OTHER

Google Enhances AI-Powered Fraud Detection and Security Initiatives in India

Google has rolled out its Safety Charter in India, focusing on enhancing AI-driven efforts to combat fraud and scam prevention across the country, which ranks as its largest market outside the United States.

The threat of digital fraud is escalating in India. Government statistics reveal that fraud tied to the country’s UPI instant payment system has skyrocketed by 85% year-on-year, totaling nearly 11 billion Indian rupees ($127 million) last year. India is also a hotspot for various digital scams, including cases where fraudsters impersonate officials to extort money via video calls and predatory loan applications.

To address these challenges, Google has launched its Safety Charter. Additionally, the company has opened a security engineering center in India, its fourth worldwide, following centers in Dublin, Munich, and Malaga.

Launched during the Google for India summit last year, the security engineering center (GSec) aims to forge partnerships with local communities, including government agencies, academic institutions, students, and small to medium enterprises, focusing on developing solutions for cybersecurity, privacy, safety, and AI challenges, as mentioned by Google VP of security engineering Heather Adkins in an interview with TechCrunch.

Google has also partnered with the Ministry of Home Affairs’ Indian Cyber Crime Coordination Centre (I4C) to raise public awareness about cybercrimes, as detailed in a company blog post. This effort builds on prior initiatives, including the introduction of DigiKavach, an online fraud detection program launched in 2023 aimed at minimizing the adverse effects of harmful financial applications and predatory lending.

According to Adkins, Google’s GSec in India will focus on three key areas: combating online scams and fraud while ensuring user safety, enhancing cybersecurity for enterprises, government, and critical infrastructure, and promoting responsible AI development.

“These three focus areas will be integrated into our safety charter for India, and in the coming years… we plan to harness our engineering capabilities here to tackle local challenges, close to where our users are,” Adkins stated.

Globally, Google is utilizing AI to combat online scams and has removed millions of ads and ad accounts. The company plans to implement AI more extensively in India to fight digital fraud.

Google Messages, preinstalled on many Android devices, uses AI-powered Scam Detection to effectively protect users from over 500 million potentially suspicious messages each month. Similarly, Google introduced Play Protect in India last year, claiming it has blocked nearly 60 million attempts to install high-risk apps, preventing over 220,000 unique applications across more than 13 million devices. Google Pay, one of India’s top UPI-based payment apps, issued 41 million alerts for transactions believed to be potentially fraudulent.

Adkins, a founding member of Google’s security team with over 23 years in the company, discussed various topics during her TechCrunch interview:

She emphasized the critical importance of monitoring the use and potential misuse of AI by malicious actors.

“We’re closely observing AI, and so far, we’ve mainly seen large language models like Gemini being used as productivity enhancers. For example, these tools can make phishing scams more effective, especially when different languages are involved, using translation to lend credibility to scams through deepfakes, images, and videos,” said Adkins.

Google is rigorously testing its AI models to ensure they detect inappropriate actions.

“This is crucial for generated content that may be harmful, as well as for their actions,” Adkins emphasized.

Google is devising frameworks such as the Secure AI Framework to reduce the risk of abuse associated with its Gemini models. Nonetheless, to prevent generative AI from future exploitation by hackers, the company advocates for a framework governing the interactions of multiple agents.

“The industry is evolving rapidly, much like the early internet days when everyone shared code in real-time, with safety considerations coming later,” Adkins remarked.

Google aims for collaboration rather than merely imposing its frameworks to prevent hackers from exploiting generative AI. Instead, Adkins indicated that the company is engaging with the research community and developers.

“One of the key considerations is to avoid over-constraining ourselves in the early stages of research,” Adkins noted.

On surveillance vendors

Alongside the risk of generative AI misuse, Adkins highlights commercial surveillance vendors as a significant threat. This includes spyware developers like NSO Group, infamous for its Pegasus spyware, as well as smaller firms that provide surveillance technology.

“These companies are proliferating globally, creating and marketing platforms for hacking,” Adkins explained. “Prices can range from $20 to $200,000, depending on the platform’s complexity, allowing attackers to target individuals without needing specialized skills.”

Some of these vendors also offer espionage tools in markets like India. However, the country faces unique challenges due to its size, experiencing not just AI-driven deepfakes and voice cloning scams, but also cases of digital arrests, which Adkins describes as standard scams adapted for the digital environment.

“You can observe how quickly threat actors are evolving… I find studying cybersecurity in this region interesting as it often forecasts what we can expect on a global scale,” Adkins noted.

On multi-factor authentication

Google has consistently advocated for users to embrace more secure authentication methods beyond traditional passwords to protect their online identities. The company has enabled multi-factor authentication (MFA) for all user accounts and promotes the use of hardware-based security keys, as Adkins pointed out, noting that employees frequently use these on their laptops. The term passwordless is gaining traction in technology, though it carries various meanings.

However, expecting users in a diverse market like India to fully abandon passwords is challenging due to the country’s extensive demographics and differing economic contexts.

“We have long recognized that passwords are insecure. The introduction of multi-factor authentication marked significant progress,” Adkins stated, adding that SMS-based authentication may be the preferred method among Indian users compared to other MFA options.