A Representative Study on Human Detection of Artificially Generated Media Across Countries
Joel Frank, Franziska Herbert, Jonas Ricker, Lea Schönherr, Thorsten Eisenhofer, Asja Fischer
IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 5
Overview
In an era increasingly shaped by sophisticated artificial intelligence, the line between authentic and artificially generated media has become dangerously blurred. This IEEE S&P talk, presented by Joel Frank and his colleagues, delves into a critical question: can humans reliably distinguish state-of-the-art AI-generated media from real-world content? The research presented is a comprehensive, representative study spanning the United States, Germany, and China, involving approximately 3,000 participants, and examining images, audio, and text.

Key moments
- 0:00 Introduction to Deepfakes and the need for human detection
- 2:00 Interactive examples of AI-generated images, audio, and text
- 2:48 Overview of the study design across countries and media types
- 4:30 Detailed explanation of the study phases and participant interaction
- 6:35 Key finding: Human accuracy is roughly 50% across the board
- 8:00 Participants consistently rate generated media as human-made
- 10:00 US participants cannot distinguish AI from real data
A Representative Study on Human Detection of Artificially Generated Media Across Countries
Speakers: Joel Frank; Franziska Herbert; Jonas Ricker; Lea Schönherr; Thorsten Eisenhofer; Asja Fischer
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=QikVRQSgayo
Overview
In an era increasingly shaped by sophisticated artificial intelligence, the line between authentic and artificially generated media has become dangerously blurred. This IEEE S&P talk, presented by Joel Frank and his colleagues, delves into a critical question: can humans reliably distinguish state-of-the-art AI-generated media from real-world content? The research presented is a comprehensive, representative study spanning the United States, Germany, and China, involving approximately 3,000 participants, and examining images, audio, and text.
The talk highlights a concerning trend: as automated deepfake detection methods are increasingly bypassed, human judgment remains the last line of defense. However, this study reveals that this defense is alarmingly porous. The findings demonstrate that people are, on average, no better than random guessing at identifying AI-generated content, often defaulting to classifying it as human-made. This has profound implications for cybersecurity, misinformation, and the very fabric of trust in digital information.
The significance of this work cannot be overstated. With the proliferation of deepfakes for scams, political manipulation, and disinformation campaigns—ranging from a $250,000 voice clone fraud to a $25 million video impersonation scam and AI-generated political calls—understanding human vulnerability is paramount. This study provides crucial empirical data on the scale of this challenge, offering insights into regional differences, the impact of AI model maturity, and the limited utility of demographic or personal factors in enhancing detection capabilities.
Background
▶ Watch: Introduction to Deepfakes and the need for human detection (0:00)
The rise of deepfake technology has introduced a new frontier of challenges in digital security and information integrity. As early as 2019, a UK-based energy company fell victim to a $250,000 scam orchestrated through a voice clone of its CEO. More recently, a sophisticated operation in Hong Kong defrauded a company of $25 million by leveraging fake video personas of its Chief Financial Officer. The political landscape is not immune, as evidenced by the AI-generated robocall featuring President Joe Biden's voice, urging Democratic voters not to participate in the polls. These incidents underscore the tangible, high-stakes threat posed by artificially generated media.
In response to this escalating threat, both industry and academic communities have invested significant resources into developing automatic detection methods for deepfakes. These systems aim to identify subtle artifacts or inconsistencies indicative of AI generation. However, a critical limitation of these methods, as highlighted by other research presented at the same conference, is their susceptibility to bypass. As generative AI models become more sophisticated, they can often produce outputs that evade current automated detectors. This reality means that once automatic detection fails, the burden of identification falls squarely on human judgment.
Despite the growing prevalence and sophistication of deepfakes, there has been a notable lack of comprehensive, representative data on human detection capabilities. Prior research has often been limited in scope, either focusing on specific media types, smaller participant pools, or non-representative demographics. This knowledge gap motivated the present study, which sought to address the fundamental question of how effectively humans can discern state-of-the-art AI-generated content across diverse cultural and linguistic contexts. The problem isn't just that deepfakes exist, but that the human ability to identify them, and the factors influencing that ability, were largely unquantified on a global scale.
