DFPD: Dual-Forgery Proactive Defense against Both Deepfakes and Traditional Image Manipulations
Beijing Chen, Yuting Hong, Ziqiang Li, Zhangjie Fu
Abstract
Proactive defense against face forgery seeks to disrupt the output of forgery models by embedding imperceptible adversarial perturbations into face images to be protected. However, existing methods predominantly focus on deepfakes, often neglecting traditional image manipulations. It limits their practical applicability, as attackers may resort to traditional manipulations when deepfake attempts fail. To bridge this gap, a Dual-Forgery Proactive Defense (DFPD) method is proposed for combating both deepfakes and traditional image manipulations. For deepfake resistance, the DFPD designs a gradient-based ensemble adversarial attack that effectively disrupts outputs from multiple deepfake models. To defeat traditional manipulations, it also designs a fragile watermarking algorithm based on Invertible Neural Network (INN), enabling accurate localization of tampered regions. Furthermore, to mitigate the mutual interference between perturbation injection and watermark embedding, on the one hand, the DFPD adopts a serial pipeline starting with watermark embedding and then perturbation injection, which ensures that the injected perturbations are not displaced into residual image during INN-based embedding. On the other hand, a morphological post-processing module is introduced to eliminate adversarial noise in the tampering localization results. Extensive experiments validate the effectiveness of DFPD, demonstrating a 20.25% improvement in deepfake disruption over the best baseline in terms of PSNR and a 9.67% increase in traditional tampering localization in terms of ACC, while preserving high perceptual quality (32.75 dB PSNR).
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 31fc2803-9ad1-4b29-9b13-a61203ae31d2Related papers
- DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute DistortionEungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong YooCVPR 2026
- BiFPro: A Bidirectional Facial-data Protection Framework against DeepFakeHonggu Liu, Xiaodan Li, Wenbo Zhou, Han Fang et al.ACM MM 2023 · 12 citations
- RecoverMark: Robust Watermarking for Localization and Recovery of Manipulated FacesHaonan An, Xiaohui Ye, Guang Hua, Yihang Tao et al.CVPR 2026 · 2 citations
- LampMark: Proactive Deepfake Detection via Training-Free Landmark Perceptual WatermarksTianyi Wang, Mengxiao Huang, Harry Cheng, Xiao Zhang et al.ACM MM 2024 · 27 citations
- Uncovering and Mitigating Destructive Multi-Embedding Attacks in Deepfake Proactive ForensicsLixin Jia, Haiyang Sun, Zhiqing Guo, Yunfeng Diao et al.AAAI 2026 · 4 citations
