In short
Episode Notes: Fighting AI with AI
Podcast Overview Podcast Title: The Indicator from Planet Money Description: A bite-sized show about big ideas, helping listeners understand the economy in under 10 minutes. Episode Title: Fighting AI with AI Air Date: [Insert Date Here] Episode Description: Explores the rise of vocal deepfakes and the technology emerging to combat AI voice fraud, particularly in banking.
Key Concepts and Discussions
- Introduction to AI Voice Fraud
- Deepfakes: Technology that can clone a person's voice in just a few seconds of recorded audio.
- Fraud Impact: Millions of Americans have fallen victim, with losses often reaching thousands of dollars.
- Voices of Experience
- Darian Woods and Angel Carreras Segment: A playful test revealing how easily an AI-generated voice could deceive someone into conducting fraudulent activities, like purchasing gift cards.
- Scam Dynamics: Criminals exploit urgency to manipulate victims, especially in emotional situations.
- Business Response
- Defensive Measures: Banks and institutions are adopting AI technologies to counter AI voice fraud.
- Mark Kroposzewski (PNC Bank): Discusses ongoing vulnerabilities in bank systems due to increasing digitalization of banking.
- Technology Against Fraud
- Reality Defender:
- Co-founded by Ben Coleman, aims to protect banks from voice fraud.
- Uses advanced inference techniques to detect features indicative of AI-generated voices.
- Limitations of Current Security Measures:
- Banks still heavily rely on voice biometrics, which Coleman warns could be a single point of failure.
- Multi-Factor Authentication
- Importance of Layered Security:
- Kroposzewski emphasizes the necessity of multi-factor authentication beyond voice recognition to bolster security.
- Banks are looking at various data points, including user location and device information.
- Customer Vulnerability
- Fraud Targeting Customers:
- Scammers often exploit customers' weaker defenses rather than bank systems.
- Techniques include impersonating loved ones in distress and urging immediate financial actions.
- Call for Regulation
- Ben Coleman’s Advocacy:
- Coleman believes that all online content should be vetted for AI generation to curb scams effectively.
- Engaged with Congress for potential regulations requiring disclosures regarding AI-generated content.
- Future Implications
- Technological Progress vs. Regulation:
- The rapid development of AI technologies outpaces the implementation of regulations.
- Expectation of automated detection systems in the future to identify AI content.
Key Takeaways
- Awareness of AI Deepfakes: Understanding the potential for deception through voice cloning is crucial for individuals and institutions.
- Importance of Security Evolution: As technology advances, so too must the strategies used to combat emerging threats.
- Regulatory Framework: There is a pressing need for legislative measures to keep pace with technological advances in AI.
Conclusion This episode effectively highlights the dual nature of AI - as both a tool for advancement and a weapon for fraudulent activities. It underscores the importance of vigilance, innovation in security measures, and the necessity for regulatory oversight in the face of rapidly evolving technologies.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:01NPR
0:11So Waylon, the other day I decided to give our colleague Angel Carreras a little test. Hello, Darian. Hey. Sorry, did you have headphones on? Angel, I need your help with something real quick. What's up? I need your help with something real quick. You sound like an AI. Would you be able to go out and buy some gift cards for me? You sound like an AI. I don't have time today. It's a surprise for our colleague. Darian, I'm so sorry. You're not fooling me. This is AI. If you could just go out and buy like$200 in gift cards, that would be awesome. Okay, actually, you've convinced me. Where should I get these?
0:47D-A-I, Darian? Come on, quick. On your feet, Darian. Angel, I have to admit something to you. Too sloppy, Darian. This is not my real voice. Too sloppy. I am a deep fake. Gosh. Angel, I got you. You got nothing. You got nothing. Oh, my gosh. Angel was so clever. If you had called me, I would have fallen for it immediately. I would have been like, where do you want the gift cards from? Gap? Do you need a gap gap card? No, I know. And so, yeah, depending on the person, depending on the situation, like maybe it's been urgent, like a cousin calling from a hospital, this could have really fooled somebody.
