TraceEvader: Making DeepFakes More Untraceable via Evading the Forgery Model Attribution
Mengjie Wu, Jingui Ma, Run Wang, Sidan Zhang, Ziyou Liang, Boheng Li, Chenhao Lin, Liming Fang, Lina Wang
Abstract
In recent few years, DeepFakes are posing serve threats and concerns to both individuals and celebrities, as realistic DeepFakes facilitate the spread of disinformation. Model attribution techniques aim at attributing the adopted forgery models of DeepFakes for provenance purposes and providing explainable results to DeepFake forensics. However, the existing model attribution techniques rely on the trace left in the DeepFake creation, which can become futile if such traces were disrupted. Motivated by our observation that certain traces served for model attribution appeared in both the high-frequency and low-frequency domains and play a divergent role in model attribution. In this work, for the first time, we propose a novel training-free evasion attack, TraceEvader, in the most practical non-box setting. Specifically, TraceEvader injects a universal imitated traces learned from wild DeepFakes into the high-frequency component and introduces adversarial blur into the domain of the low-frequency component, where the added distortion confuses the extraction of certain traces for model attribution. The comprehensive evaluation on 4 state-of-the-art (SOTA) model attribution techniques and fake images generated by 8 generative models including generative adversarial networks (GANs) and diffusion models (DMs) demonstrates the effectiveness of our method. Overall, our TraceEvader achieves the highest average attack success rate of 79% and is robust against image transformations and dedicated denoising techniques as well where the average attack success rate is still around 75%. Our TraceEvader confirms the limitations of current model attribution techniques and calls the attention of DeepFake researchers and practitioners for more robust-purpose model attribution techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cfc87bb2-e7cb-488c-8e3d-c2cc3a6a2d9bCited by top-tier papers3
- Lips Are Lying: Spotting the Temporal Inconsistency between Audio and Visual in Lip-Syncing DeepFakesWeifeng Liu, Tianyi She, Jiawei Liu, Boheng Li et al.NeurIPS 2024 · 57 citations
- StealthDiffusion: Towards Evading Diffusion Forensic Detection through Diffusion ModelZiyin Zhou, Ke Sun, Zhongxi Chen, Huafeng Kuang et al.ACM MM 2024 · 7 citations
- Untraceable DeepFakes via Traceable Fingerprint EliminationJiewei Lai, Lan Zhang, Chen Tang, Pengcheng Sun et al.ICLR 2026
Builds on14
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- Pseudo Numerical Methods for Diffusion Models on ManifoldsLuping Liu, Yi Ren, Zhijie Lin, Zhou ZhaoICLR 2022 · 861 citations
- Leveraging Frequency Analysis for Deep Fake Image RecognitionJoel Frank, Thorsten Eisenhofer, Lea Schönherr, Asja Fischer et al.ICML 2020 · 848 citations
- Attributing Fake Images to GANs: Learning and Analyzing GAN FingerprintsNing Yu, Larry Davis, Mario FritzICCV 2019 · 533 citations
- Fourier Spectrum Discrepancies in Deep Network Generated ImagesTarik Dzanic, Karan Shah, Freddie D. WitherdenNeurIPS 2020 · 235 citations
Related papers
- Evading DeepFake Detectors via Adversarial Statistical ConsistencyYang Hou, Qing Guo, Yihao Huang, Xiaofei Xie et al.CVPR 2023
- FrePGAN: Robust Deepfake Detection Using Frequency-Level PerturbationsYonghyun Jeong, Doyeon Kim, Youngmin Ro, Jongwon ChoiAAAI 2022 · 159 citations
- Deepfake Network Architecture AttributionTianyun Yang, Ziyao Huang, Juan Cao, Lei Li et al.AAAI 2022 · 72 citations
- AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake DetectionXiangtao Meng, Li Wang, Shanqing Guo, Lei Ju et al.S&P 2024 · 17 citations
- Contrastive Pseudo Learning for Open-World DeepFake AttributionZhimin Sun, Shen Chen, Taiping Yao, Bangjie Yin et al.ICCV 2023 · 42 citations