Key Findings
▶ Watch: Overview of the study design across countries and media types (2:48)
The central research question driving this study was whether people can identify state-of-the-art generated media. The findings present a stark and concerning answer: generally, no. The study, involving approximately 3,000 participants across the US, Germany, and China, provided robust empirical evidence for this conclusion.
A primary finding was the overall low accuracy of human detection. Across all countries and media types—images, audio, and text—participants' accuracy hovered around 50%. This figure is critical because 50% accuracy is equivalent to random guessing, indicating that the average person is no more likely to correctly identify a deepfake than if they simply flipped a coin.
Digging deeper into the data, the researchers observed a significant human bias towards rating AI-generated samples as human-produced. When participants were unsure, their ratings consistently skewed towards "definitely human," rather than being evenly distributed or leaning towards "nonhuman." This means that even when a sample was machine-generated, participants were more inclined to believe it was real. This bias was so pronounced that the average rating across all samples, including those generated by AI, was consistently positive on the 7-point scale (where +3 is "definitely human" and -3 is "definitely nonhuman").
A notable outlier emerged in Germany, specifically concerning audio data. German participants demonstrated a statistically significant higher accuracy in identifying AI-generated audio samples compared to participants in the US and China. This difference was particularly evident when analyzing the contrast distribution for generated audio, where German participants were better at identifying machine-generated data in 80% of cases compared to the US. Anecdotal evidence from the researchers suggests this might be due to older German text-to-speech models producing audio that sounded more "robotic and monotonous" compared to the more human-like quality of English (US) generated audio.
Conversely, for US participants, the quality of AI-generated media, particularly text and images, was so advanced that there was no statistically significant difference in how they rated human-generated versus AI-generated samples. This indicates that for English-speaking audiences, the AI-generated content was virtually indistinguishable from real content, effectively making human judgment obsolete.
The study also investigated the influence of demographic and personal variables. While some demographic factors, like age, showed a slight influence (e.g., older Germans were less accurate at identifying deepfake audio), these effects were largely diminished or nonexistent when the AI-generated content was of high quality. Similarly, personal variables such as familiarity with deepfakes or cognitive reflection had complex, often counteracting effects. For instance, being familiar with deepfakes might help identify fake content, but it could also introduce a bias, making individuals more suspicious of real content. Ultimately, these factors offered little consistent benefit in improving overall detection accuracy against sophisticated AI.
In summary, the key findings paint a grim picture: humans are generally ill-equipped to detect state-of-the-art AI-generated media. They tend to err on the side of believing content is human-made, and while regional differences in AI quality might offer temporary windows of detectability, the overarching trend is towards indistinguishability.
Technical Deep Dive
▶ Watch: Detailed explanation of the study phases and participant interaction (4:30)
The study meticulously designed its methodology to assess human detection capabilities across three crucial media types: images, audio, and text, utilizing state-of-the-art generative AI models prevalent at the time of the study.
For images, the researchers employed StyleGAN2, a leading generative adversarial network, to produce high-fidelity human faces. To ensure representativeness and control for potential biases, both the real-world image samples and the StyleGAN2-generated images were equally split across gender, age, and ethnicity. This allowed for a balanced assessment of detection difficulty irrespective of demographic features within the image.
The audio samples were created using a sophisticated text-to-speech (TTS) pipeline, specifically combining Tacotron 2 and HiFi-GAN. Tacotron 2 is an acoustic model that converts text into an intermediate acoustic representation (mel spectrograms), while HiFi-GAN is a vocoder that synthesizes this representation into high-fidelity audio waveforms. The models were trained on a dataset of text-audio pairs. For the study, 15 random real samples were selected from the training set, and 15 corresponding fake samples were generated from their transcriptions using the TTS pipeline. This controlled approach ensured that the content of the real and fake audio samples was semantically identical, isolating the perceptual difference to the generation quality.