1:26Yeah, a lot of people are falling for these kinds of audio deepfakes. Like millions of Americans have lost money to a scam call that uses an AI voice. And the losses from these scams can be in the thousands of dollars. But it's not all hopeless. Businesses are using AI to fight AI. This is The Indicator from Planet Money. I'm Darian Woods. This week on The Indicator, we're going to bring you a special series on the evolving business of crime. Today's show, defending against AI voice clones. We speak with the company working to ferret out AI deepfakes, and we learn how banks are fortifying themselves in an age where anyone can sound like anyone else.
2:11This message comes from Vanguard. Capturing value in the bond market is not easy. That's why Vanguard offers a suite of over 80 institutional quality bond funds, actively managed by a 200-person global team of sector specialists, analysts, and traders. They're designed for financial advisors looking to give their clients consistent results year in and year out. See the record at Vanguard.com slash audio. That's Vanguard.com slash audio. All investing is subject to risk. Vanguard Marketing Corporation Distributor. This message comes from Dell Technologies. Your new Dell PC with Intel Core Ultra helps you handle a lot when your holiday to-dos get to be a lot.
2:55Luckily, the Dell PC helps you get it all done. Get yours at Dell.com slash holiday. This message comes from Mint Mobile. Starting at$15 a month, make the switch at mintmobile.com slash switch. $45 upfront payment for three months. Five gigabyte plan equivalent to$15 a month. Taxes and fees extra. First three months only. See terms. Banks are a big target of AI voice fraud. I mean, that's where the money is, literally. And so if you're a chief information officer at a bank, you're constantly checking your websites and phone line systems for any vulnerabilities. That's what Mark Kroposzewski is doing at PNC Bank.
3:35Frosters constantly bang on every door trying to find any crack in essentially our armor or our moat around the bank. As banking has gone more digital, obviously the criminals have followed there. One scheme calls people up, it records you talking for several seconds, and then it turns that into a cloned AI voice and uses that to bypass Bing's voice verification on the phone. Because it's so easy now to reproduce your voice, you really can't rely on any one vector to say, OK, I'm just going to accept it's you because I hear you. One person has been on this problem for years. Ben Coleman used to work for Goldman Sachs, and there he saw the early stages of these kinds of frauds.
4:23So in 2021, he co-founded a tech company that would try to protect big institutions like banks from voice fraud. He just didn't have the language for it yet. But we didn't have the buzzword of DeepFix. We didn't have generative AI. We didn't have chat, TBT or anything. So we said we can detect AI avatars and virtual humans, which were about to be this huge kind of tsunami of fraud. How did you see this coming? I just assumed if I was a hacker, what would I be doing? How do I do more hacking? That's what I ask myself every day, Tarion. Go to Black Hat Hacker Whelan Wong. Watch out. Ben thought that voice verification was this huge vulnerability for banks.
5:03If the bank verified your voice on the phone, you could do a wire transfer or reset the password and gain complete control. He named his company Reality Defender. We're doing what's called inference, which is looking for different features that probabilistically indicate that AI was used. An AI voice has a particular harmonic structure that the human ear doesn't hear, but Reality Defender software can detect. There's indicators of AI, which means that the information is, yes, it's yours, but it's being used by somebody who's not you. So your company is almost like one of these AI detection websites where teachers might put a student's essay and say, is this AI?
5:44Yeah, turnitin.com. Ben says the majority of top 20 banks use Reality Defender software, and many use other services like Ben's. But he says that banks should step up even further. Unfortunately, many institutions, not only banks, but also government organizations, insurance companies, media organizations, are still using what are called voice biometrics, which is a show of saying your voice is your password. Ben thinks banks should just remove seeing a voice as a kind of password entirely. We asked Mark Gwapazeski at PNC Bank why it was still using voice ID. Are there risks to PNC using voice authentication technology?
6:24I think if you're only using the one dimension, there's risk in everything. There'd be risk in accepting a driver's license, for example, somebody walking into your branch, which is why you're starting to see a lot more technologies that are looking for multi-factor authentication or even just those other signals. So I would sort of say you always want to have layers of security. And that's probably the key thing that we're always looking at is how well do we feel we have our various layers covered? And then you're able to learn where you might be overusing one of those signals and adjust. So it's not just your voice the banks are looking at, but also your location, the device you're calling from, details like your birthday, a text message verification code, all kinds of things.
