What Is Deepfake as a Service for Security Training?
Most guidance on defending against Deepfake as a Service assumes security training can teach employees to detect synthetic media well enough to protect themselves. A growing body of peer-reviewed research on human deepfake detection accuracy suggests this assumption does not hold, and that certain forms of “awareness” training may be actively counterproductive. This paper reviews that research, examines a specific confidence-accuracy gap with direct implications for training design, and argues that effective security training in this area needs to shift from detection skill toward verification behavior that does not depend on correctly judging whether media is real.
1. Introduction
Deepfake as a Service refers to the on-demand, outsourced provision of AI-generated impersonation, synthetic voice, video, or identity documents, sold or rented by criminal marketplaces or misused commercial platforms. Prior work has examined what this means for fraud broadly and for voice and video phishing specifically. This paper asks a narrower, training-focused question: given what is actually known about human ability to detect synthetic media, what should a security training program teach, and what should it stop teaching?
Section 2 briefly restates why Deepfake as a Service is training-relevant. Section 3 reviews the research literature on human detection accuracy. Section 4 examines a confidence-accuracy gap with specific implications for how training content is designed. Section 5 outlines what training and compliance programs should teach instead. Section 6 states this paper’s limitations. Section 7 concludes.
2. Why Deepfake as a Service Changes the Training Problem
Security awareness training has historically treated social engineering detection as a learnable skill: recognize a suspicious link, notice a spoofed domain, spot an urgency cue in an email. Deepfake as a Service does not present the same kind of learnable signal. A cloned voice or a real-time face-swapped video call does not contain a misspelled domain or a suspicious header; it contains a voice or face that, to the target, sounds or looks correct. The training question this raises is empirical, not motivational: can a person be trained to reliably tell the difference, given enough examples and enough warning?
3. Can People Be Trained to Spot Deepfakes? What the Research Shows
The available evidence says, largely, no. A systematic review and meta-analysis of 56 studies involving 86,155 participants, published in Computers in Human Behavior Reports, found that overall human accuracy in detecting deepfakes averages 55.54 percent across modalities, barely better than chance. For high-quality deepfake video specifically, research by Korshunov and Marcel found human detection accuracy of approximately 24.5 percent, meaningfully worse than the 50 percent a coin flip would produce. Detection accuracy for deepfake images, a comparatively less sophisticated form of synthetic media, was somewhat better at 62 percent, though still leaving a large error rate.

A University of Florida study published in February 2026 adds a specific and unsettling detail: participants classified deepfake images at a rate statistically indistinguishable from chance, and misclassified deepfake images as real 69 percent of the time, a pattern the researchers labeled “truth bias,” the default human tendency to assume that what is seen is genuine. In the same study, a convolutional neural network model achieved 97 percent accuracy on the identical images humans could not reliably judge, underscoring that the gap here is not a lack of effort or attention; it is a gap in what unaided human perception can do with this specific kind of content.
4. The Confidence Problem: Why Awareness Alone Can Backfire
A 2025 iProov study of 2,000 UK and U.S. consumers found that only 0.1 percent of participants correctly identified every piece of synthetic and real media shown to them, despite being explicitly told in advance to watch for deepfakes. In the same study, approximately 60 percent of participants reported feeling confident in their judgments.

This gap matters specifically for training design. A training module that shows employees a handful of deepfake examples and lists visual or auditory “tells” to watch for can plausibly increase confidence without proportionally increasing accuracy, since the research above suggests the underlying detection task is close to unlearnable through brief exposure. Separate research on the “illusory truth effect” has found that repeated exposure to synthetic content increases its perceived credibility over time, even among people who have been told the content may be fabricated, and a related phenomenon researchers call the “liar’s dividend” describes how the mere existence of convincing fakes makes it easier for people to dismiss genuine evidence as fabricated. Together, this suggests a training program optimized for the wrong outcome, employee confidence rather than employee accuracy, could leave an organization more exposed than a program that never addressed deepfakes at all, by producing employees who feel equipped to judge authenticity and are not.
5. What Security Training Should Teach Instead
Given Sections 3 and 4, a training curriculum built around teaching detection skill is training toward a capability the underlying research does not support. The more defensible design goal is training employees and codifying, for compliance purposes, verification behavior that does not require judging whether a voice, face, or document is authentic at all.
Concretely, this means training that emphasizes out-of-band verification for any high-risk request, initiating contact through an independently known channel rather than responding within the same call or message, regardless of how convincing that call or message seemed. It means explicit permission, ideally stated as policy rather than left to individual judgment, to pause and verify an unusual request from a senior executive without treating that pause as a breach of deference or professionalism, since social pressure not to question a “boss” on a call is a documented factor in successful vishing and video-vishing incidents. It means training scenarios built around recognizing situational risk factors, urgency, financial authorization, deviation from normal process, rather than perceptual cues in the media itself. For compliance teams specifically, this shifts the deliverable from a training completion metric to a verification procedure that can be audited: not “employees were shown examples of deepfakes,” but “high-risk transactions require verification through a channel independent of the request itself.”
6. Limitations and Open Questions
The detection-accuracy research summarized in Section 3 was conducted primarily under controlled study conditions, showing participants a series of media samples and asking them to judge authenticity. This differs from a real, targeted attack, where a specific victim has contextual trust in the caller’s identity and no framing that primes suspicion. It is plausible that real-world detection rates in a targeted social engineering attempt are worse than laboratory figures suggest, not better, since study participants are, by design, primed to expect some fakes.
Second, this paper’s recommendation in Section 5, to shift training toward procedural verification rather than detection skill, is a reasonable inference from the detection-accuracy literature, but it is not itself directly validated by a rigorous study measuring whether procedural training reduces successful deepfake-enabled social engineering in practice. Most existing security-training-effectiveness research measures outcomes for email phishing simulations, not deepfake-specific interventions, and this paper is not aware of an equivalent, rigorously measured deepfake-specific training outcome study as of this writing.
Third, study populations in the detection-accuracy research (general consumers in the iProov study, broad participant pools in the meta-analysis) may not directly represent trained enterprise employees who have already received baseline security awareness training, and detection accuracy could plausibly differ, in either direction, for that more specific population.
7. Conclusion
Peer-reviewed research on human deepfake detection accuracy, converging across a large meta-analysis and multiple independent studies, indicates that people cannot reliably distinguish synthetic media from authentic media, even when actively trying and even when warned in advance. A training program built around teaching this discrimination skill is training toward a capability the evidence does not support, and a specific, documented confidence-accuracy gap suggests such training can increase false confidence without a corresponding increase in actual detection ability. The more defensible design for both security training content and compliance-codified procedure is verification behavior that does not depend on judging the authenticity of a voice, face, or document at all.
References
- Systematic review and meta-analysis of 56 papers. Human performance in detecting deepfakes. Computers in Human Behavior Reports, 2024.
- Korshunov, P., and Marcel, S. Research on human detection accuracy for high-quality deepfake video.
- University of Florida. Study on human classification accuracy for deepfake images, February 2026.
- iProov. Deepfake Detection Study 2025 (n=2,000, UK and U.S. consumers).
- World Economic Forum. Why Detecting Dangerous AI Is Key to Keeping Trust Alive, 2025 (cited research on commercial detection tool degradation in real-world deployment).
Frequently Asked Questions
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /