Original title:
Umělá inteligence v počítačové bezpečnosti
Translated title:
Artificial Intelligence in Computer Security
Authors:
Firc, Anton ; Evans, Nicholas (referee) ; Ross, Arun (referee) ; Malinka, Kamil (advisor) Document type: Doctoral theses
Year:
2025
Language:
eng Publisher:
Vysoké učení technické v Brně. Fakulta informačních technologií Abstract:
[eng][cze]
Od svého vzniku ohrožují falešné zvuky počítačovou bezpečnost, protože zvyšují účinnost útoků sociálního inženýrství a umožňují podvrhnout systémy rozpoznávání řečníků. Zatímco výzkum se zaměřoval především na metody detekce, chyběla strukturovaná perspektiva kybernetické bezpečnosti, čímž vznikla mezera ve výzkumu. Tato práce představuje strukturované hodnocení kybernetické bezpečnosti rizik, která deepfakes představují. Klí\-čo\-vým výsledkem je pochopení modelu útočníka, který dále slouží jako vodítko pro vývoj a hodnocení metod ochrany. Navrhujeme rámec hodnocení detekčních metod, který řeší známé problémy detekce deepfake, jako je špatná generalizace a omezená srovnatelnost. Naše analýza lidského vnímání zvukových deepfakes inspirovaná reálnými útoky odhalila, že lidé nedokážou deepfakes při skutečných útocích spolehlivě rozpoznat. Na základě našich zjištění navrhujeme rozšířený model ochrany proti deepfake hrozbám. Tento model zahrnuje více opatření aktivních v různých fázích životního cyklu deepfake a nabízí strukturovanou ochranu. V neposlední řadě zkoumáme informovanost veřejnosti jako proaktivní obrannou strategii, která přináší osvětu s cílem zmírnit rizika útoků sociálního inženýrství založených na deepfake.
Since their origin, deepfake audio threatens computer security, increasing the effectiveness of social engineering attacks and enabling spoofing of speaker recognition systems. While the research focused primarily on detection methods, a structured cybersecurity perspective was missing, creating a research gap. This thesis introduces a structured cybersecurity assessment of risks posed by deepfakes. A key outcome is understanding an attacker model that further guides the development and evaluation of protection methods. We propose an evaluation framework for detection methods to address known challenges of deepfake detection, such as poor generalisation and limited comparability. Our analysis of the human perception of audio deepfakes inspired by real-world attacks revealed that humans fail to recognise deepfakes reliably in actual attacks. Based on our findings, we propose an extended protection model for deepfake threats. This model includes multiple measures active in different stages of the deepfake lifecycle, offering structured protection. Finally, we explore public awareness as a proactive defence strategy, delivering outreach and educational efforts to mitigate the risks of deepfake-driven social engineering attacks.
Keywords:
deepfakes; kyberbezpečnost; metody ochrany; rozpoznávání mluvčího; sociální inženýrství; cybersecurity; deepfakes; protection methods; social engineering; speaker recognition
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: https://hdl.handle.net/11012/255594