Hello all, thank you for attending today. I've just realized I've got the wrong glasses on, so it's going to be very difficult for me to read my notes here, but forgive me if I sort of look a bit strange.
So yes, so Peter James, iProov's Chief Product Officer, and talking about videoconferencing, and let's say the big challenge with deepfakes is that it means that we can't trust our eyes, and of course if we can't trust our eyes then is videoconferencing a doomed technology? But first of all, let's just think about like why does it even matter, right? Why is this a problem? And I don't know about you, but I spend my day on videoconferencing. I move from one meeting to another, all of those remote meetings, be that with my team, with prospects, or with customers.
And in those calls we'll be talking about normal things, but we'll be talking about commercial things. We'll be talking about strategic. We'll be making decisions in there. We'll be talking and making financial decisions. And you want to know, and you want to be able to trust, that the person on the other end is who you think they are, because of the types of things that you're sharing, the decisions that you're making. And this goes broader than that. Our culture and everything has moved to expect there to be services availability everywhere and anywhere.
So remote access to the types of services that are very important to our lives. Getting access to a prescription, being able to make insurance claims, even getting access to benefits and pensions. Things that are really important to our lives. So it's integral to that modern life, and it's not just directing those services, but it's also carrying a lot of money and a lot of reliance on those services being there. And because of that, it means then that it's also something that's very attractive to attackers. And we've seen this in many examples, but I've got three here.
We had the very first, I think, big example, public example of a deepfake attack through video conferencing with Arup a couple of years ago, where some finance guy thought he was speaking to his senior leadership team and was tricked into making transfers of over $25 million. So quite significant. And then we've got the infamous North Korean hackers. Two examples here. One where they're using deepfake videos to target crypto firms.
And then one which has become more and more prevalent over the last year or so, which is where they're using AI, video conferencing, deepfakes, to trick their ways in interviews into getting access to remote jobs. So they're fooling people into thinking they're hiring US employees, when in fact they're hiring people who are in North Korea. And they're doing the job, they're paying them to do that job, and that currency is leaving the US and heading over to North Korea. So these are proper challenging situations. They're growing. It's becoming more and more prevalent. How do we stop that?
So what's the challenge? The challenge is that for years, where we've been building out our security, we spent a lot of money, a lot of attention on securing our perimeter defenses. What we've been doing is relying on credentials, relying on devices, relying on documents. And so as long as those were valid, then we assumed that the person behind the credential was also the person we expected them to be. But with the rise of AI, with the rise of deepfakes, we can't be sure of that anymore. They don't authenticate the human, they authenticate the credential.
And because we always rely on seeing, being, believing, with AI and deepfakes, we can't rely on that. There we go. Get all the peats working. And with generative AI, this fundamentally turned that assumption on its head. And in a big way. So at iProof, our job is liveness and detecting deepfakes. And over the decade from 2014 to 2024, we saw this emerge. We saw in 2016, deepfakes start to emerge. We saw the first face swaps in 2018. These weren't sophisticated. They were sophisticated for the time, but would be laughable now. But they weren't expected. So people weren't on guard.
They weren't expecting to see deepfakes. And so again, the trust was there and things started to come through. But people got wise to that, started to spot these things. But the tools continued to improve. The capabilities began to continue to improve.
And 2024, we declared that as being the year of no return. This was the year when the tools got so good, so available, so accessible, easy to use. So easy to run in real time on your own home machine, that you can no longer, with obviously good tooling and good capabilities, you can no longer tell a deepfake with your bare eyes. And if you'd like to test that as it happens, you come to our stand upstairs. We've got a deepfake challenge on there. You can scan and you can test yourself against a number of deepfakes and potentially win an air tag. So worth trying out.
But just because 2024 was the year of no return, it didn't mean that it was a plateau of development. Tools continue to get better. And this isn't just some hackers in some back room pulling together tools, sweating over what they can do and how they can do it. We've got some of the biggest companies in the world plying billions of dollars into developing this technology, making it better, making it more accessible. And they're doing that for good reasons, right? So they're doing it for legitimate reasons. We're doing it for entertainment, right?
