AI ディープフェイク対策に過去の低技術的セキュリティが有効と専門家が推奨
本文の状態
日本語全文を表示中
詳細モードで約12分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
ZDNET AI
AI ディープフェイクの高度化に対し、ZDNET は専門家の提言として高コストな技術的対策よりも、低技術的なセキュリティプロトコルの導入が有効であると指摘する。
AI深層分析を開く2026年8月22日 01:05
AI深層分析
キーポイント
ディープフェイクの高度化と検出困難性
AI による偽造コンテンツ(ディープフェイク)やクローン技術は年々洗練され、従来の手法では検出が極めて困難になっている。
長期的なシステム侵攻のリスク
高度な攻撃には単発的な偽造だけでなく、企業のシステムへの長期間にわたる潜伏・浸透型インシデントが含まれる。
低技術的対策の有効性提言
専門家は複雑な AI 検出ツールよりも、確立された低技術的なセキュリティプロトコル(例:事前の合意形成、多段階認証)がより堅牢な防御となると推奨する。
Arup 社における具体的な事例
2024 年 1 月、エンジニアリングサービス企業 Arup では、偽の CFO と見なされた人物とのビデオ会議をきっかけに、多額の送金詐欺が発生した。
顔や声の認識はもはや証明にならない
AI生成クローンが公的な発言から組み立てられるようになり、目と耳で相手を確認する従来のプロトコルは機能しなくなった。
重要な引用
Deepfakes and AI clones get more sophisticated and harder to detect.
Advanced attacks involve long-term infiltration of a company's systems.
"Seeing and hearing someone is no longer proof they are real,"
"Any protocol that relies on 'I recognized their face and voice' is now broken."
編集コメントを表示
編集コメント
技術的な検出ツールに頼りきっている組織にとって、この「低技術的解決策」の提言は逆説的に響くだろう。しかし、AI の進化速度が人間の判断プロセスを上回る現状を考えると、基本に立ち返る姿勢こそが最も堅牢な防衛となるはずだ。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

*ZDNET をフォロー:* *Google の優先ソースとして登録する*
ZDNET の主要ポイント
- ディープフェイクや AI クローンが高度化し、検出がますます困難になっている。
- 高度な攻撃には、企業のシステムへの長期的な浸透が含まれる。
- 専門家は、より効果的な防御手段となる低技術のセキュリティプロトコルを推奨している。
2024 年 1 月、コンサルティングファーム「Arup」の従業員が、同社の CFO が参加していると信じていた人物とのビデオ会議に参加しました。その結果、第三者口座宛てに約 2,500 万ドル(約 37 億円)相当の送金指示が 15 件実行されてしまいました。
ビデオ会議の向こう側にいた全員は、Arup の経営陣が過去に行った公的な登壇や決算説明会などの映像を基に、AI が合成したクローンたちでした。
関連記事:AI を活用する脅威アクターに対抗するための 6 つの必須戦略
「目で見たり耳で聞いたりしても、それが本人である証明にはもうなりません」と、GrackerAI の技術 CEO であるディープク・グプタ氏は ZDNET の取材に対し、Arup の事例を踏まえてこう語っています。「『顔や声の認識』を信頼するプロトコルは、もはや機能しなくなっているのです」
私たちは今、真偽が曖昧な世界に生きています。従業員たちは年間を通じて数百万ドル規模の会社資金を扱っており、一度のミスが大きな痛手となります。たとえ直接的な資金損失に至らなくても、顧客からの信頼失墜や法規制違反による罰金だけで、本来は黒字だった企業が経営破綻に追い込まれるケースさえあります。
サイバー詐欺に署名(指紋)が残らなくなった今、組織を守るにはどうすればよいのか。GrackerAI の Gupta 氏や B2B セキュリティ企業 S2i2 の CTO ジェームス・スコビー氏といったセキュリティ専門家は、大規模なビジネス運用から「単純すぎる」と見なされてきた低技術(ローテク)システムこそが解決策の鍵だと考えています。
明らかな手掛かりはもうない
企業活動の歴史において、ライブ音声やビデオ通話は身元確認のゴールドスタンダードであり続けてきました。これらの手法は、高価値取引の認証、機密性の高い医療データの交換、法的に重要な事項の議論などにおいて中心的な役割を果たしてきました。
