paper-with-me

Papers

Is It Possible to Backdoor Face Forgery Detection with Natural Triggers?

2023-12-31 · Xiaoxuan Han, Songlin Yang, Wei Wang, Ziwen He, Jing Dong

Deep neural networks have significantly improved the performance of face forgery detection models in discriminating Artificial Intelligent Generated Content (AIGC). However, their security is significantly threatened by the injection of triggers during model training (i.e., backdoor attacks). Although existing backdoor defenses and manual data selection can mitigate those using human-eye-sensitive triggers, such as patches or adversarial noises, the more challenging natural backdoor triggers remain insufficiently researched. To further investigate natural triggers, we propose a novel analysis-by-synthesis backdoor attack against face forgery detection models, which embeds natural triggers in the latent space. We thoroughly study such backdoor vulnerability from two perspectives: (1) Model Discrimination (Optimization-Based Trigger): we adopt a substitute detection model and find the trigger by minimizing the cross-entropy loss; (2) Data Distribution (Custom Trigger): we manipulate the uncommon facial attributes in the long-tailed distribution to generate poisoned samples without the supervision from detection models. Furthermore, to completely evaluate the detection models towards the latest AIGC, we utilize both state-of-the-art StyleGAN and Stable Diffusion for trigger generation. Finally, these backdoor triggers introduce specific semantic features to the generated poisoned samples (e.g., skin textures and smile), which are more natural and robust. Extensive experiments show that our method is superior from three levels: (1) Attack Success Rate: ours achieves a high attack success rate (over 99%) and incurs a small model accuracy drop (below 0.2%) with a low poisoning rate (less than 3%); (2) Backdoor Defense: ours shows better robust performance when faced with existing backdoor defense methods; (3) Human Inspection: ours is less human-eye-sensitive from a comprehensive user study.

📄 PDF Abstract BibTeX arXiv:2401.00414

Code (0)

등록된 구현이 없습니다.

Tasks

Backdoor Attackbackdoor defense

Methods 이 논문이 사용한 방법론

HuMan(Expedia)||How do I get a human at Expedia? How do I get a human at Expedia? How Do I Get a Human at Expedia? – Call ☎️ +1-(888) 829 (0881) or +1-805-330-4056 or +1-805-330-4056 for Real-Time Help & Exclusive…
Adaptive Instance Normalization 설명 없음
R1 Regularization R_INLINE_MATH_1 Regularization is a regularization technique and gradient penalty for training [generative adversarial…
Convolution A convolution is a type of matrix operation, consisting of a kernel, a small matrix of weights, that slides over input data performing element-wise multiplication with the…
Dense Connections Dense Connections, or Fully Connected Connections, are a type of layer in a deep neural network that use a linear operation where every input is connected to every output…
Diffusion Diffusion models generate samples by gradually removing noise from a signal, and their training objective can be expressed as a reweighted variational lower-bound…
Feedforward Network A Feedforward Network, or a Multilayer Perceptron (MLP), is a neural network with solely densely connected layers. This is the classic neural network architecture of the…
StyleGAN 설명 없음

Similar Papers 제목 키워드 기반

Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery Detection

2024-02-18 · Jiawei Liang, Siyuan Liang, Aishan Liu, Xiaojun Jia 외

The proliferation of face forgery techniques has raised significant concerns within society, thereby motivating the development of face forgery detection methods. These methods aim to distinguish forged faces from genuin…

Backdoor Attack

A Large-scale Universal Evaluation Benchmark For Face Forgery Detection

2024-06-13 · Yijun Bei, Hengrui Lou, Jinsong Geng, Erteng Liu 외

With the rapid development of AI-generated content (AIGC) technology, the production of realistic fake facial images and videos that deceive human visual perception has become possible. Consequently, various face forgery…

DiversityFace GenerationFairness

Forensics Adapter: Adapting CLIP for Generalizable Face Forgery Detection

2025-01-01 · CVPR 2025 1 · Xinjie Cui, Yuezun Li, Ao Luo, Jiaran Zhou 외

We describe the Forensics Adapter, an adapter network designed to transform CLIP into an effective and generalizable face forgery detector. Although CLIP is highly versatile, adapting it for face forgery detection is…

Forensics Adapter: Unleashing CLIP for Generalizable Face Forgery Detection

2024-11-29 · Xinjie Cui, Yuezun Li, Delong Zhu, Jiaran Zhou 외

We describe Forensics Adapter, an adapter network designed to transform CLIP into an effective and generalizable face forgery detector. Although CLIP is highly versatile, adapting it for face forgery detection is non-tri…

Prompt Learning

Leveraging Real Talking Faces via Self-Supervision for Robust Forgery Detection

2022-01-18 · CVPR 2022 1 · Alexandros Haliassos, Rodrigo Mira, Stavros Petridis, Maja Pantic

One of the most pressing challenges for the detection of face-manipulated videos is generalising to forgery methods not seen during training while remaining effective under common corruptions such as compression. In this…

DeepFake Detection