We want to have movies, we want to have capabilities that look more real, that allow us to create better entertainment. We're using it in marketing, we're using it in sales, right? We want to be able to create better tools, we want to create better reality, and we want to be able to do things faster. We want to scale ourselves much more broadly. And we also want to make sure that we're doing it in a more cost effective way. So these tools are great. They're doing good things for us as business people, and they're allowing us to really improve our wares.
What we've seen in just the last 12 months is 10 years worth of development in just that one year. This is accelerating. They're getting better. And the challenge is, of course, that they're getting cheaper, they're getting better, they're getting more accessible. And that's true of legitimate use, but it's also true of the illegitimate use. The bad actors have access to these tools as well. So let's just touch a minute on how it is that an injection attack actually works. So there's two main sides to this.
The first part, you've got to create the deep fake, you've got to create the face swap or whatever it is that you're doing, because that's the thing that's actually going to trick the human on the other side. So we create the deep fake, we're able to fool the human. But that only works if we can get it into the system. So the second part is then that you create the ability to inject that into the stream of your video so that the system is fooled into thinking it's getting a stream from the real camera. So two sides to the challenge, but both sides possible.
And I'll show you an example of how this works in a little while. And so as we talked about earlier, the door is left open for those human to human interactions. And that means then that the door is open for some pretty nefarious activities. And that these activities have some significant consequences. So three examples here. So the US Government Accountability Office in 2024 said that there was between 200 and 500 billion federal dollars lost to fraud every year. On the national security side, we talked about the North Korean hackers earlier.
There's evidence here, this is from Google Threat Intelligence, that over 3,000 North Korean workers have infiltrated over 300 Western companies. So this isn't just a few people doing this, this is a scale problem and happening all the time. And then we've got 40 billion in AI-enabled fraud losses by 2027. So it's a really challenging situation. So what do we do? Do we just revert back to in-person? Do we just give up and just say, actually, you know what, it's too easy to fake this. I can't tell. We're just going to have to go back to in-person meetings.
Now, of course, as you will all say, that's just a ridiculous idea, right? We're too entrenched. It's too important to our lives. And it's that everything has shifted to be available remotely. There are so many people who rely on the fact that they need access to these services, and that those services are available when they need them. But in order to be able to offer that level of service, they need to be offered more centrally, and so giving remote access.
If we were to reverse all of that, it'd be a huge cost, huge implications to us to be able to put all of those services back locally to where people are. Or, of course, we could just continue our exposure to the attacks and just live with the fact that some of those things happen.
Again, not going to be worthwhile, not going to be the thing that we want because of the consequences we talked about at the beginning. Why we care? Because what we're doing is important things, and we're doing things that our businesses are reliant on, that our services are reliant on. So what we need to do is we need to be able to block the bad actors, but we need to let the right people through whenever we need to.
Simple, right? Well, we like to think that with iProve Verified Meetings, we can make it that simple. And what we've done is we've used that decade of experience that we have in doing this with remote services, looking for deepfakes, protecting against deepfakes, protecting against presentation attacks, and we've brought all of that experience, all of that capability into the video conferencing service. So let me show you how it works.
So first, we'll look at it from the attacker's perspective. So I talked earlier about how an attack works. So here's Abby. She's going to choose a face swap in this particular tool and apply that. She's then moved to the video conferencing. She's selecting the virtual camera. So this is how that now gets injected into the feed. We've now got the new Abby, and when she joins the video call, there's no way to tell that that's not a real video that's coming in. In real time, it's swapping her face, and our interviewer is fooled. From the host's perspective, it's just a normal video call.
Abby's joined. No reason for him to believe that's not really her, but we've given him the tools to make sure of that. So clicking on the tool opens up this window, select the instant check, and our backend now starts to look at those frames. It starts to look at the video and see if there's anything suspicious. We know there is, of course, because we saw her doing it, but so does the system. And there's an immediate clear sign to the user that there's a deep fake going on.
It's really important that there's a user experience here that's able to be used, because everybody uses video conferencing. I'm using it, you're using it, we're using it for interviews, the whole business uses it. So we need to make sure that it's a system that's not only secure, but simple to use. So we give a simple red, amber, green result.
Also, when you're doing it, you don't want to just check at the beginning, because you could join at the beginning, then you could walk off frame, you can come back in, maybe now you've brought somebody else in to represent you. So that's where the deep fake happens. So that ability to check is there throughout the whole call. You can check at any point and we'll give you that result.
