-art fakes. That means relying solely on software is not enough. Human judgment must be part of the equation, and that requires constant education.

In the news

The good

Meta recently faced backlash over its plans to roll out Muse, an AI image generation tool for Instagram. The tool would have allowed users to create and share images of anyone, using their likeness without consent. Privacy advocates and users protested loudly, forcing Meta to withdraw the feature. This is a rare victory for consumer pushback against tech companies that treat user data as a free resource. It also highlights the importance of speaking up when companies introduce features that compromise privacy. Experts advise that users should always read terms of service and be vocal about objections to data mining.

The bad

Two major security vulnerabilities surfaced this week. First, Zoom disclosed critical flaws in its desktop application that could allow an attacker to take over a user's account. The issue lies in how Zoom handles certain authentication tokens. Users are urged to update to the latest version immediately. Second, a security researcher discovered that Shark robot vacuums have a vulnerability that exposes live video feeds, Wi-Fi passwords, and home floor plans to anyone within range who knows how to exploit it. The researcher was able to access cameras of other owners in his geographic region. This underscores the importance of segmenting IoT devices on a separate guest network to limit the damage from any single device being compromised.

The annoying

Data brokers continue to collect and sell personal information without most people's knowledge. These companies gather data from public records, online activity, and purchase histories, then bundle profiles that anyone can buy. Sam Singleton, a colleague at PCWorld, explains that opting out is possible but tedious. It requires contacting each broker individually and providing identification. Some brokers make it deliberately difficult to remove yourself. However, services that automate opt-out requests exist, though they come with their own privacy trade-offs. The best defense is to limit the amount of personal information you share online and to use privacy settings on social media.

Tip of the week

Scareware is a common tactic where malicious websites or apps display fake warnings about viruses on your PC, pressuring you to pay for unnecessary software or hand over personal details. Many antivirus programs block these sites, but Microsoft Edge has a built-in scareware blocker that does not require any extra installation. To check if it is enabled, go to Settings > Privacy, Search, and Services > Security. Scroll down to Scareware blocker and ensure the toggle is green. On newer Windows devices, it is often turned on by default; on older ones, you may need to activate it manually. This simple step can protect you from one of the oldest tricks in the cybercriminal playbook.

The arms race between AI generation and detection is ongoing. While the industry works on more robust authentication methods—such as digital watermarks and blockchain verification—individuals must educate themselves. The best practice is to approach any unsolicited video or image with skepticism, especially if it involves a request for money or sensitive information. Verify through a second channel, like a phone call or in-person conversation. As generative AI continues to evolve, staying informed is not just a matter of curiosity but a critical security measure.


Source: PCWorld News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy