Ensign joins growing list of companies, agencies to introduce deepfake detection in software suite

The integration of the software will create a more comprehensive view of the threats that employees may face

Yong Jun Yuan
Published Tue, Sep 17, 2024 · 04:26 PM
    • Ensign Labs vice-president of machine learning and cloud research Lee Joon Sern demonstrating the use of Aletheia, a real-time deepfake detection solution developed by Ensign.
    • When a user views or listens to any visual or aural content, they can activate the software for one minute to detect if the content has been manipulated by AI.
    • Ensign Labs vice-president of machine learning and cloud research Lee Joon Sern demonstrating the use of Aletheia, a real-time deepfake detection solution developed by Ensign. PHOTO: KEVIN LIM, ST
    • When a user views or listens to any visual or aural content, they can activate the software for one minute to detect if the content has been manipulated by AI. PHOTO: AFP

    CYBERSECURITY player Ensign Infosecurity launched its solution to detect deepfakes generated with artificial intelligence (AI) within its suite of cybersecurity solutions for enterprise customers on Tuesday (Sep 17).

    Ensign joins ST Engineering as well as the Agency for Science, Technology and Research’s Centre for Advanced Technologies in Online Safety (Catos) in developing such tools that aim to detect AI-manipulated content.

    Although he declined to reveal which of Ensign’s customers had signed on to the service, head of Ensign Labs Tan Ah Tuan said companies in the finance and energy sectors have indicated interest in the product.

    He noted that in his experience, he has seen some companies’ employees receive malicious content. Such content aims to trick employees and come in the form of manipulated audio and video mimicking that of key personnel, such as chief executives.

    In Hong Kong, an employee of a multinational company was reported to have been tricked into transferring HK$200 million (S$33.2 million) in funds to fraudsters after they attended a video conference call with deepfakes of the company’s chief financial officer and other employees.

    Deepfake detection

    Ensign said unlike other competing solutions, its deepfake detection software will run on the Windows operating system or as a Google Chrome browser plug-in.

    When a user views or listens to any visual or aural content, they can then activate the software for one minute to detect if the content has been manipulated by AI.

    If deepfaked content is detected, a notification will alert users that they could be watching or listening to manipulated content. The software will also take screenshots and highlight parts of the video that could have been manipulated, while manipulated audio will also be recorded so that users can listen back to the recordings.

    Ensign Labs vice-president of machine learning and cloud research Lee Joon Sern said that the software, which is based on the company’s own AI model, has been made to run on individual computers without the need to send video and audio clips to powerful servers for processing. He said the software has also been tested on four to five-year-old computers, which may have less processing power.

    “The advantage of this is that if you have a sensitive video call that has company information, and that you cannot upload to a public space for forensics, this (software) can do it right at the endpoint for you,” he said. An endpoint refers to a physical computer that is used by employees.

    He added that a side benefit of this is that the software is cheaper to run than cloud-based models, since the processing power used to detect deepfakes resides on the employee’s existing computer and not the cloud.

    Furthermore, Lee said the software will be integrated into the company’s suite of cybersecurity products to create a more comprehensive view of the threats that employees may face.

    He said that when the software detects that an employee has seen a deepfake, it can inform the company’s assigned cybersecurity analyst as well. This incident could then be tied in with other signals – such as if they have recently visited a phishing site – to trigger automatic actions. For example, they can reduce their monetary or administrative IT privileges.

    Just as antivirus software is updated over time, he said the detection solution will continue to be updated as deepfakes become more sophisticated. 

    For instance, the software could be updated to detect deepfakes across multiple video frames instead of individual frames, although Lee said that this would result in an increase in processing power needed to perform such tasks. 

    Currently, he noted that the software is not able to detect highly sophisticated deepfakes generated for the likes of movie production, such as in Star Wars. Among other scenes, computer-generated imagery of a young Luke Skywalker was used in an episode the TV mini-series The Book of Boba Fett in 2022.

    “That will be (from) the very very high-end attackers, and may not be the mass market (type), he said.

    Tan added that the company is in talks with the authorities to explore how they can work with the public sector to protect the public from deepfake scams as well.

    Deepfakes of local public figures have been published online in the past.

    In December 2023, a deepfake of then-Prime Minister Lee Hsien Loong was published to promote a cryptocurrency scam.

    StarHub earlier extended its assigned rights in Ensign until Oct 4, 2025, and maintains a 55.73 per cent effective interest in the cybersecurity company.