Host: Hello everyone, welcome back to another insightful session of ExtraMile by SecureITWorld, your hub for expert-led cybersecurity insights. Here we discuss leading tech cybersecurity practices, tactics, and advancements. I’m your host, Rittika, and for this conversation, I’m delighted to introduce our guest, Nicos Vekiarides, the CEO of the leading AI-powered digital file validation platform, Attestiv.
The firm helps users detect and validate AI-generated files and defects while enhancing customer experience and trust. Nicos is a tech leader and entrepreneur with expertise across AI, blockchain, cloud storage, and others. Let’s get started with this conversation and explore the importance of file validation while maintaining data integrity, the impact of digital media transparency, and more.
Welcome, Nicos. We are super excited to have you with us today.
Nicos: Well, thank you. It’s nice to be here.
Host: Yeah. So, you spent over two decades building enterprise AI infrastructures and data protection startups. So, according to you, which factors contribute to successful startups?
Nicos: Well, there’s a few factors, certainly it’s team. Having that team chemistry is super important. There’s market timing, and some people say that’s a little bit of luck, and that’s true.
And then of course, there has to be some resilience because it’s always a long journey, and along that journey, you have to kind of have this humility where you can realize that you’re wrong and pivot because otherwise it’s very hard to succeed.
Host: Okay. That is an amazing approach on building successful startups, I must say.
Next up, data integrity is at stake today with the evolution of sophisticated threats such as AI deception, deepfakes, and others. How does AI-powered digital file validation safeguard data and its integrity in this regard?
Nicos: Well, it used to be the data protection and I’ve been in data protection for many years, but it used to be that data protection was simply protecting your data and your system, and now it’s changed. Is this data real? Has it been manipulated in some way?
And in order to address that, you need automation and you need AI and that’s where validation comes in and it actually aggregates signals about your data and then allows you to make decisions on whether this data is suitable for a particular purpose.
Host: Absolutely. Sustaining data integrity in the digital era is crucial. So, moving ahead, you have discussed that only detection is an orthodox but outdated method to tackle deepfakes.
How does validation alongside detection offer a holistic approach for this purpose?
Nicos: Well, detection is a signal. So, if you’re looking for something like a deepfake, that’s one signal that tells you something might be fraudulent. On the other hand, we look at many signals.
So, there’s many signals, for instance, there’s signals that something was reused, there’s signals that something might have been photoshopped, there’s signals that it could be manipulated in other ways, there’s actually numerical errors, there’s all sorts of things that say, hey, there’s something wrong with this image, there’s something wrong with this document. So essentially, we have this holistic approach that aggregates all of these signals and turns it into a decision process that tells us, hey, what about this particular file makes it unsuitable and what’s the next step? And with AI, we can actually start to do that human in the loop translation and say, what is the next step?
Should we escalate this? If it’s an insurance claim, should we actually go back and ask for more photos? Or is there a third path that we should take?
Host: Yeah, absolutely. Detection alongside validation surely tackles deepfakes. So next up, generative AI tools evolve every week.
What specific internal engineering framework or workflow do you use to ensure Attestiv’s detection models do not become obsolete the moment new open-source generator arrives?
Nicos: We look at this in three ways. One is we’re constantly building models in-house that address this. So, we’re looking at the new threats and we’re building models that are able to do this.
The second way that we address this is we’re leveraging the best of off-the-shelf technology. That could be C2PA credentials. So, whenever something in the C2PA credentials change that can help us, we leverage that.
We recently announced that we’re leveraging Google’s deepfake detection. So that’s another piece that provides another signal into our product. And then the third way is simply, we also utilize Gen AI as the orchestrator.
And Gen AI is a very powerful visual model that continues to improve over time. So, we have three specific technologies that we put to work and they’re all moving at a very fast trajectory. And that keeps us ahead of the game, including hundreds of signals that might indicate fraud.
Host: Yeah, indeed a commendable approach to staying aligned with the evolving generative AI models. Moving ahead, Attestiv has recently launched the automated file validation platform DeepScan.
Which core capabilities of the platform will help organizations in file validation and making critical business decisions? And can you share specific use cases in this regard?
Nicos: So really there’s three parts of the platform. One is the forensic analysis and that gives you the signals. But beyond that, there’s the ability for our customers to put in their own business rules.
Because what might seem fraudulent to one party might be different for, in a different use case. And then finally, we correlate against data that the customer already has. So, think of if it’s an insurance company in a claim file.
