paper-with-me

Papers

CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating Deepfakes

2021-05-23 · Hao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang, Yuheng Li, Zhi Tang, Wei Chu, Jingdong Chen, Weisi Lin, Kai-Kuang Ma

Malicious applications of deepfakes (i.e., technologies generating target facial attributes or entire faces from facial images) have posed a huge threat to individuals' reputation and security. To mitigate these threats, recent studies have proposed adversarial watermarks to combat deepfake models, leading them to generate distorted outputs. Despite achieving impressive results, these adversarial watermarks have low image-level and model-level transferability, meaning that they can protect only one facial image from one specific deepfake model. To address these issues, we propose a novel solution that can generate a Cross-Model Universal Adversarial Watermark (CMUA-Watermark), protecting a large number of facial images from multiple deepfake models. Specifically, we begin by proposing a cross-model universal attack pipeline that attacks multiple deepfake models iteratively. Then, we design a two-level perturbation fusion strategy to alleviate the conflict between the adversarial watermarks generated by different facial images and models. Moreover, we address the key problem in cross-model optimization with a heuristic approach to automatically find the suitable attack step sizes for different models, further weakening the model-level conflict. Finally, we introduce a more reasonable and comprehensive evaluation method to fully test the proposed method and compare it with existing ones. Extensive experimental results demonstrate that the proposed CMUA-Watermark can effectively distort the fake facial images generated by multiple deepfake models while achieving a better performance than existing methods.

📄 PDF Abstract BibTeX arXiv:2105.10872

Code (1)

vdigpku/cmua-watermark 공식 구현 pytorch

Tasks

Adversarial AttackFace SwappingModel Optimization

Similar Papers 제목 키워드 기반

Dual Defense: Adversarial, Traceable, and Invisible Robust Watermarking against Face Swapping

2023-10-25 · Yunming Zhang, Dengpan Ye, Caiyun Xie, Long Tang 외

The malicious applications of deep forgery, represented by face swapping, have introduced security threats such as misinformation dissemination and identity fraud. While some research has proposed the use of robust water…

Face SwappingMisinformation

Optimization-Free Universal Watermark Forgery with Regenerative Diffusion Models

2025-06-06 · Chaoyi Zhu, Zaitang Li, Renyi Yang, Robert Birke 외

Watermarking becomes one of the pivotal solutions to trace and verify the origin of synthetic images generated by artificial intelligence models, but it is not free of risks. Recent studies demonstrate the capability to …

Synthetic Data Generation

DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark

2024-04-23 · Yunming Zhang, Dengpan Ye, Caiyun Xie, Sipeng Shen 외

The wide deployment of Face Recognition (FR) systems poses privacy risks. One countermeasure is adversarial attack, deceiving unauthorized malicious FR, but it also disrupts regular identity verification of trusted autho…

Adversarial AttackDecoderFace Recognition

UnMarker: A Universal Attack on Defensive Image Watermarking

2024-05-14 · Andre Kassis, Urs Hengartner

Reports regarding the misuse of Generative AI (GenAI) to create deepfakes are frequent. Defensive watermarking enables GenAI providers to hide fingerprints in their images and use them later for deepfake detection. Yet, …

DeepFake DetectionDenoisingFace Swapping

Theoretically Grounded Framework for LLM Watermarking: A Distribution-Adaptive Approach

2024-10-03 · Haiyun He, Yepeng Liu, Ziqiao Wang, Yongyi Mao 외

Watermarking has emerged as a crucial method to distinguish AI-generated text from human-created text. In this paper, we present a novel theoretical framework for watermarking Large Language Models (LLMs) that jointly op…