paper-with-me

Papers

Metamorphic Testing-based Adversarial Attack to Fool Deepfake Detectors

2022-04-19 · Nyee Thoang Lim, Meng Yi Kuan, Muxin Pu, Mei Kuan Lim, Chun Yong Chong

Deepfakes utilise Artificial Intelligence (AI) techniques to create synthetic media where the likeness of one person is replaced with another. There are growing concerns that deepfakes can be maliciously used to create misleading and harmful digital contents. As deepfakes become more common, there is a dire need for deepfake detection technology to help spot deepfake media. Present deepfake detection models are able to achieve outstanding accuracy (>90%). However, most of them are limited to within-dataset scenario, where the same dataset is used for training and testing. Most models do not generalise well enough in cross-dataset scenario, where models are tested on unseen datasets from another source. Furthermore, state-of-the-art deepfake detection models rely on neural network-based classification models that are known to be vulnerable to adversarial attacks. Motivated by the need for a robust deepfake detection model, this study adapts metamorphic testing (MT) principles to help identify potential factors that could influence the robustness of the examined model, while overcoming the test oracle problem in this domain. Metamorphic testing is specifically chosen as the testing technique as it fits our demand to address learning-based system testing with probabilistic outcomes from largely black-box components, based on potentially large input domains. We performed our evaluations on MesoInception-4 and TwoStreamNet models, which are the state-of-the-art deepfake detection models. This study identified makeup application as an adversarial attack that could fool deepfake detectors. Our experimental results demonstrate that both the MesoInception-4 and TwoStreamNet models degrade in their performance by up to 30\% when the input data is perturbed with makeup.

📄 PDF Abstract BibTeX arXiv:2204.08612

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackDeepFake DetectionFace Swapping

Similar Papers 제목 키워드 기반

Adversarial Perturbations Fool Deepfake Detectors

2020-03-24 · Apurva Gandhi, Shomik Jain

This work uses adversarial perturbations to enhance deepfake images and fool common deepfake detectors. We created adversarial perturbations using the Fast Gradient Sign Method and the Carlini and Wagner L2 norm attack i…

Face Swapping

Adversarial Magnification to Deceive Deepfake Detection through Super Resolution

2024-07-02 · Davide Alessandro Coccomini, Roberto Caldelli, Giuseppe Amato, Fabrizio Falchi 외

Deepfake technology is rapidly advancing, posing significant challenges to the detection of manipulated media content. Parallel to that, some adversarial attack techniques have been developed to fool the deepfake detecto…

Adversarial AttackDeepFake DetectionFace SwappingSuper-Resolution

Metamorphic Detection of Adversarial Examples in Deep Learning Models With Affine Transformations

2019-07-10 · Rohan Reddy Mekala, Gudjon Einar Magnusson, Adam Porter, Mikael Lindvall 외

Adversarial attacks are small, carefully crafted perturbations, imperceptible to the naked eye; that when added to an image cause deep learning models to misclassify the image with potentially detrimental outcomes. With …

Face RecognitionSelf-Driving Cars

Robust Android Malware Detection System against Adversarial Attacks using Q-Learning

2021-01-27 · Hemant Rathore, Sanjay K. Sahay, Piyush Nikam, Mohit Sewak

The current state-of-the-art Android malware detection systems are based on machine learning and deep learning models. Despite having superior performance, these models are susceptible to adversarial attacks. Therefore i…

Adversarial DefenseAndroid Malware DetectionBIG-bench Machine LearningMalware Detection+4

Defense Against Adversarial Attacks on Audio DeepFake Detection

2022-12-30 · Piotr Kawa, Marcin Plata, Piotr Syga

Audio DeepFakes (DF) are artificially generated utterances created using deep learning, with the primary aim of fooling the listeners in a highly convincing manner. Their quality is sufficient to pose a severe threat in …

Audio Deepfake DetectionDeepFake DetectionFace Swapping