Prerequisites
Tutorial 17: Audio intelligence: location and context from sound.
01
Synthetic media fails in ways that authentic media does not
A video clip lands in your inbox. The subject is a politician, a source, a suspect. The content is explosive. Before it moves anywhere, you need to answer one question: is the media authentic? Deepfake detection gives you a structured method for answering it, grounded in the physical and statistical properties of real versus synthetic media.
AI-generated video and audio now circulate routinely in conflict zones, election campaigns and financial fraud. The production barrier has collapsed: a convincing voice clone costs nothing and takes minutes. A face-swap that would have required a studio in 2019 now runs on a consumer laptop. The investigative consequence is that any unverified media (video, audio, image) must be treated as potentially synthetic until the evidence says otherwise.
Deepfake detection is not a single test. It is a layered workflow that combines tool-based scoring, human perceptual analysis and provenance interrogation. No single detector is definitive; each operates on a different signal class and each can be defeated by a sufficiently motivated adversary. The value of the method is in corroboration across layers: a clip that passes one test but fails three others warrants a different editorial judgement than one that fails all four.
In the field
Two days before Slovakia's September 2023 parliamentary election, an audio clip circulated on Facebook, Instagram and Telegram purporting to record a phone call between opposition leader Michal Šimečka and journalist Monika Tódová from Denník N, discussing ballot manipulation. Both subjects immediately denied it. AFP fact-checker Robert Barca, who monitors Slovak Facebook content, identified manipulation artefacts in the recording, including unnatural diction, pauses and tone of voice, and traced its spread to an anonymous Telegram account. AFP flagged the posts to Meta before the election.
- Audio analysis. AFP identified modification artefacts in the waveform inconsistent with a natural phone recording, including unnatural prosody transitions and pauses at speaker turn boundaries.
- Provenance gap. The clip's earliest traceable appearance was an anonymous Telegram account with no publication trail, a pattern consistent with coordinated inauthentic behaviour rather than a leaked recording.
AFP Fact Check · Slovakia parliamentary election · September 2023
Note: a separate Slovak deepfake clip that same week (Progressive Slovakia leader Šimečka discussing beer prices) was verified by fact-checking organisation Demagog, whose team contacted ElevenLabs directly for expert comment on the synthesis fingerprint. That ElevenLabs consultation applied to the beer-prices clip, not the ballot-manipulation clip described above; the two are documented separately and should not be conflated.
Learning outcomes
By the end of this tutorial you will be able to:
Identify the visual, acoustic and statistical artefact classes that distinguish synthetic media from authentic recordings.
Run a structured deepfake detection workflow across video and audio using four free or low-cost tools.
Interpret detection scores correctly, including the limitations and failure modes of each tool.
Conduct a provenance interrogation to establish whether a clip has a traceable origin.
Document detection findings to an evidential standard that supports editorial or legal review.
This tutorial is for Signal subscribers.
Methods goes deep on a single technique each fortnight. The decision framework, the tools, the failure modes, and the evidentiary standard required to use the finding defensibly.
Join SignalA Signal subscription gives you:
- Full OSINT Reference Card library
- Methods, all tradecraft tutorials in full
- Shadow Analysis, all evidence-based reporting
- Forensic Dossiers, full access
- Discord access included


