DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute Distortion
Eungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong Yoo
Abstract
Face-swapping deepfakes allow realistic identity transfer, which can serve creative purposes but increases the risk of identity abuse. A proactive defense aims to prevent deepfake creation by obstructing identity feature extraction from input images, essential for identity-driven face-swapping. Existing proactive defense approaches aim to protect faces by hindering accurate identity feature extraction, but tend to introduce visible artifacts and fail to degrade the visual quality of the face-swapping deepfakes. This work proposes a proactive face-swapping defense using identity blending and attribute distortion (DeepProtect) that integrates global identity fusion in the latent space and local prompt-driven adversarial watermarking to address these problems. This work dilutes distinct identity representations by channel-wise blending of multiple identities in the latent space and optimizing the generator for visual consistency. The proposed approach distorts facial components in the identity space, directly influencing how faces are reconstructed in deepfakes. This approach applies semantic directions derived from user-provided text prompts to embed imperceptible adversarial watermarks that selectively distort facial attributes, affecting the visual fidelity of deepfake results. The proposed method hinders face-swapping deepfakes while preserving the perceptual quality of the protected images, offering a robust and practical solution for facial privacy protection. The experimental results reveal that DeepProtect effectively defends against face-swapping deepfakes while preserving visual consistency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1ed730b-3024-4e83-a348-6f8194b51c08Builds on27
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu et al.ICLR 2022 · 18,833 citations
- Image2StyleGAN: How to Embed Images Into the StyleGAN Latent Space?Rameen Abdal, Yipeng Qin, Peter WonkaICCV 2019 · 1,195 citations
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao et al.ICML 2022 · 663 citations
- SimSwap: An Efficient Framework For High Fidelity Face SwappingRenwang Chen, Xuanhong Chen, Bingbing Ni, Yanhao GeACM MM 2020 · 409 citations
Related papers
- SCOL: Style Code Orchestration in Latent Space for Proactive Face-Swapping DefenseEungi Lee, Jae Hyun Yoon, Seok Bong YooACM MM 2025
- NullSwap: Proactive Identity Cloaking Against Deepfake Face SwappingTianyi Wang, Shuaicheng Niu, Harry Cheng, Xiao Zhang et al.ICCV 2025 · 4 citations
- Defeating DeepFakes via Adversarial Visual ReconstructionZiwen He, Wei Wang, Weinan Guan, Jing Dong et al.ACM MM 2022 · 27 citations
- DFPD: Dual-Forgery Proactive Defense against Both Deepfakes and Traditional Image ManipulationsBeijing Chen, Yuting Hong, Ziqiang Li, Zhangjie FuACM MM 2025
- FaceShield: Defending Facial Image Against Deepfake ThreatsJaehwan Jeong, Sumin In, Sieun Kim, Hannie Shin et al.ICCV 2025 · 3 citations
