BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/The Detector Scored Well. Your Video Is Not the Te…
IndustryAugust 31, 2026
Read · 5 min
deepfake detection · deepfakes

The Detector Scored Well. Your Video Is Not the Test Set.

A detection accuracy figure describes the dataset it was measured on. Here is what the research actually concludes, and what protects a business instead.

A supplier sends you a video. It shows a person who appears to be your operations manager approving a change of bank details, and the voice is close enough that two people in the office are unsure. Somebody suggests running it through a detector, and a search turns up several that promise very high accuracy on exactly this kind of thing.

Before you spend anything, it is worth knowing what the researchers who built the largest public dataset of these videos concluded after running a competition on it. Their word was unsolved.

Key takeaways
  • The team behind the largest public face swap dataset, over 100,000 clips from 3,426 paid actors, described detection in their own paper as extremely difficult and still an unsolved problem.
  • Five years later the research still opens the same way. A 2025 generalisation paper begins by stating that generalising to unseen manipulation techniques remains a challenge for practical deployment.
  • An accuracy figure is a measurement on a specific dataset. Your incoming video is by definition not in that dataset, which is the entire reason the number does not transfer.
  • One counterintuitive finding from that 2025 work: detection difficulty on academic datasets has not strictly increased over time, and models trained on older, diverse data generalise well. Newest is not a safety claim.
  • Provenance is the strategy that does not depend on guessing. Content Credentials record how an asset was made and cryptographically bind that record to the file.
  • For a business being impersonated, the useful responses are provenance on your own content, platform reporting, and a rule that has been in force since April 2024.

What did the largest study actually conclude?

That the problem is unsolved, in the authors' own words, and they wrote that after assembling the biggest resource anyone had built for solving it. That combination is the single most useful fact in this subject.

The paper describing the DeepFake Detection Challenge dataset sets out the scale. Over 100,000 clips sourced from 3,426 paid actors, all of whom agreed to have their likenesses modified, produced with several deepfake methods, GAN based face swapping and non learned techniques. A public Kaggle competition ran on top of it, and the paper analyses the top submissions in detail.

Its conclusion is carefully worded and worth reading in both directions. The authors say that although detection is extremely difficult and still an unsolved problem, a model trained only on their dataset can generalise to real deepfake videos found in the wild, and that such a model can be a valuable analysis tool when examining a potentially faked video.

Note what that sentence promises. A valuable analysis tool. Not a verdict, not proof, not something you act on alone. The people with the strongest possible incentive to present detection as working chose to describe their best result as an aid to analysis.

Has it been fixed since?

No, and the opening line of the current literature says so almost verbatim. This is the check worth doing whenever a vendor implies the field has moved on.

A 2025 paper on deepfake detection that generalises across benchmarks begins by stating that the generalisation of deepfake detectors to unseen manipulation techniques remains a challenge for practical deployment. Its authors evaluated across fourteen benchmark datasets spanning 2019 to 2025 and report state of the art average cross dataset performance, which is real progress, and the framing of the problem has not changed.

Two of its findings are more useful to a buyer than the headline result. The first is that training on paired real and fake footage from the same source video is essential to stop the model learning shortcuts. A detector that has not done this may be picking up on compression artefacts or lighting rather than on manipulation, which works beautifully on the test set and fails on your video.

The second finding is the one that should change how you read a sales deck. The authors report that detection difficulty on academic datasets has not strictly increased over time, and that models trained on older, diverse datasets show strong generalisation. Trained on the newest fakes therefore is not the reassurance it is presented as. Diversity of training data matters more than its recency, and a vendor emphasising recency may be telling you which of the two they lack.

Why does the accuracy number not transfer?

Because it was measured on fakes the model had already been shown, and your adversary chose their tool afterwards. That is not a flaw in any particular product. It is the structure of the task.

