paper-with-me

Papers

Active Adversarial Noise Suppression for Image Forgery Localization

2025-06-15 · Rongxuan Peng, Shunquan Tan, Xianbo Mo, Alex C. Kot, Jiwu Huang

Recent advances in deep learning have significantly propelled the development of image forgery localization. However, existing models remain highly vulnerable to adversarial attacks: imperceptible noise added to forged images can severely mislead these models. In this paper, we address this challenge with an Adversarial Noise Suppression Module (ANSM) that generate a defensive perturbation to suppress the attack effect of adversarial noise. We observe that forgery-relevant features extracted from adversarial and original forged images exhibit distinct distributions. To bridge this gap, we introduce Forgery-relevant Features Alignment (FFA) as a first-stage training strategy, which reduces distributional discrepancies by minimizing the channel-wise Kullback-Leibler divergence between these features. To further refine the defensive perturbation, we design a second-stage training strategy, termed Mask-guided Refinement (MgR), which incorporates a dual-mask constraint. MgR ensures that the perturbation remains effective for both adversarial and original forged images, recovering forgery localization accuracy to their original level. Extensive experiments across various attack algorithms demonstrate that our method significantly restores the forgery localization model's performance on adversarial images. Notably, when ANSM is applied to original forged images, the performance remains nearly unaffected. To our best knowledge, this is the first report of adversarial defense in image forgery localization tasks. We have released the source code and anti-forensics dataset.

📄 PDF Abstract BibTeX arXiv:2506.12871

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial Defense

Similar Papers 제목 키워드 기반

ForensicsSAM: Toward Robust and Unified Image Forgery Detection and Localization Resisting to Adversarial Attack

2025-08-10 · Rongxuan Peng, Shunquan Tan, Chenqi Kong, Anwei Luo 외 arxiv

Parameter-efficient fine-tuning (PEFT) has emerged as a popular strategy for adapting large vision foundation models, such as the Segment Anything Model (SAM) and LLaVA, to downstream tasks like image forgery detection a…

parameter-efficient fine-tuningAdversarial RobustnessAdversarial Attack

Counterfactual Explanations for Face Forgery Detection via Adversarial Removal of Artifacts

2024-04-12 · Yang Li, Songlin Yang, Wei Wang, Ziwen He 외

Highly realistic AI generated face forgeries known as deepfakes have raised serious social concerns. Although DNN-based face forgery detection models have achieved good performance, they are vulnerable to latest generati…

Adversarial Attackcounterfactual

Self-Adversarial Training incorporating Forgery Attention for Image Forgery Localization

2021-07-06 · Long Zhuo, Shunquan Tan, Bin Li, Jiwu Huang

Image editing techniques enable people to modify the content of an image without leaving visual traces and thus may cause serious security risks. Hence the detection and localization of these forgeries become quite neces…

Evading Detection Actively: Toward Anti-Forensics against Forgery Localization

2023-10-16 · Long Zhuo, Shenghai Luo, Shunquan Tan, Han Chen 외

Anti-forensics seeks to eliminate or conceal traces of tampering artifacts. Typically, anti-forensic methods are designed to deceive binary detectors and persuade them to misjudge the authenticity of an image. However, t…

Adversarial AttackSelf-Supervised Learning

Dual Defense: Adversarial, Traceable, and Invisible Robust Watermarking against Face Swapping

2023-10-25 · Yunming Zhang, Dengpan Ye, Caiyun Xie, Long Tang 외

The malicious applications of deep forgery, represented by face swapping, have introduced security threats such as misinformation dissemination and identity fraud. While some research has proposed the use of robust water…

Face SwappingMisinformation