関連記事:企業の 43% がすでに AI を活用したサイバー攻撃を経験している
しかしここ数年、深層偽造(ディープフェイク)技術が人間らしい振る舞いを驚くべき速さで模倣できるようになり、この基準は静かに侵食されつつあります。かつては背景の雑音や合成音声特有の変調、呼吸音が聞こえないといった明確な手掛かりが存在しました。しかし、ディープフェイク技術はこの確立された検知手法をすでに上回っており、デジタル上の同僚が本物かどうかを見分けることが極めて困難になっています。
ロンドン大学校(UCL)の最近の研究では、リスナーがディープフェイクを正確に識別できるのは約 73% の場合だけであることが判明しました。適切な訓練やディープフェイクサンプルへの慣れがあっても、精度はわずか 3.84% しか向上しませんでした。それからたった 1 年後、デュイスブルク・エッセン大学とインディアナ大学の研究者らが 56 の類似研究の結果を統合したところ、人間の検出精度は実際には偶然の確率に近いことが明らかになりました。
「兆候(テールズ)は補助的なシグナルとしてわずかな価値しかありません」と S2i2 のスコビー氏は説明します。しかし、これらの手法に頼って効果的な対策とするのはもはや選択肢ではありません。なぜなら、これらは攻撃時に従業員の知覚に依存するよう訓練してしまうためで、まさに詐欺師が狙っている感覚だからです。
NSA(国家安全保障局)、FBI(連邦捜査局)、CISA(サイバーセキュリティ・インフラセキュリティ庁)が共同で発表した情報シートでも、音声や動画コンテンツにおける操作の痕跡を可視化する従来の自動検出プロトコルは排除されました。これらの手法は、統計的に有意な操作痕跡を検出し記録できると仮定していますが、もはやそれが必ずしも成り立つわけではありません。
さらに懸念すべきは、技術が高度化するにつれ、ソーシャルエンジニアリング攻撃が単発の金銭詐欺に留まらず、企業のシステムへの長期的な浸透へと拡大している点です。
関連記事:AI 画像詐欺で来年は 400 億ドルの被害?国際基準が有効か
グプタ氏は、2024 年にセキュリティ研修企業 KnowBe4 がなりすまし被害に遭った事例を挙げました。同社は面接や身元確認の過程で不審な点を見逃し、攻撃者を採用してしまいました。実際には北朝鮮の工作員だった人物は、社用ワークステーションを受け取ってからシステムへマルウェアをアップロードしようとしていたことが発覚しました。
「皮肉なものです」とグプタ氏はこの事件を振り返りながら語りました。「セキュリティ研修企業である同社は、まさにこうしたソーシャルエンジニアリング詐欺を見抜く方法を教えるビジネスを行っています」。さらに彼は、北朝鮮の攻撃者がこの手の作戦を大規模に実行しており、毎年数千もの偽装従業員を送り込み、米国や欧州の企業の社員になりすましているとも付け加えました。
2025 年に米国司法省から発表された公衆への注意喚起では、北朝鮮の攻撃者が米国内や中国、アラブ首長国連邦、台湾に協力者を抱えていた可能性が示唆されています。Google の脅威インテリジェンスグループ(GTIG)は 2022 年以降、同様の事案を調査しており、近年では欧州諸国を標的とするケースが増えています。
昔ながらの手法こそ最強
高度な検出モデルや標準的なセキュリティ対策が機能しない場合、単一の制御された入り口(ポイント・オブ・エントリー)に依存するアナログな解決策の方がはるかに効果的です。
「最も高度な AI 攻撃に対する防御には、あえて低技術(ローテク)な手法を用いるのが常です」とグプタ氏は語ります。ディープフェイク技術は、公開されている外見や声を模倣する能力において飛躍的に向上しましたが、観測可能なチャネルの外に存在し、遠隔で監視できないものに対しては全く無力です。
関連記事:AI 時代における企業が失敗できないセキュリティ対策 5 つとその重要性
現在、多くの詐欺調査コンサルタントは、政府機関からのガイダンスに基づき、ハードウェアベースのセキュリティキーや口頭でのパスフレーズをセキュリティ対策として推奨しています。米国国土安全保障省傘下のCISA(サイバーセキュリティ・インフラストラクチャセキュリティ庁)は、FIDO2およびPIVハードウェア認証情報を、多要素認証(MFA)における新たなゴールドスタンダードとして推奨しています。また、職場や家庭内で共有する秘密の口頭パスフレーズについても、FBIから繰り返し推奨されています。
口頭パスフレーズとは、ビデオ通話や音声通話の際に、参加者間で事前に共有される秘密の単語またはフレーズのことです。従業員は、相手側にその秘密のパスフレーズを言うよう求めることで、通話相手の身元を確認できます。ただし、この手法が効果を発揮するのは、組織内の全員が一貫してそれを使用している場合に限られます。グプタ氏は自身の経験から、相手が上司だと主張するなど威圧的な態度をとられた際など、従業員はセキュリティチェックを省略しがちであると指摘しています。