For text, the study leveraged GPT-3, a large language model, to generate artificial news articles. Real-world news articles were collected from neutral sources like Reuters in different languages to serve as benchmarks. GPT-3 then generated corresponding fake articles, ensuring that the content and style were plausible enough to challenge human discernment.
The study's execution involved three main phases:
- Introduction: Participants were introduced to the study's purpose, data usage, and opt-out options. Demographic data, including self-reported familiarity with deepfakes, was collected.
- Main Part: Participants were assigned to a fixed condition (images, audio, or text only). Each participant rated six samples (three real, three generated) on a 7-point Likert scale, ranging from -3 ("definitely nonhuman") to +3 ("definitely human"). A progress bar was included to manage participant expectations regarding survey length.
- Post-Survey: Additional data was collected on personal variables, including generalized trust and cognitive reflection, using established psychological scales.
To analyze the nuanced findings, the researchers performed a regression analysis to predict the probability of participants correctly categorizing samples as either human-generated or machine-generated. This analysis confirmed the overall bias: participants had a significantly higher probability of correctly identifying real human data than correctly identifying AI-generated data, largely because they predominantly rated all samples as human-generated.
Furthermore, a contrast distribution analysis was utilized to quantitatively compare detection performance between countries, particularly highlighting the statistically significant difference in German participants' ability to identify AI-generated audio. This method involved subtracting the probability mass of one distribution from another (e.g., US correct detection probability vs. German correct detection probability), providing a clear measure of which country's participants were more adept at certain tasks. This technical rigor ensured that subtle but significant differences in human perception across cultures and media types were accurately quantified and interpreted.
The framework and analysis code for the study were made publicly available on GitHub, allowing for reproducibility and further research by the community, demonstrating a commitment to open science.
Demo / Proof of Concept
▶ Watch: Participants consistently rate generated media as human-made (8:00)
While the conference talk did not feature a live, interactive demonstration of a deepfake generation tool or an attack scenario, the presenter effectively illustrated the core problem through illustrative examples at the beginning of the presentation. Joel Frank showcased six distinct media samples – two images, two audio spectrograms (representing audio), and two text snippets – and challenged the audience to identify which were human-generated and which were AI-generated.
This "pause the video and guess" segment served as a potent demonstration of the problem's difficulty. The subsequent reveal of the correct answers underscored the central premise of the study: even for an audience likely to be more technically informed or security-aware, distinguishing between real and synthetic content is an inherently hard task. These initial examples, drawn directly from the samples used in the study, visually and auditorily established the high quality of contemporary AI-generated media.
The purpose of this demonstration was not to showcase a novel deepfake technique or a defensive tool, but rather to concretely illustrate the human perceptual challenge that the study then quantified. It provided immediate, tangible evidence that the "state-of-the-art" generative models (like StyleGAN2, Tacotron 2 + HiFi-GAN, and GPT-3) are indeed producing content that is virtually indistinguishable from reality, setting the stage for the empirical findings that followed. The lack of a traditional "proof of concept" for an exploit is appropriate, as the talk focused on human perception rather than a system vulnerability.
Defensive Implications
▶ Watch: US participants cannot distinguish AI from real data (10:00)
The findings of this representative study carry profound defensive implications for individuals, organizations, and society at large in the face of escalating deepfake threats. The most critical takeaway is that human judgment is an unreliable and insufficient defense mechanism against sophisticated AI-generated media.
Firstly, the pervasive human bias towards believing content is authentic (rating AI-generated media as human) creates a massive vulnerability. Defenders cannot rely on the intuition or critical thinking skills of the average user to flag deepfakes. This "default to human" assumption means that malicious actors using deepfakes will have a significant advantage in deceiving targets, whether for financial scams, corporate espionage, or political disinformation. Security awareness training must explicitly address this inherent bias, emphasizing that what "looks" or "sounds" real may very well be fake.
