Adversarial Robust Safeguard for Evading Deep Facial Manipulation
Jiazhi Guan, Yi Zhao, Zhuoer Xu, Changhua Meng, Ke Xu, Youjian Zhao
Abstract
The non-consensual exploitation of facial manipulation has emerged as a pressing societal concern. In tandem with the identification of such fake content, recent research endeavors have advocated countering manipulation techniques through proactive interventions, specifically the incorporation of adversarial noise to impede the manipulation in advance. Nevertheless, with insufficient consideration of robustness, we show that current methods falter in providing protection after simple perturbations, e.g., blur. In addition, traditional optimization-based methods face limitations in scalability as they struggle to accommodate the substantial expansion of data volume, a consequence of the time-intensive iterative pipeline. To solve these challenges, we propose a learning-based model, Adversarial Robust Safeguard (ARS), to generate desirable protection noise in a single forward process, concurrently exhibiting a heightened resistance against prevalent perturbations. Specifically, our method involves a two-way protection design, characterized by a basic protection component responsible for generating efficacious noise features, coupled with robust protection for further enhancement. In robust protection, we first fuse image features with spatially duplicated noise embedding, thereby accounting for inherent information redundancy. Subsequently, a combination comprising a differentiable perturbation module and an adversarial network is devised to simulate potential information degradation during the training process. To evaluate it, we conduct experiments on four manipulation methods and compare recent works comprehensively. The results of our method exhibit good visual effects with pronounced robustness against varied perturbations at different levels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Breaking the Generator Barrier: Disentangled Representation for Generalizable AI-Text DetectionXiao Pu, Zepeng Cheng, Lin Yuan, Yu Wu et al.ACL 2026 · 1 citation
- DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute DistortionEungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong YooCVPR 2026
Builds on18
- SimSwap: An Efficient Framework For High Fidelity Face SwappingRenwang Chen, Xuanhong Chen, Bingbing Ni, Yanhao GeACM MM 2020 · 409 citations
- UCF: Uncovering Common Features for Generalizable Deepfake DetectionZhiyuan Yan, Yong Zhang, Yanbo Fan, Baoyuan WuICCV 2023 · 264 citations
- Dual Contrastive Learning for General Face Forgery DetectionKe Sun, Taiping Yao, Shen Chen, Shouhong Ding et al.AAAI 2022 · 241 citations
- TALL: Thumbnail Layout for Deepfake Video DetectionYuting Xu, Jian Liang, Gengyun Jia, Ziming Yang et al.ICCV 2023 · 133 citations
- CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating DeepfakesHao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang et al.AAAI 2022 · 131 citations
Related papers
- DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image EditingJune Suk Choi, Kyungmin Lee, Jongheon Jeong, Saining Xie et al.ICLR 2025
- FaceShield: Defending Facial Image Against Deepfake ThreatsJaehwan Jeong, Sumin In, Sieun Kim, Hannie Shin et al.ICCV 2025 · 3 citations
- Adversarial Perturbations Cannot Reliably Protect Artists From Generative AIRobert Hönig, Javier Rando, Nicholas Carlini, Florian TramèrICLR 2025
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang et al.ACM MM 2020 · 40 citations
- Privacy-preserving Adversarial Facial FeaturesZhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang et al.CVPR 2023