関連記事: OpenAIの攻撃エージェントが指示通りに行動した - 予想以上に執拗に
「制御は自動化し、例外を許さないようにする」——スコビー氏はこう述べ、攻撃者が緊迫感や社会的圧力を煽り、従業員に既定の手順を無視させるケースが多いと指摘しました。また、セキュリティ訓練の一環として、深層偽造音声やボイッシングの模擬通話を実施し、権威ある人物のように見える相手に対して「ノー」と言う練習を積むよう提案しています。
グプタ氏はさらに、認証要件として社内のシステム内で直接、口頭でのパスフレーズ(verbal passphrase)の導入を義務付ける方が効果的だと付け加えました。一部の金融プラットフォームではすでにこの手法を採用しています。
例外を許さないポリシーの実施に加え、大規模組織でも単一障害点を避けつつスケーラブルに運用できる低技術的な解決策として、パスフレーズ認証が挙げられます。スコビー氏は、標準的なパスワード管理のベストプラクティスをそのまま口頭パスフレーズにも適用するよう推奨しています。具体的には以下の通りです。
- 手動でパスフレーズを作成せず、ランダムなパスワードジェネレーターを利用する。
- 無関係な単語をランダムな数字や記号で区切って組み合わせる(例:"harley9jedi@buddies.sinclair")。
- 単一障害点を避けるため、役割や取引ごとに異なるパスフレーズを用意する。
- パスフレーズは定期的に更新するが、固定されたスケジュールに従う必要はない。
- パスフレーズ認証を他のセキュリティプロトコル(ハードウェアキー、アウトオブバンドコールバック、二要素認証など)と組み合わせる。
Scobey氏は、Electronic Frontier Foundation(EFF)が公開している単語リストを参照し、推測されにくくかつ記憶しやすいランダムなパスフレーズを組み立てることを提案しています。ただし、人間の心には無意識のバイアスや好みが存在するため、パスフレーズよりもランダムパスワード生成器の使用の方が望ましいです。「強さは、単語の意味の深さではなく、選択のランダム性によって生まれます」とScobey氏は付け加えています。
大規模な組織では、特定の取引や従業員の役割に特化した、ロールベースおよび関係ベースのパスフレーズを導入すべきです。例えば、1,000ドル未満のすべての財務取引を承認するために「経理部門用」の固有パスフレーズを用意し、1,000ドル以上20,000ドルまでの取引には別のパスフレーズを設定するといった運用が可能です。
このアプローチを採用すれば、万が一一つのパスフレーズが漏洩しても、他のパスフレーズはそのままに保ちつつ、該当するものだけを容易に再設定できます。また、パスフレーズは定期的にローテーションさせるべきですが、固定されたカレンダーに従う必要はありません。現在ではNISTガイドラインも、90日ごとのパスワードリセットルールが予測可能性を生みすぎるとして見直すべきと示しています。代わりに、漏洩の証拠がある場合や、役割変更が発生した場合、あるいは従業員が退社する場合などにパスフレーズを差し替えるべきです。
関連記事:ベストなパスワードマネージャー:専門家による検証
最終的に、大企業における高価値取引のセキュリティを確保するために、暗証文句(パスフレーズ)だけでは不十分です。オフ・オブ・バンド(OoB)コールバックや二重認証などの他のプロトコルと組み合わせる必要があります。
このアプローチとは、複数の公式通信チャネルを通じてリクエストを検証し、処理前に第 2 の承認者による検証を必須とするものです。
グプタ氏によると、企業側はセキュリティシステムに過度な障壁を導入することに抵抗を示す傾向があります。しかし、目指すべきはいたるところで摩擦を生むことではなく、リスクの高いワークフローにのみ制限を設けることです。
「セキュリティが網羅的なものではなく、特定のターゲットに向けたものであると認識されれば、人々はそれを回避しようと試みなくなります」とグプタ氏は語ります。暗証文句の数が多すぎて管理が困難になる場合は、Keeper Security などの FedRAMP 認証済みパスワードマネージャーを使用して、企業の認証情報を保存することをスコビー氏は提案しています。
原文を表示

*Follow ZDNET: *Add us as a preferred source* on Google.*
ZDNET's key takeaways
- Deepfakes and AI clones get more sophisticated and harder to detect.