Also, we can't just sit on our haunches and expect that once we've released the software that that will continue to save you and continue to support you forever. Just as we do with liveness, this is not just software, this is a service. So we need to make sure that you're protected for the long term. So we have our iProof Security Operations Center, who are constantly monitoring, constantly watching the service, constantly looking at what attackers are doing.
So we've got threat hunting, threat intelligence, we've got our own red teams attacking our system, using those new tools, looking for new capabilities, looking for new techniques that are being used to make sure that we're constantly protecting the system. And because it's cloud-based, it means that we can release new capabilities, we can release new protections immediately. They go out to all of our customers immediately, and there's no effort on the customer side to have to do to incorporate that.
So the time between us releasing a protection and that protection being affected on the customer side is minimized, because that's the real risk point while there's an attack that we know about and you're not protected. So, as I say, there are four key elements then to verify meetings and to make sure that you're protected. The first is that you've got layered defenses. We talk about deepfakes like they're a single thing, but they're not.
There are hundreds of tools out there, there are hundreds of techniques, there are thousands of combinations of tools and techniques to be able to instigate these types of threats. So you need a system that's able to have multiple layers of protection to be able to protect you from all of those. You need that continuous resilience. As we saw earlier, decades worth of development in a year. These tools are getting better and they're getting better quicker. So we can't sit still and just let the system stay still as well.
We have to keep improving the system, making sure it's protecting you from the latest attacks. And then we need a user interface that the user can use. The untrained user is able to understand the result that they're getting.
So red, amber, green, simple feedback informing them of the next steps. And then we want to make sure that any decisions that we make based on this are able to be monitored, are able to be reviewed, and they're auditable. So recording the result so that they can be reviewed later. So I asked at the beginning, whether it's a doom technology, whether video confidency can survive in the deepfake era. You'll be unsurprised to hear that I think the answer is yes, as long as we're using systems like iProves verified meetings, liveness, strong liveness is the way that we continue to use this system.
So thank you very much. I hope it's helpful. Please come to see us at our booth, and we can talk through this in more detail. Thank you. Thank you.
So, do we have any questions? Does it work seamlessly with Zoom teams and other technologies? So we've built the technology as a plug-in. So the capability is centralized. We don't have plug-ins for all the video conferencing systems yet, but there's a roadmap that we'll see that come through.
So yes, absolutely, Zoom teams. Google's a little bit trickier because it's all web-based. We need access to the raw video feed so that we can do these tests. And so that will come in time, I hope. Any more questions?
Yes, there's a question at the back. Hi, thanks for the presentation. So from a fraud perspective, where do you see that this deepfake scheme is going to be in the next, let's say, three years, like bold prediction? In what sense?
I mean, let's say the last 10 years, and then over the last year, we see just a huge acceleration of the capabilities. And the biggest challenges are not just that the technology is getting better, but the bad actors themselves are starting to see the value of this. And so they're starting to share the techniques as well. So we're seeing collaboration between threat groups around what works, what they can do, sharing where they see particular weaknesses.
And so the big challenge here is unlike in the old days when people would be creating masks or doing some sort of presentation attack, those were very hard to scale. It cost you a lot of money to create a very good realistic mask. You then have to do that again for the second and the third one. With these techniques, you can share them, you can scale them incredibly quickly, incredibly easily and incredibly cheaply. And so even if they don't work every time, you're so scaled that you can still make good hay while the techniques are open. Any further questions? So just one final question.
Is it the participant in the meeting that has control, or is there an overarching sort of policy that can be set by the organization that will automatically prevent these deepfakes? So, well, I mean, there's nothing that stops the deepfake. This is about detecting the fact that there is a deepfake there.
And so, as with all sort of enterprise tools, you can decide who has access to the plugin or not. And so, yeah, there'll be controls there.
Again, we want to be very conscious of privacy and those types of things. So, again, there'll be updates in the terms and privacy policies. There'll be clear instruction to the participants that this is a thing that will be happening.
And so, so, yeah, there'll be those sorts of controls in place. OK, so thank you very much indeed to Peter here. And please, can we now have Eric John set us and we'll be introduced by Gwilym. Thank you. Thank you very much.