paper-with-me

Papers

Making DeepFakes more spurious: evading deep face forgery detection via trace removal attack

2022-03-22 · Chi Liu, Huajie Chen, Tianqing Zhu, Jun Zhang, Wanlei Zhou

DeepFakes are raising significant social concerns. Although various DeepFake detectors have been developed as forensic countermeasures, these detectors are still vulnerable to attacks. Recently, a few attacks, principally adversarial attacks, have succeeded in cloaking DeepFake images to evade detection. However, these attacks have typical detector-specific designs, which require prior knowledge about the detector, leading to poor transferability. Moreover, these attacks only consider simple security scenarios. Less is known about how effective they are in high-level scenarios where either the detectors or the attacker's knowledge varies. In this paper, we solve the above challenges with presenting a novel detector-agnostic trace removal attack for DeepFake anti-forensics. Instead of investigating the detector side, our attack looks into the original DeepFake creation pipeline, attempting to remove all detectable natural DeepFake traces to render the fake images more "authentic". To implement this attack, first, we perform a DeepFake trace discovery, identifying three discernible traces. Then a trace removal network (TR-Net) is proposed based on an adversarial learning framework involving one generator and multiple discriminators. Each discriminator is responsible for one individual trace representation to avoid cross-trace interference. These discriminators are arranged in parallel, which prompts the generator to remove various traces simultaneously. To evaluate the attack efficacy, we crafted heterogeneous security scenarios where the detectors were embedded with different levels of defense and the attackers' background knowledge of data varies. The experimental results show that the proposed attack can significantly compromise the detection accuracy of six state-of-the-art DeepFake detectors while causing only a negligible loss in visual quality to the original DeepFake samples.

📄 PDF Abstract BibTeX arXiv:2203.11433

Code (0)

등록된 구현이 없습니다.

Tasks

Face Swapping

Similar Papers 제목 키워드 기반

Untraceable DeepFakes via Traceable Fingerprint Elimination

2025-08-05 · Jiewei Lai, Lan Zhang, Chen Tang, Pengcheng Sun 외 arxiv

Recent advancements in DeepFakes attribution technologies have significantly enhanced forensic capabilities, enabling the extraction of traces left by generative models (GMs) in images, making DeepFakes traceable back to…

DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat Rhythms

2020-06-13 · Hua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie 외

As the GAN-based face image and video generation techniques, widely known as DeepFakes, have become more and more matured and realistic, there comes a pressing and urgent demand for effective DeepFakes detectors. Motivat…

DeepFake DetectionFace SwappingPhotoplethysmography (PPG)Video Generation

An Examination of Fairness of AI Models for Deepfake Detection

2021-05-02 · Loc Trinh, Yan Liu

Recent studies have demonstrated that deep learning models can discriminate based on protected classes like race and gender. In this work, we evaluate bias present in deepfake datasets and detection models across protect…

DeepFake DetectionFace SwappingFairness

Generative Propaganda

2025-09-23 · Madeleine I. G. Daepp, Alejandro Cuevas, Robert Osazuwa Ness, Vickie Yu-Ping Wang 외 arxiv

Generative propaganda is the use of generative artificial intelligence (AI) to shape public opinion. To characterize its use in real-world settings, we conducted interviews with defenders (e.g., factcheckers, journalists…

Improving the Efficiency and Robustness of Deepfakes Detection through Precise Geometric Features

2021-04-09 · CVPR 2021 1 · Zekun Sun, Yujie Han, Zeyu Hua, Na Ruan 외

Deepfakes is a branch of malicious techniques that transplant a target face to the original one in videos, resulting in serious problems such as infringement of copyright, confusion of information, or even public panic. …

Open-Ended Question Answering