A detector is a classifier. It is trained on examples of manipulated video produced by the generation methods that existed when the training set was built, and it learns the traces those methods leave. Scored against held out examples from the same generators, it does well, and that is the number that reaches the marketing page. Then a new generation tool ships, leaving different traces, and the classifier has never seen them.

Diagram breaking down what a single deepfake detection accuracy number hides, including the dataset, unseen methods, compression, false alarms and training demographics

Everything else that varies between the lab and your inbox pushes in the same direction. The video that reaches you has been through a messaging app, recompressed, possibly re-recorded from a screen, cropped, and played at a resolution nobody optimised for. Each of those steps removes exactly the fine grained signal a detector relies on.

So the honest reading of a quoted figure is narrow. It tells you the product works on the data it was tested against. It says very little about a compressed clip made last month with a tool the vendor has not seen, which is the only case you actually care about. We reached the same conclusion from a different direction when looking at written text, in our piece on what AI content detection can honestly tell a shop, and the underlying mathematics is the same.

What should you ask before buying one?

Five questions, and the pattern of answers matters more than any individual response. A vendor doing serious work answers these readily because they have measured them.

Ask thisWhy it changes the numberA good answer sounds like
Which datasets was that scored onIn distribution scores are much higher than cross dataset onesNamed datasets, plus a cross dataset figure that is lower
Was the manipulation method in trainingUnseen methods are the deployment case and the hard oneA held out evaluation on methods excluded from training
What happens after compressionMessaging apps strip the signal detectors useFigures at several compression levels, not one
What is the false positive rateWrongly flagging real footage has its own costA rate on genuine video, reported separately
Who was in the training dataError rates vary by skin tone, age and lightingA demographic breakdown, or an honest admission there is none

The fourth row is the one people forget, and it is the one that hurts a business. A detector that flags a genuine supplier video as fake has not saved you anything. It has introduced a delay, a dispute, and a reason to distrust a real counterparty, and unlike a missed fake it happens on ordinary days rather than rare ones.

How good does a detector have to be to be useful?

Better than the base rate of the thing it is looking for, which is a much higher bar than it sounds and the reason impressive sounding numbers can be worthless in practice. This is the arithmetic nobody puts on a pricing page.

Work it through with a shop's actual traffic. Suppose you receive two hundred pieces of video and voice a month from suppliers, couriers, staff and customers, and suppose one of them in that whole month is a fake. Now apply a detector that catches 90 percent of fakes and wrongly flags 5 percent of genuine material.

It catches the fake, most of the time. It also flags about ten genuine items, because 5 percent of the hundred and ninety nine real ones is roughly ten. So when the tool raises an alarm, the chance that the flagged item is actually fake is around one in eleven. Ten times out of eleven you are investigating a real supplier, a real courier, a real member of staff.

Card explaining why a ninety percent accurate deepfake detector still produces mostly false alarms when fakes are rare in a business inbox

Nothing about that result depends on the detector being bad. It follows from fakes being rare in your particular stream, and rarity is the normal condition for a small business. The same arithmetic is why medical screening programmes agonise over who to test rather than testing everyone, and it is why a security tool that fires often gets ignored within a fortnight.

Two consequences fall out of it. First, the false positive rate matters more than the catch rate for anyone whose fake rate is low, which is almost every reader of this article. A vendor quoting only the catch rate has given you the less important of the two numbers. Second, narrowing what you run the detector on improves the result more than improving the detector does. Applying it only to unsolicited media that asks for money or credentials raises the underlying rate of fakes in the pool, and every alert becomes more meaningful.

It also changes who should be looking. A detector pointed at everything needs somebody to triage ten false alarms a month, which is a job nobody has been given and which quietly stops happening by the second month. A detector pointed only at unsolicited payment requests produces perhaps one alert a quarter, which a single person can genuinely review with care. The tool that fires rarely and is read every time beats the tool that fires often and is dismissed, and that is a decision about scope rather than about software.

That second point is the practical takeaway. You are not going to get a better model than the research field has. You can absolutely choose a smaller, riskier pool to point it at, and that choice is worth more than the difference between any two products on the market.

