You Can't Spot a Deepfake?And Neither Can Your Brain Nor Eyes: A Neurophysiological Framework for Deepfake Exploitation of Cognitive Engagement and Implicit Visual Evaluation

Authors: Cagri Arisoy, Md Imanul Huq, Amy W. Hays, Nitesh Saxena

Published: 2026-09-26 16:46:19+00:00

Comment: Accepted at the 29th Information Security Conference (ISC 2026)

AI Summary

This research introduces DECEIVE, a framework to assess how deepfake videos exploit cognitive engagement and implicit visual evaluation by humans. Through an EEG and eye-tracking study, it found no significant neuro-physiological differences between real and deepfake videos, contrary to expectations, indicating deepfakes effectively evade both conscious and subconscious human detection. Participants behaviorally accepted a substantial portion of manipulated clips, especially familiar identities, confirming deepfakes as effective adversarial payloads.

Abstract

Deepfakes have rapidly emerged as a pressing threat to information integrity and security because they exploit human trust in visual and auditory perception. Yet, little is known about whether humans and their underlying (sub)conscious neuro-physiological processes can reliably distinguish deepfake from real videos. We introduce DECEIVE (Deepfake Exploitation of Cognitive Engagement and Implicit Visual Evaluation), a framework that models how deepfake videos are validated as adversarial payloads through behavioral and neuro-physiological screening of viewers, and how attacks can be refined by selecting payloads that evade detection. The framework is dataset agnostic and applies to synthetic or real media. It is inherently dual-use: an adversary with equivalent measurements could iterate on candidate manipulations and retain those that evade human detection. This motivates open, defensive evaluation. Measuring which deepfakes defeat human perception establishes a realistic bound on attacker capability against which detection tooling, provenance and watermarking mechanisms, and user-facing protections can be assessed. As an instantiation, we conducted an EEG and eye-tracking study in which participants viewed real, deepfake, and look-alike videos drawn from Celeb-DF and a curated celebrity set, while behavioral judgments and implicit responses were recorded. Contrary to expectations of subconscious differentiation suggested by prior work on paintings and phishing websites, no statistically significant neuro-physiological differences emerged between real and deepfake videos, although clear distinctions were observed for look-alike videos. Behaviorally, participants accepted 26.68% of manipulated clips as authentic, rising to 31.94% for familiar identities, confirming the studied deepfakes as effective adversarial payloads within DECEIVE.


Key findings
The study found no statistically significant neuro-physiological or ocular differences between real and deepfake videos, suggesting deepfakes bypass both conscious and subconscious human detection mechanisms. Participants showed a 26.68% false positive rate for deepfakes, rising to 31.94% for familiar identities, indicating human vulnerability is even higher for well-known figures.
Approach
The authors conducted an EEG and eye-tracking study where participants viewed real, deepfake, and look-alike videos. They measured behavioral judgments (acceptance/rejection) and neuro-physiological responses (EEG for cognitive engagement and eye-tracking for visual evaluation) to assess human susceptibility and subconscious differentiation.
Datasets
Celeb-DF, Curated YouTube celebrity database (COT-DB)
Model(s)
UNKNOWN
Author countries
Türkiye, USA