- Type
- Synthetic media
- Core methods
- GANs, diffusion models, autoencoders
- Media
- Video, audio, image
- Emerged
- Around 2017
- Main risks
- Fraud, disinformation, impersonation
- Related
- Voice cloning, watermarking
- Type
- Synthetic media
- Core methods
- GANs, diffusion models, autoencoders
- Media
- Video, audio, image
- Emerged
- Around 2017
- Main risks
- Fraud, disinformation, impersonation
- Related
- Voice cloning, watermarking
A deepfake is a piece of synthetic media in which an individual's face, body, or voice is generated or manipulated by deep learning techniques to make them appear to say or do things they never did. The term combines "deep learning" and "fake" and entered common usage around 2017. Deepfakes are most commonly produced using generative adversarial networks, autoencoders, and, more recently, diffusion models, which can synthesise highly convincing video and audio from relatively modest amounts of source material.
How deepfakes are made
Early face-swap deepfakes relied on a pair of autoencoders that learned to compress and reconstruct the faces of two people, then swapped the decoders so that one person's expressions were rendered with another's appearance. Generative adversarial networks improved realism by pitting a generator that creates fake frames against a discriminator that tries to detect them, driving both toward higher fidelity. Modern pipelines increasingly use diffusion models and large multimodal systems that can generate or edit video directly from text or reference images.
Audio deepfakes, often called voice cloning, use neural text-to-speech and voice-conversion models that can reproduce a target speaker's timbre and intonation from a few seconds of recorded speech. The convergence of video synthesis, voice cloning, and freely available data-scraping tools means that convincing fakes can now be produced in minutes rather than requiring specialist expertise.
Detection and provenance
Deepfake detection is an active research area, but it remains an adversarial problem: as generators improve, the visual and acoustic artefacts that detectors rely on become harder to find. Detection approaches include classifiers trained to spot statistical traces of synthesis, analysis of physiological signals such as blinking or pulse, and inconsistencies in lighting and reflections. Because detection alone is fragile, attention has shifted toward provenance and authenticity standards, such as content credentials and cryptographic watermarking that label media at the point of creation. The table below contrasts the two strategies.
| Strategy | Approach | Limitation | | --- | --- | --- | | Detection | Classify media as real or fake after the fact | Degrades as generators improve | | Provenance | Attach verifiable origin data at creation | Requires broad adoption by platforms |
Uses and harms
Deepfakes have legitimate applications in film dubbing, accessibility, satire, education, and synthetic data generation. However, they are widely associated with harm, including non-consensual imagery, political disinformation, and financial fraud in which fabricated executives or public figures authorise transfers or promote fake investment schemes. The erosion of the assumption that recorded media is authentic, sometimes called the "liar's dividend," also lets genuine evidence be dismissed as fabricated.
Malaysia has experienced a sharp rise in deepfake-enabled fraud. Scammers have circulated fabricated videos impersonating Prime Minister Datuk Seri Anwar Ibrahim, businessman Tan Sri Robert Kuok, AirAsia's Tan Sri Tony Fernandes, and other prominent figures to promote fraudulent investment schemes. Authorities reported that Malaysians lost more than RM1.12 billion to online scams in the first half of 2025, with synthetic video and cloned audio now standard tools in the scammer's toolkit.
The regulatory response is evolving. As of 2025 Malaysia had no dedicated anti-deepfake statute, and prosecutions relied on existing laws such as the Penal Code, the Communications and Multimedia Act 1998, and the Personal Data Protection Act. Commentators including the Penang Institute have argued that this patchwork is inadequate for AI-driven fraud and have called for specific legislation.
Government bodies are mobilising. The National Cyber Security Agency (NACSA) has been finalising the Cyber Security Strategy 2025–2030, which explicitly accounts for AI-related threats, and the Ministry of Digital has introduced AI guidelines and training programmes as proactive measures against online scams. Malaysia has also moved toward national AI standards, sometimes referenced as MY-AI, aimed at the online fraud crisis.
Financial institutions such as Maybank and CIMB, along with Bank Negara Malaysia, have intensified public awareness campaigns warning that visual likeness can no longer be treated as proof of identity, and have promoted multi-factor verification to counter voice and video impersonation.