- Advanced attacks involve long-term infiltration of a company's systems.
- Experts recommend low-tech security protocols that offer better defenses.
In January 2024, an employee at professional services firm Arup joined a video call with someone they believed included the company's CFO. This call resulted in 15 wire transfers to third-party accounts totaling about $25m.
Every participant on the other side of the video call was an AI-generated clone cobbled together from public appearances and earnings calls of Arup executives.
Also: 6 essential strategies to defend against AI-powered threat actors
"Seeing and hearing someone is no longer proof they are real," said Deepak Gupta, technical CEO at GrackerAI, when discussing the Arup incident with ZDNET. "Any protocol that relies on 'I recognized their face and voice' is now broken."
We live in a post-truth world where employees handle millions of dollars in company funds every year. Mistakes can be expensive, even when attacks don't lead to a direct loss of funds. Over time, the damage to customer trust and fines for legislative non-compliance alone can put an otherwise profitable company out of business.
How can you keep your organization safe when cyber fraud no longer leaves a signature? Security experts like GrackerAI's Gupta and James Scobey, CTO at B2B cybersecurity firm S2i2, think the answer lies in the same low-tech systems once considered too simple for large-scale business operations.
There are no obvious tells
Live voice and video calls have remained the gold standard for identity verification throughout most of corporate history. These techniques have been central for authenticating high-value transactions, exchanging sensitive medical data, or discussing matters of legal importance.
Also: 43% of companies have already experienced AI-enabled cyberattacks
But in the last five years, that standard has been quietly eroded by deepfakes that have grown better at mimicking human behavior at an uncanny speed. There used to be certain tells, like background noises, synthetic voice modulation, and the distinct lack of breathing sounds. However, deepfake technology has outpaced these tried-and-tested tells, and it's difficult to tell when your digital coworker is real.
A recent University College London study found that listeners could accurately identify deepfakes only about 73% of the time. Even with proper training and familiarization with deepfake samples, the accuracy rate improved by just 3.84%. Just a year later, researchers from the University of Duisburg-Essen and Indiana University aggregated results from 56 similar studies and found that human detection rates were actually closer to chance in terms of accuracy.
"Tells still have marginal value as a supporting signal," explained S2i2's Scobey. However, relying on these techniques as an effective control is no longer an option because they train employees to rely on their perception during attacks, which is precisely the sense these scammers target.
A joint information sheet released by the NSA, FBI, and the Cybersecurity and Infrastructure Security Agency (CISA) also ruled out traditional automated detection protocols that visualize evidence of manipulation in voice or video content. These methods assume that statistically significant traces of manipulation can be found and recorded, which is no longer necessarily the case.
What's even more troubling is that as technology becomes more sophisticated, social engineering attacks are no longer restricted to one-off financial scams but extend to the long-term infiltration of a company's systems.
Also: AI image fraud will cost $40 billion next year - can these international standards help?
Gupta pointed to a 2024 incident involving security training firm KnowBe4, which was the victim of identity fraud. KnowBe4 hired an attacker after interviews and screening that did not flag the individual as suspicious. They even supplied the employee with a company workstation before realizing they were a North Korean operative using the device to upload malware to their systems.
"It's almost poetic," Gupta remarked while recounting the incident. "This is a security training company; its whole business is teaching people to spot social engineering scams like this." He also added that North Korean attackers have been running this type of operation at scale, sending off thousands of fake workers each year to pose as employees at companies in the US and in Europe.
