Exploring Frequency Adversarial Attacks for Face Forgery Detection
Shuai Jia, Chao Ma, Taiping Yao, Bangjie Yin, Shouhong Ding, Xiaokang Yang
Abstract
Various facial manipulation techniques have drawn seri-ous public concerns in morality, security, and privacy. Al- though existing face forgery classifiers achieve promising performance on detecting fake images, these methods are vulnerable to adversarial examples with injected impercep- tible perturbations on the pixels. Meanwhile, many face forgery detectors always utilize the frequency diversity be-tween real and fake faces as a crucial clue. In this paper, in- stead of injecting adversarial perturbations into the spatial domain, we propose a frequency adversarial attack method against face forgery detectors. Concretely, we apply dis-crete cosine transform (DCT) on the input images and in-troduce a fusion module to capture the salient region of ad-versary in the frequency domain. Compared with existing adversarial attacks (e.g. FGSM, PGD) in the spatial do-main, our method is more imperceptible to human observers and does not degrade the visual quality of the original images. Moreover, inspired by the idea of meta-learning, we also propose a hybrid adversarial attack that performs at-tacks in both the spatial and frequency domains. Exten-sive experiments indicate that the proposed method fools not only the spatial-based detectors but also the state-of- the-art frequency-based detectors effectively. In addition, the proposed frequency attack enhances the transferability across face forgery detectors as black-box attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b9f1da3d-0cb9-4601-9480-a19a97773540Cited by top-tier papers16
- OST: Improving Generalization of DeepFake Detection via One-Shot Test-Time TrainingLiang Chen, Yong Zhang, Yibing Song, Jue Wang et al.NeurIPS 2022 · 102 citations
- FreqBlender: Enhancing DeepFake Detection by Blending Frequency KnowledgeHanzhe Li, Jiaran Zhou, Yuezun Li, Baoyuan Wu et al.NeurIPS 2024 · 96 citations
- An Analysis of Recent Advances in Deepfake Image Detection in an Evolving Threat LandscapeSifat Muhammad Abdullah, Aravind Cheruvu, Shravya Kanchi, Taejoong Chung et al.S&P 2024 · 42 citations
- Imperceptible Adversarial Attack via Invertible Neural NetworksZihan Chen, Ziyue Wang, Jun-Jie Huang, Wentao Zhao et al.AAAI 2023 · 34 citations
- Learning to Distill Global Representation for Sparse-View CTZilong Li, Chenglong Ma, Jie Chen, Junping Zhang et al.ICCV 2023 · 22 citations
Builds on14
- FaceForensics++: Learning to Detect Manipulated Facial ImagesAndreas Rössler, Davide Cozzolino, Luisa Verdoliva, Christian Riess et al.ICCV 2019 · 2,966 citations
- Local Relation Learning for Face Forgery DetectionShen Chen, Taiping Yao, Yang Chen, Shouhong Ding et al.AAAI 2021 · 340 citations
- Dual Contrastive Learning for General Face Forgery DetectionKe Sun, Taiping Yao, Shen Chen, Shouhong Ding et al.AAAI 2022 · 241 citations
- Exploiting Fine-Grained Face Forgery Clues via Progressive Enhancement LearningQiqi Gu, Shen Chen, Taiping Yao, Yang Chen et al.AAAI 2022 · 187 citations
- Spatiotemporal Inconsistency Learning for DeepFake Video DetectionZhihao Gu, Yang Chen, Taiping Yao, Shouhong Ding et al.ACM MM 2021 · 175 citations
Related papers
- Evading DeepFake Detectors via Adversarial Statistical ConsistencyYang Hou, Qing Guo, Yihao Huang, Xiaofei Xie et al.CVPR 2023
- Spatial-Phase Shallow Learning: Rethinking Face Forgery Detection in Frequency DomainHonggu Liu, Xiaodan Li, Wenbo Zhou, Yuefeng Chen et al.CVPR 2021
- Frequency-aware GAN for Adversarial Manipulation GenerationPeifei Zhu, Genki Osada, Hirokatsu Kataoka, Tsubasa TakahashiICCV 2023 · 13 citations
- Evading Forensic Classifiers with Attribute-Conditioned Adversarial FacesFahad Shamshad, Koushik Srivatsan, Karthik NandakumarCVPR 2023
- Face Reconstruction from Facial Templates by Learning Latent Space of a Generator NetworkHatef Otroshi-Shahreza, Sébastien MarcelNeurIPS 2023 · 48 citations
