BiFPro: A Bidirectional Facial-data Protection Framework against DeepFake
Honggu Liu, Xiaodan Li, Wenbo Zhou, Han Fang, Paolo Bestagini, Weiming Zhang, Yuefeng Chen, Stefano Tubaro, Nenghai Yu, Yuan He, Hui Xue
Abstract
The rapid progress of the DeepFake technique has caused severe privacy problems. Thus protecting facial data against DeepFake becomes an urgent requirement. Face protection can be regarded as a bidirectional process: Face-out-detection (FOD) and Face-in-forensics (FIF). For FOD, the detectability should be satisfied when using the protected face to replace other faces. For FIF, traceability should be guaranteed when the protected face is replaced by others. For this, we propose a Bidirectional Facial-data Protection Framework (BiFPro) to protect face data comprehensively. This framework is composed of three main parts: Watermarking embedding, Face-out-detection (FOD) and Face-in-forensics (FIF). For the FOD case, we ensure the vulnerability of the original face by embedding fragile watermarking. Once the protected facial image is used to replace other faces, the watermarking information will be corrupted in the synthesized face images which can be used to detect the authenticity of the protected facial images. As for the FIF case, we guarantee the traceability of the protected face image by embedding robust watermarking, with which the fake faces can be traced with the reserved watermarking even after the face is swapped. Experimental results demonstrate that our proposed BiFPro could generate the watermarking which is fragile to FOD and at the same time robust to FIF with an average watermark extraction success rate reaching more than 95% when defending against the four advanced DeepFake techniques. Finally, we hope this work can encourage more initiative countermeasures against DeepFake.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 34955550-733c-4a52-bc15-02eed0d33bfbCited by top-tier papers2
- PhantomSeal: Proactive Deepfakes Defense with Identity/Context Protection and Forensic TracingLiangqin Ren, Zeyan Liu, Ye Wang, Yuxin Chen et al.CCS 2026
- FIRE: Robust Detection of Diffusion-Generated Images via Frequency-Guided Reconstruction ErrorBeilin Chu, Xuan Xu, Xin Wang, Yufei Zhang et al.CVPR 2025
Related papers
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 74 citations
- All in One: Unifying Deepfake Detection, Tampering Localization, and Source Tracing with a Robust Landmark-Identity WatermarkJunjiang Wu, Liejun Wang, Zhiqing GuoCVPR 2026 · 4 citations
- Robust Secure Swap: Responsible Face Swap With Persons of Interest Redaction and Provenance TraceabilityYunshu Dai, Jianwei Fei, Fangjun Huang, Chip Hong ChangICML 2025
- DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute DistortionEungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong YooCVPR 2026
- SepVAMark: Deep Separable Visual-Audio Fusion Watermarking for Source Tracing and Deepfake DetectionChuan Zhang, Zihan Li, Zihao Xu, Xuhao Ren et al.ACM MM 2025 · 2 citations
