Deepfake Detection Techniques

Authors

  • Jonas Kovacs Author
  • Ivan Petrov Author
  • Oscar Garcia Author

DOI:

https://doi.org/10.5281/zenodo.19614820

Keywords:

deepfake detection; face forgery; voice cloning; media forensics; rPPG; cross-generation generalisation; CLIP; adversarial robustness; FaceForensics++; synthetic media

Abstract

Deepfake technology -- AI-generated synthetic media that manipulates or fabricates the likeness, voice, or actions of real individuals -- has advanced from a research curiosity to a widely accessible tool that poses documented threats to personal reputation, democratic discourse, financial fraud prevention, and court admissibility of audiovisual evidence. Detection has become an arms race: each generation of generative model produces fakes that defeat detectors trained on the prior generation. This study evaluates eleven deepfake detection approaches across four media modalities: face-swap video deepfakes, full face synthesis, voice cloning, and multi-modal (audio-visual) forgeries. Detection methods evaluated include frequency-domain analysis (FFT-CNN), spatial CNN classifiers (Xception, EfficientNet-B4), transformer-based detectors (ViT-Detect, CLIP-Detect), biological signal analysis (rPPG-based), recurrent temporal models (LSTM-Temporal), graph neural networks for face consistency (FaceGraph), audio spectrogram CNNs, and a multi-modal ensemble. Evaluation used FaceForensics++ (FF++), DFDC, Celeb-DF v2, WildDeepfake, ASVspoof 2021, and a purpose-built Cross-Generation Deepfake Benchmark (CGDB) testing generalisation to unseen generation methods. CLIP-Detect achieves the highest AUC on FF++ (0.994) but degrades substantially on unseen generation methods (CGDB AUC: 0.748). rPPG-based detection shows the strongest cross-generation generalisation (CGDB AUC: 0.836) by detecting physiological implausibilities rather than generation artefacts. Multi-modal ensemble achieves the best overall performance (mean AUC 0.924 across all benchmarks). Critical generalisation failure modes and adversarial robustness limitations are characterised

Downloads

Published

2026-08-19

How to Cite