So, if you put it all together, if you’re an insurance company and you’re processing claims, now you can have specific rules that say, hey, here’s a photo. We think the signals say, hey, this might have been modified. But then I have my business rules which say, well, if it was modified with annotations that highlight where this vehicle was damaged, then maybe I should ignore those.
So, then we start to look around those and say, okay, what else in the photo might be a problem? And then finally, it’s correlating it to the information you already had. So, let’s say this claim was filed in March, but these photos you’re sending me are from January.
So now there’s something wrong there. So, we put it all together and then we determine the best course of action. And that’s exactly how we’re used in the insurance industry.
But we are applicable to other industries, financial services, loan underwriting, anything that requires photos, proof of condition, validating the condition of an asset.
Host: That is amazing. And our next question is about financial and insurance claims only. So how financial and insurance claims engines are excessively fragile?
And what specific technical friction point continually emerges when integrating validation APIs into legacy corporate infrastructure? And how can Attestiv address this friction and ensure continuous validation?
Nicos: Well, that is a real challenge. And this is our startup in the insurance space. So, it was a surprise to us that we see systems that are installed, but all of the implementations of the same system are sometimes different across customers.
So, it makes integration relatively challenging. So, what we do is we have our own APIs. Sometimes we have to come in at the point of intake.
Sometimes we have to come in at the point of escalation. But that’s a starting point so that customers can start using us and see the value that we bring. And then finally, we are doing a lot of integrations into products that customers are already using.
And then once we integrate into those products, it is a very easy process because they simply flip a switch and enable us. That’s the goal. But in order to address this, we have to provide multiple different ways to integrate, and we have to make it easy for our customers.
Host: Yeah. The financial sector is among the industries that require continuous validation. So, moving further, digital media transparency has become a prime component for organizations.
How does adding content credentials and metadata help here, and what are the other best practices?
Nicos: Certainly, content credentials are a good practice. So, you can integrate those into every, let’s say, image or every document. That helps a lot.
But on the other hand, a lot of our customers, they’re looking at data that’s coming in externally from the outside world. It could be from claimants, it could be from customers, from their customers. But that means there is no single source that they come from.
So, while they become a useful tool, they’re not something that we can depend on. The same holds true, as a lot of our customers sometimes have this method of simply controlling the application that captures. So essentially, it makes it less likely to be manipulated.
But then even then, there’s still ways to manipulate. So, if they force you to use your phone to take a photo, you can still aim the phone at a monitor at your screen, and you can take photos that way. So that’s why there always has to be a need for checking for different forms of manipulation, and that’s where we come in.
But these credentials do help us. They certainly don’t hurt. But until they become standard across the whole industry, we can’t always depend on them.
Host: Yeah. And in the AI era, maintaining digital media transparency is unignorable. So lastly, not all synthetic media are malicious.
Enterprises use generative AI for marketing, localized video, and automated workflows. How do you architect a detection platform that can accurately differentiate between malicious and business-approved media?
Nicos: That really hits to the heart of the matter. I’ll tell you a quick story is when we first started this, we went into a customer, and we are a POC, and we found that 30% of their images that they were using were manipulated in some way. And of course, we went back, and we said, well, how do we say this in a tactful way that 30% of your images are bad?
So, we thought we were being tactful, and we said, well, is there any way you can fix these images so that they don’t have these manipulations? Maybe you can get them earlier in the process. And interestingly, that ended the engagement just as fast as if we told them all their data was bad.
So, we learned a very quick lesson from that, which is our product has to look around these purposeful manipulations. And at the end of the day, you might see generative AI in all photos because cameras will have that capability. So that means we have to examine these types of what would be anomalies and ignore them.
And that’s really the heart of our system. We have tuning, we have calibration, we have ways of ignoring what’s purposeful manipulation versus malicious changes to the photos. So, it could be things like annotations.
It could be things like heat maps that a customer might put on the photos. Most customers like to compress their photos because they save space. So, IT people love to save space.
So, we always are looking around manipulations. And that’s a great question because that’s the heart of our product. With our calibration, we can do that very well.
Host: It is truly complex to differentiate between malicious and purposeful media, but your approach is truly incredible. So, thank you, Nicos, for joining us and sharing your thoughts on file validation, deepfakes, and digital media transparency. It was quite a valuable and insightful session for us and our audience. Thank you so much.
Nicos: Thank you.
Host: And to our viewers, thank you for watching today’s session. Stay tuned with ExtraMile by SecureITWorld for more expert-led conversations.
Explore Our Other Insightful Interview:


