Secondly, the study underscores the urgent need for robust and un-bypassable automatic detection methods. While current automatic detectors can be circumvented, the long-term defensive strategy must focus on developing next-generation AI forensics tools that can reliably identify synthetic content, even as generative models continue to advance. Investment in research for watermarking, provenance tracking, and tamper-detection technologies for digital media becomes even more critical. These technologies could provide cryptographic assurances of authenticity, rather than relying on perceptual cues.
Thirdly, the observed regional differences in AI generation quality (e.g., German audio) present a transient opportunity but also a potential for tailored attacks. While some AI models might produce artifacts detectable in specific languages or contexts, this advantage is fleeting as generative AI rapidly improves. Defenders should be aware of these temporary "tells" but understand that they will soon disappear. Attackers, conversely, could exploit these differences, deploying higher-quality deepfakes in regions where their models are more advanced, or where human detection is already weaker.
Finally, the limited and often counteracting influence of demographic and personal variables on detection accuracy suggests that simply educating the public or hoping for "smarter" users is not a viable long-term solution. While general media literacy is important, it cannot be the primary defense against deepfakes. Instead, defensive strategies must focus on technological solutions at the platform level (e.g., social media, communication apps) to identify and flag synthetic content before it reaches the end-user, or to provide tools that empower users with verifiable information about media authenticity. Organizations must also implement stricter verification protocols for high-stakes communications, such as multi-factor authentication for financial transactions that involve voice or video, and independent verification of critical instructions. The era of trusting what you see and hear online without robust verification is effectively over.
Key Takeaways
- Humans are generally unable to distinguish state-of-the-art AI-generated media from real media. Across images, audio, and text, average detection accuracy hovers around 50%, equivalent to random guessing.
- A strong human bias exists to classify AI-generated content as human-produced. Participants consistently rated synthetic media as authentic, leading to a high false positive rate for real content and a low true positive rate for fake content.
- While regional differences in AI generation quality can temporarily impact detectability (e.g., older German audio models), this advantage is rapidly diminishing. For US participants, AI-generated content was often indistinguishable from real media.
- Demographic factors (like age) and personal variables (like familiarity with deepfakes) have limited or counteracting influence on detection accuracy. These factors offer no consistent benefit in improving human ability to identify deepfakes when AI quality is high.
- Over-reliance on human detection is a critical security vulnerability. Given the demonstrated inability of humans to reliably identify deepfakes, defensive strategies must shift away from human judgment as the primary safeguard.
- There is an urgent need for robust, un-bypassable automatic detection technologies and proactive platform-level interventions. Future defenses must focus on technical solutions like provenance tracking and AI forensics, rather than solely on user education.
About the Speaker(s)
The talk was presented by Joel Frank, who introduced the work as a collaborative effort with his colleagues Franziska Herbert, Jonas Ricker, Lea Schönherr, Thorsten Eisenhofer, and Asja Fischer. The transcript identifies Joel Frank as the primary presenter for this "representative study on human detection of artificially generated media across countries," indicating his central role in communicating the research findings. While specific titles or affiliations for the speakers were not detailed in the provided transcript, their collective presentation at IEEE S&P highlights their involvement in significant research within the cybersecurity and AI domains. Joel Frank's presentation demonstrated a deep understanding of the research methodology and its implications.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This is a foundational piece of research, quantifying human vulnerability to sophisticated AI-generated media on a global scale. It delivers a brutal truth: humans are no better than random guessing at detecting deepfakes, with a dangerous bias towards believing everything is real. This study unequivocally shifts how defenders must approach misinformation and deepfake threats, providing critical empirical data that was sorely lacking.
Heather Calloway (CISO) — MUST SEE
This study delivers a stark and critical message: human judgment is no defense against sophisticated AI-generated media. It provides irrefutable evidence that our default trust mechanisms are broken, demanding an immediate re-evaluation of digital security and verification strategies at the highest levels.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024