A public notice from the US Department of Justice in 2025 also suggested that North Korean attackers operated with assistance from collaborators in the US, China, the United Arab Emirates, and Taiwan. The Google Threat Intelligence Group has been investigating similar incidents since 2022, with a significant portion of them now targeting European nations.
Old-fashioned is best
Where advanced detection models and standard security countermeasures fail, analog solutions that rely on a single controlled point of entry prove much more effective.
"The defense against the most advanced AI attack is often deliberately low-tech," said Gupta. Deepfake technology may be much better now at replicating publicly accessible appearances and voices, but is entirely useless against anything that exists outside observable channels, and that cannot be spied on remotely.
Also: 5 security tactics your business can't get wrong in the age of AI - and why they're critical
More fraud consultants now recommend hardware-based security keys or verbal passphrases as security measures, based on guidance from several government agencies. CISA, which operates under the US Department of Homeland Security, now recommends FIDO2 and PIV hardware credentials as the new gold standard for multi-factor authentication (MFA). Secret verbal passphrases shared between members of a workplace (or household) are also a recurring recommendation from the FBI.
A verbal passphrase is a secret word or phrase shared between participants during a video or voice call. Employees can authenticate the person on the other end of a call by asking them to say the secret passphrase. However, these verbal passphrases are only effective if they're used consistently by everyone in an organization. Gupta explained that, in his experience, employees often skip security checks when they feel intimidated, such as when the person on the other end of a call presents themselves as a superior at work.
Also: OpenAI's attack agent did exactly what it was told - just more relentlessly than expected
"Make the control automatic and no-exception," said Scobey, confirming that attackers often create a sense of urgency or social pressure to encourage company workers to skirt established protocol. He also suggested running simulated deepfake or voice-phishing calls as part of employee security training to help people practice saying no to someone who appears to speak from a position of authority.
Gupta added that it might even be better to enforce verbal passphrases as an authentication requirement directly in the company systems, which some finance platforms are already doing.
Apart from implementing a no-exception policy, low-tech solutions like passphrase authentication need to be made scalable for larger organizations that cannot afford a single point of failure. Here, Scobey recommended taking the same best practices that apply to standard company password management and applying them to verbal passphrases, for example:
- Don't create verbal passphrases manually; use a random password generator.
- Use unrelated words separated by random numbers and symbols, for example: "harley9jedi@buddies.sinclair".
- Maintain separate verbal passphrases for different roles and transactions to avoid a single point of failure.
- Reset your passphrases periodically, but not according to a fixed schedule.
- Combine passphrase authentication with other security protocols (hardware keys, out-of-band callbacks, dual authentication).
Scobey pointed to the Electronic Frontier Foundation's word list for stringing together random passphrases that are difficult to guess but easy to recall. It's better to use a random password generator, since human minds have subconscious biases and preferences that make passphrases easier to guess. "The strength comes from the randomness of the selection," Scobey added, "not from how meaningful the words are."
Larger organizations should also implement role- and relationship-based passphrases that are specific to certain transactions and employee roles. For example, a company could have a unique passphrase for the accounts payable department to authorize all financial transactions under $1,000, another passphrase for transactions ranging from $1,000+ to $20,000, and so on.
With that approach, if one passphrase is compromised, it can be easily reset while others stay intact. Passphrases should also be rotated frequently, but not according to a fixed calendar. NIST guidelines now suggest overturning the 90-day password reset rule because it creates too much predictability. Instead, passphrases should be replaced whenever there's evidence of compromise, role change, or employee offboarding.
Also: The best password managers: Expert tested
Finally, a verbal passphrase alone cannot provide sufficient security for high-value transactions in large enterprises. The passphrase must be combined with other protocols, such as out-of-band callbacks and dual authorization. That approach means authenticating the request through more than one official communication channel and requiring a second authorized employee to validate the request before it's processed.
Gupta has found that companies object to introducing too many hurdles in the security system. However, the goal isn't to add friction everywhere, but to confine it only to high-risk exposure workflows.
"When people experience security as targeted rather than blanket, they stop trying to bypass it," he said. If the sheer number of passphrases makes them difficult to manage, Scobey suggested using a FedRAMP-authorized password manager, such as Keeper Security, to store company credentials.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み