paper-with-me

Papers

Exploring Decision-based Black-box Attacks on Face Forgery Detection

2023-10-18 · Zhaoyu Chen, Bo Li, Kaixun Jiang, Shuang Wu, Shouhong Ding, Wenqiang Zhang

Face forgery generation technologies generate vivid faces, which have raised public concerns about security and privacy. Many intelligent systems, such as electronic payment and identity verification, rely on face forgery detection. Although face forgery detection has successfully distinguished fake faces, recent studies have demonstrated that face forgery detectors are very vulnerable to adversarial examples. Meanwhile, existing attacks rely on network architectures or training datasets instead of the predicted labels, which leads to a gap in attacking deployed applications. To narrow this gap, we first explore the decision-based attacks on face forgery detection. However, applying existing decision-based attacks directly suffers from perturbation initialization failure and low image quality. First, we propose cross-task perturbation to handle initialization failures by utilizing the high correlation of face features on different tasks. Then, inspired by using frequency cues by face forgery detection, we propose the frequency decision-based attack. We add perturbations in the frequency domain and then constrain the visual quality in the spatial domain. Finally, extensive experiments demonstrate that our method achieves state-of-the-art attack performance on FaceForensics++, CelebDF, and industrial APIs, with high query efficiency and guaranteed image quality. Further, the fake faces by our method can pass face forgery detection and face recognition, which exposes the security problems of face forgery detectors.

📄 PDF Abstract BibTeX arXiv:2310.12017

Code (0)

등록된 구현이 없습니다.

Tasks

Face Recognition

Similar Papers 제목 키워드 기반

Exploring Frequency Adversarial Attacks for Face Forgery Detection

2022-03-29 · CVPR 2022 1 · Shuai Jia, Chao Ma, Taiping Yao, Bangjie Yin 외

Various facial manipulation techniques have drawn serious public concerns in morality, security, and privacy. Although existing face forgery classifiers achieve promising performance on detecting fake images, these metho…

Adversarial AttackMeta-Learning

SemBind: Binding Diffusion Watermarks to Semantics Against Black-Box Forgery Attacks

2026-01-28 · Xin Zhang, Zijin Yang, Kejiang Chen, Linfeng Ma 외 arxiv

Latent-based watermarks, integrated into the generation process of latent diffusion models (LDMs), simplify detection and attribution of generated images. However, recent black-box forgery attacks, where an attacker need…

Contrastive Learning

Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery Detection

2024-02-18 · Jiawei Liang, Siyuan Liang, Aishan Liu, Xiaojun Jia 외

The proliferation of face forgery techniques has raised significant concerns within society, thereby motivating the development of face forgery detection methods. These methods aim to distinguish forged faces from genuin…

Backdoor Attack

Rethinking Forgery Attacks on Semantic Watermarks in Black-Box Settings: A Geometric Distortion Perspective

2026-06-29 · Cheng-Yi Lee, Yichi Zhang, Yuchen Yang, Chun-Shien Lu 외 arxiv

Recent studies have shown that semantic watermarks, which embed information into the initial noise of latent diffusion models (LDMs), are vulnerable to black-box forgery attacks. However, existing methods primarily rely …

Hierarchical Forgery Classifier On Multi-modality Face Forgery Clues

2022-12-30 · Decheng Liu, Zeyang Zheng, Chunlei Peng, Yukai Wang 외

Face forgery detection plays an important role in personal privacy and social security. With the development of adversarial generative models, high-quality forgery images become more and more indistinguishable from real …

Multi-Label ClassificationMUlTI-LABEL-ClASSIFICATION