Deepfake-as-a-Service: Governance Frameworks, Software Quality Engineering, and Organizational Resilience in the Age of Synthetic Media
*** PREPRINT / AUTHOR-ACCEPTED VERSION ***This paper was presented at the conference and is the author-accepted camera-ready version. It is posted here for self-archiving purposes in accordance with the IEEE Author Posting Policy prior to official publication and indexing in IEEE Xplore. Abstract—Deepfake-as-a-Service (DaaS) has matured from a real-time impersonation threat into an upstream data-integrity threat that reaches directly into the training pipelines of collaborative and federated AI systems. This paper extends prior work on DaaS as a cybersecurity and Software Quality Engineering (SQE) problem to the distributed machine-learning (ML) setting, where synthetic audio, video, and image content generated by commercial DaaS infrastructure can be ingested — deliberately or incidentally — as training or fine-tuning data by multi-party model-development pipelines. We report the trajectory of DaaS-enabled activity, with circulating deepfake files rising from approximately 500,000 in 2023 to approximately 8 million in 2025, and document how the same commercial infrastructure that enabled the $25.6 million Arup deepfake-video fraud can be repurposed to poison collaborative training corpora with unverified synthetic identities. Building on COBIT 2019 (Control Objectives for Information and Related Technology), the NIST AI Risk Management Framework, and Risk-Based Quality Engineering (RBQE) principles, we introduce the PROOF Framework — Provenance, Robustness, Oversight, Observability, and Forensic auditability — a five-pillar auditing methodology purpose-built for verifying the integrity of synthetic and human-sourced training data as it moves through distributed, multi-vendor ML pipelines. Our contributions are: (1) a vendor and pipeline risk-assessment checklist for DaaS and collaborative-AI data sources mapped to COBIT 2019 and NIST AI RMF control references; (2) an operational instantiation of the PROOF Framework combining security-injection testing, Zero Trust content verification, and Human-in-the-Loop (HITL) escalation logic for distributed pipeline auditing; (3) practitioner guidance for governance, risk, compliance, and software-engineering teams operating collaborative AI systems across jurisdictions; and (4) an explicit validation roadmap, presented in Section VI-F, defining the pilot-study design, benchmark datasets, and success metrics through which future work will empirically evaluate the framework, since the contributions above are presented at the methodological and architectural level rather than as a deployed implementation.
Authors
- Kiran Paul Kanikaram (ORCID: https://orcid.org/0009-0004-5146-3993)
- Akanksha Raghvesh (ORCID: https://orcid.org/0009-0001-9233-2234)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-26
- DOI
- https://doi.org/10.5281/zenodo.22981864
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- preprint