Cloudflare, Google top deepfake abuse infrastructure study
TL;DR
- A peer-reviewed Stanford Journal of Online Trust and Safety paper identifies 88 active sites distributing AI-generated non-consensual intimate imagery.
- Five providers dominate the stack: Cloudflare, Google, Namecheap, WordPress and Proton, with Cloudflare supplying 'the lion's share of services.'
- The 40 most-visited deepfake sites have drawn over 4 billion views, and 93% of identified sites are discoverable through Google Search.
Researchers spent six weeks in February and March cataloguing where deepfake abuse sites actually live on the internet. Most of them, according to their paper in Stanford's Journal of Online Trust and Safety, live on the same five companies: Cloudflare, Google, Namecheap, WordPress and Proton. Cloudflare, 404 Media reports, provided "the lion's share of services," including hosting, content delivery networks, and domain-name servers.
The paper, "The Backbone of Abuse," is by Sarah Morgan and Sophie Nightingale of Lancaster University and Hany Farid of Dartmouth. Out of 400 URLs surfaced through keyword searches and Google Alerts, they narrowed to 88 sites actively distributing AI-generated non-consensual intimate imagery; 38 of those host nothing else. The 40 most-visited such sites have drawn more than four billion views, and 93% are discoverable through Google Search.
Targets, in the study's phrasing, are "female celebrities, actresses, pop singers, K-pop idols, and women working in politics or activism." "Anyone with a single photo online can be quickly and easily targeted" in false intimate content "without their consent," Morgan said.
Google told 404 Media: "We have strict policies against non-consensual explicit content — including AI-generated imagery — across all our products," pointing to takedown processes and algorithm adjustments that demote offending sites. WordPress replied that it is "open-source software, not a hosting provider," drawing the line between WordPress.org and WordPress.com; Farid pushed back that Automattic-operated WordPress.com hosts millions of sites and serves images through its infrastructure. Cloudflare, Proton and Namecheap did not respond to requests for comment.
The recommendation is direct: infrastructure providers should stop serving the identified sites, and should build verification systems with NGOs and governments so abuse sites are cut off further up the stack.
Shared on Bluesky by 2 AI experts
Originally reported by 404media.co
Read the original article →Original headline: Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds