Deep-Fake CAPTCHA: Mitigating Next-Generation Social Engineering Attacks
Authors: Guy Frankovits, Lior Yasur, Fred M. Grabovski, Yisroel Mirsky
Published: 2026-09-10 11:35:11+00:00
Comment: Expanded work from the original ASIA CCS paper on DF-CAPTCHA (now evaluates video deepfakes too)
AI Summary
This paper introduces DF-CAPTCHA, an active defense mechanism against real-time deepfake impersonation in voice and video calls. Unlike passive detection methods, DF-CAPTCHA challenges callers with tasks difficult for deepfake systems but easy for humans, verifying responses based on realism, identity consistency, task completion, and response time. The framework significantly improves deepfake detection across both audio and video modalities compared to passive methods, offering a robust defense against social engineering attacks.
Abstract
This paper presents DF-CAPTCHA, an active defense against real-time deepfake impersonation in voice and video calls. Instead of passively searching for artifacts, DF-CAPTCHA prompts the caller to perform simple challenge-response tasks that are easy for humans but difficult for current real-time deepfake systems to generate convincingly. The framework verifies the response using four criteria: realism, identity consistency, task completion, and response time. We evaluate the approach across both audio and video modalities using user studies and experiments with real-time deepfake models. Results show that people often struggle to distinguish real-time deepfakes from authentic media, while DF-CAPTCHA substantially improves detection performance over passive methods, reaching high accuracy in both modalities. These findings suggest that active challenge-based verification is a practical and robust defense against next-generation social engineering attacks based on real-time deepfakes.