CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating Deepfakes
Hao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang, Yuheng Li, Zhi Tang, Wei Chu, Jingdong Chen, Weisi Lin, Kai-Kuang Ma
Abstract
Malicious applications of deepfakes (i.e., technologies generating target facial attributes or entire faces from facial images) have posed a huge threat to individuals' reputation and security. To mitigate these threats, recent studies have proposed adversarial watermarks to combat deepfake models, leading them to generate distorted outputs. Despite achieving impressive results, these adversarial watermarks have low image-level and model-level transferability, meaning that they can protect only one facial image from one specific deepfake model. To address these issues, we propose a novel solution that can generate a Cross-Model Universal Adversarial Watermark (CMUA-Watermark), protecting a large number of facial images from multiple deepfake models. Specifically, we begin by proposing a cross-model universal attack pipeline that attacks multiple deepfake models iteratively. Then, we design a two-level perturbation fusion strategy to alleviate the conflict between the adversarial watermarks generated by different facial images and models. Moreover, we address the key problem in cross-model optimization with a heuristic approach to automatically find the suitable attack step sizes for different models, further weakening the model-level conflict. Finally, we introduce a more reasonable and comprehensive evaluation method to fully test the proposed method and compare it with existing ones. Extensive experimental results demonstrate that the proposed CMUA-Watermark can effectively distort the fake facial images generated by multiple deepfake models while achieving a better performance than existing methods. Our code is available at https://github.com/VDIGPKU/CMUA-Watermark.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext beef91e3-532b-427d-ac5e-b2248700c1d7Cited by top-tier papers20
- Disentangled Representation Learning for Multimodal Emotion RecognitionDingkang Yang, Shuai Huang, Haopeng Kuang, Yangtao Du et al.ACM MM 2022 · 260 citations
- DENSE: Data-Free One-Shot Federated LearningJie Zhang, Chen Chen, Bo Li, Lingjuan Lyu et al.NeurIPS 2022 · 202 citations
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 74 citations
- Learning Modality-Specific and -Agnostic Representations for Asynchronous Multimodal Language SequencesDingkang Yang, Haopeng Kuang, Shuai Huang, Lihua ZhangACM MM 2022 · 64 citations
- Towards Practical Certifiable Patch Defense with Vision TransformerZhaoyu Chen, Bo Li, Jianghe Xu, Shuang Wu et al.CVPR 2022 · 60 citations
Builds on6
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Local Relation Learning for Face Forgery DetectionShen Chen, Taiping Yao, Yang Chen, Shouhong Ding et al.AAAI 2021 · 340 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- One Detector to Rule Them All: Towards a General Deepfake Attack Detection FrameworkShahroz Tariq, Sangyup Lee, Simon S. WooWWW 2021 · 90 citations
- Multi-Attentional Deepfake DetectionHanqing Zhao, Wenbo Zhou, Dongdong Chen, Tianyi Wei et al.CVPR 2021
Related papers
- Proactive Deepfake Detection via Self-Verifiable Semantic WatermarkingPeiqi Jiang, Bohan Lei, Yuhao Sun, Lingyun Yu et al.ACM MM 2025
- DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute DistortionEungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong YooCVPR 2026
- LampMark: Proactive Deepfake Detection via Training-Free Landmark Perceptual WatermarksTianyi Wang, Mengxiao Huang, Harry Cheng, Xiao Zhang et al.ACM MM 2024 · 27 citations
- UnMarker: A Universal Attack on Defensive Image WatermarkingAndre Kassis, Urs HengartnerS&P 2025
- Certified Neural Network Watermarks with Randomized SmoothingArpit Bansal, Ping-Yeh Chiang, Michael J. Curry, Rajiv Jain et al.ICML 2022 · 64 citations
