Exploring Adversarial Fake Images on Face Manifold
Dongze Li, Wei Wang, Hongxing Fan, Jing Dong
Abstract
Images synthesized by powerful generative adversarial network (GAN) based methods have drawn moral and privacy concerns. Although image forensic models have reached great performance in detecting fake images from real ones, these models can be easily fooled with a simple adversarial attack. But, the noise adding adversarial samples are also arousing suspicion. In this paper, instead of adding adversarial noise, we optimally search adversarial points on face manifold to generate anti-forensic fake face images. We iteratively do a gradient-descent with each small step in the latent space of a generative model, e.g. Style-GAN, to find an adversarial latent vector, which is similar to norm-based adversarial attack but in latent space. Then, the generated fake images driven by the adversarial latent vectors with the help of GANs can defeat main-stream forensic models. For examples, they make the accuracy of deepfake detection models based on Xception or EfficientNet drop from over 90% to nearly 0%, meanwhile maintaining high visual quality. In addition, we find manipulating noise vectors at different levels of the generator have different impacts on attack success rate, and the generated adversarial images mainly have changes on facial texture or face attributes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5bf05758-735e-4f23-8324-254666d85e11Cited by top-tier papers10
- Exploring Frequency Adversarial Attacks for Face Forgery DetectionShuai Jia, Chao Ma, Taiping Yao, Bangjie Yin et al.CVPR 2022 · 78 citations
- DISCO: Adversarial Defense with Local Implicit FunctionsChih-Hui Ho, Nuno VasconcelosNeurIPS 2022 · 65 citations
- Think Twice Before Detecting GAN-generated Fake Images from their Spectral Domain ImprintsChengdong Dong, Ajay Kumar, Eryun LiuCVPR 2022 · 61 citations
- An Analysis of Recent Advances in Deepfake Image Detection in an Evolving Threat LandscapeSifat Muhammad Abdullah, Aravind Cheruvu, Shravya Kanchi, Taejoong Chung et al.S&P 2024 · 42 citations
- AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake DetectionXiangtao Meng, Li Wang, Shanqing Guo, Lei Ju et al.S&P 2024 · 17 citations
Builds on5
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- FaceForensics++: Learning to Detect Manipulated Facial ImagesAndreas Rössler, Davide Cozzolino, Luisa Verdoliva, Christian Riess et al.ICCV 2019 · 2,966 citations
- FSGAN: Subject Agnostic Face Swapping and ReenactmentYuval Nirkin, Yosi Keller, Tal HassnerICCV 2019 · 710 citations
- Face X-Ray for More General Face Forgery DetectionLingzhi Li, Jianmin Bao, Ting Zhang, Hao Yang et al.CVPR 2020
- Boosting the Transferability of Adversarial Samples via AttentionWeibin Wu, Yuxin Su, Xixian Chen, Shenglin Zhao et al.CVPR 2020
Related papers
- Evading Forensic Classifiers with Attribute-Conditioned Adversarial FacesFahad Shamshad, Koushik Srivatsan, Karthik NandakumarCVPR 2023
- Defeating DeepFakes via Adversarial Visual ReconstructionZiwen He, Wei Wang, Weinan Guan, Jing Dong et al.ACM MM 2022 · 27 citations
- Dual Manifold Adversarial Robustness: Defense against Lp and non-Lp Adversarial AttacksWei-An Lin, Chun Pong Lau, Alexander Levine, Rama Chellappa et al.NeurIPS 2020 · 70 citations
- ImU: Physical Impersonating Attack for Face Recognition System with Natural Style ChangesShengwei An, Yuan Yao, Qiuling Xu, Shiqing Ma et al.S&P 2023
- Face Reconstruction from Facial Templates by Learning Latent Space of a Generator NetworkHatef Otroshi-Shahreza, Sébastien MarcelNeurIPS 2023 · 48 citations