What works better than detection?

Proving what is real, rather than guessing what is fake. It is the inversion the whole field has been moving toward, and it is available now.

Content Credentials, the standard produced by the Coalition for Content Provenance and Authenticity, take the opposite approach. As the C2PA frequently asked questions explain, a manifest records how content was created, what tools or processes were used, when and where it was made, and how it has changed over time. The manifest carries cryptographic hashes of both the asset and the provenance data, so tampering with either invalidates the signature.

The advantage is structural rather than incremental. A detector has to be right about an adversary it has never seen. A provenance record only has to be checked. It does not degrade when a new generation tool ships, because it makes no claim about fakes at all: it says this file came from this camera or this software, and here is the signature.

Note

Provenance has an honest weakness and the standard names it, one of several we set against each other in the breakdown of what Content Credentials prove and what they do not. Metadata gets stripped, routinely, by platforms and messaging apps that recompress everything they touch. The C2PA answer is durable credentials through soft bindings, meaning invisible watermarking or fingerprinting that can help rediscover the credential after it has been removed from the file. Useful, and not the same as the record surviving intact. Absence of a credential is never evidence of a fake.

For a shop the practical consequence is that provenance is something you apply to your own content, so that your real material can be verified, rather than something you use to judge incoming material. That asymmetry is worth internalising: it protects your brand outward, and it does very little for the video in your inbox. The related question of marks left in your published text rather than your video is covered in our look at the invisible mark AI text now carries on your website.

What do you do about a fake video of your own business?

Three things, and detection is not among them. This is the scenario that actually reaches small sellers, usually as a fake advertisement or a fake endorsement rather than the thriller version.

Publish verifiable originals. If your genuine adverts and announcements carry Content Credentials, you have a way to point at what is real. A public reference of where you actually post, on which accounts, does much of the same work for free.

Report through the impersonation route, not the copyright one. Platform impersonation processes are faster than intellectual property claims and they exist for exactly this. The mistake is to file a copyright complaint about footage the impersonator generated themselves, which they own, and which will therefore be rejected.

Know that a rule already covers it. The Federal Trade Commission's rule on impersonation of government and businesses, at 16 CFR Part 461, took effect on 1 April 2024 and addresses business impersonation directly. It does not remove a video from a platform for you, and it changes what you can escalate to and what the FTC can pursue.

If the impersonation has gone as far as a copied storefront rather than a copied face, the response is different again and considerably more urgent, which we set out in our piece on what to do when somebody clones your shop in an afternoon.

What about the video in your inbox right now?

Verify the transaction, not the video. This is the resolution to the scenario at the top of this article and it is dramatically cheaper than any detector.

The fake bank details video is a payment fraud attempt wearing new clothes. The control that defeats it is the one that has always defeated it: a change of payment details is confirmed by calling a number you already held, not one supplied in the request, and it is approved by a second person. That control costs nothing, works against a perfect fake, and does not care what generation tool was used.

Treat any detector output as one weak signal among several. Where it came from, whether the request is unusual, whether the channel is the normal one, whether anything about the timing is convenient for the sender. A detector's verdict belongs in that list rather than above it, and the DFDC authors said as much when they called their best result an analysis tool.

Security controls that assume media can be faked are the ones that survive the next generation tool. That principle is why our own approach to security leans on process and verification rather than on detecting what an attacker sent, and it is the same reasoning that makes voice and video verification steps worth writing down before you need them.

The sentence to keep

A detection score is a measurement of the past, and impersonation is a claim about the present. Everything practical follows from holding those apart.

Detection tools have a role, as an input to a human judgement, in the hands of somebody who knows what the number was measured on. What they cannot be is the control. The control is a process that stays sound whether or not the video is real, and provenance on the content you publish so that your own material can be checked rather than guessed at. Neither of those depends on winning a race against the next generator, which is fortunate, because five years of the strongest research available says that race is not being won.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building