7:13In fact, Mark says criminals flock to where the weakest defenses are. And thanks to software like Reality Defender, the greatest vulnerability isn't with bank phone lines. It's with the customers. So it's a little bit in reverse. How do you know that the company that just called you is actually PNC? We've spent a lot of time and money with the telecom carriers, different technology companies, so that if somebody's trying to spoof one of PNC's numbers, it gets blocked and it never gets delivered to you. The fraudster tries to build a sense of urgency that you need to move your money. Maybe they say the bank account's being compromised.
7:50We'll never ask you to move your money. If we think an account has been compromised, the bank will move your money for you, you know, within the bank. But he says a lot of people believe they're talking to the bank. The supposed bank worker will tell them to buy gold or cryptocurrency or withdraw cash and hand it over to someone, thinking that will keep the money safe. It's a scam every time. Another voice scam is going straight to the customer, pretending to be a loved one in need. Being in this part of the business I have with my family is essentially a safe word. And we all know if there's ever a situation where somebody is either really in trouble and asking for money, it's consistent.
8:36We will ask for the safe word. Angel could have used that. I mean, he didn't need one. But, you know, I thought the voice clone was actually pretty good. And that's why Ben Coleman from Reality Defender doesn't think that protecting banks is enough. He wants all content online to be vetted for whether it was AI generated from text to voice to video. Yeah, like celebrity scams are a problem right now. We've recently had revelations of scammers pretending to be pro golfers on Instagram and Facebook. I think we're going to look back and say I can't believe there was a time when we didn't have automated deep bank detection.
9:11Our challenge is just the technology is moving quicker than regulations. And that's why Ben went to Congress to try to advance regulation that would mean when you logged into Instagram or got a Zoom call or a WhatsApp voice memo, you would be informed about whether it was AI. We just gave testimony in Congress and in the Senate about this. We defaked Senator Blumenthal and Senator Hawley. We're going to ask the audience and those on the DS which ones are real and which ones are fake. Hi, my name is Richard Blumenthal, United States Senator from Connecticut, and I'm a diehard Red Sox fan. That clip of Richard Blumenthal was AI, by the way.
9:47Jeez, he needs a safe word. Should be Red Sox. By the way, we at The Indicator are not immune from AI deep fakers. We've heard reports of scammers pretending to be us at The Indicator. So note that we will always use an at NPR.org email address. Tomorrow in our Vice series, we bring you an episode on what's supercharging data breaches. This episode was produced by Cooper Katz-McKim with engineering by Robert Rodriguez, was fact-checked by Sierra Juarez. Cake and Cannon edits the show and The Indicator is a production of NPR. This message comes from the Council for Interior Design Qualification.
10:29Interior Designer and CIDQ President Siavash Madani explains the value of having an NCIDQ certification. An NCIDQ certified interior designer must complete a minimum of six years of specialized education and work experience and pass the three-part NCIDQ exam. All three exams emphasize and focus on health, safety, and welfare of the occupants. It's really about the implementation of design. Good design is never just about aesthetics. It's about intention, safety, and impact. We take the responsibility of protecting the public seriously. The space needs to be functional, safe, and accessible. To learn more about NCIDQ certification or to hire a certified designer, visit cidq.org slash NPR.
11:20This message comes from Capital One. The Capital One VentureX Business Card earns unlimited double miles on every purchase. Capital One, what's in your wallet? Terms and conditions apply. Find out more at CapitalOne.com slash VentureX Business.
From the publisher
With only several seconds of audio, someone can clone a victim’s voice, call their bank, and potentially get access to … everything. Vocal deepfakes have gotten very good, but so has the technology to fight back.
This week on The Indicator we're gonna bring you a special series on the evolving business of crime. In this episode, we hear from the company helping banks beat deepfakes, and we learn about the efforts to protect us all from AI voice fraud.
Related episodes:
Can you copyright artwork made using AI?
AI creates, transforms and destroys... jobs
For sponsor-free episodes of The Indicator from Planet Money, subscribe to Planet Money+ via Apple Podcasts or at plus.npr.org. Fact-checking by Sierra Juarez. Music by Drop Electric. Find us: TikTok, Instagram, Facebook, Newsletter.
Learn more about sponsor message choices: podcastchoices.com/adchoices
NPR Privacy Policy




