Uncovering and Mitigating Destructive Multi-Embedding Attacks in Deepfake Proactive Forensics
Lixin Jia, Haiyang Sun, Zhiqing Guo, Yunfeng Diao, Dan Ma, Gaobo Yang
摘要
With the rapid evolution of deepfake technologies and the wide dissemination of digital media, personal privacy is facing increasingly serious security threats. Deepfake proactive forensics, which involves embedding imperceptible watermarks to enable reliable source tracking, serves as a crucial defense against these threats. Although existing methods show strong forensic ability, they rely on an idealized assumption of single watermark embedding, which proves impractical in real-world scenarios. In this paper, we formally define and demonstrate the existence of Multi-Embedding Attacks (MEA) for the first time. When a previously protected image undergoes additional rounds of watermark embedding, the original forensic watermark can be destroyed or removed, rendering the entire proactive forensic mechanism ineffective. To address this vulnerability, we propose a general training paradigm named Adversarial Interference Simulation (AIS). Rather than modifying the network architecture, AIS explicitly simulates MEA scenarios during fine-tuning and introduces a resilience-driven loss function to enforce the learning of sparse and stable watermark representations. Our method enables the model to maintain the ability to extract the original watermark correctly even after a second embedding. Extensive experiments demonstrate that our plug-and-play AIS training paradigm significantly enhances the robustness of various existing methods against MEA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper13
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- SimSwap: An Efficient Framework For High Fidelity Face SwappingRenwang Chen, Xuanhong Chen, Bingbing Ni, Yanhao GeACM MM 2020 · 被引用 409 次
- Artificial Fingerprinting for Generative Models: Rooting Deepfake Attribution in Training DataNing Yu, Vladislav Skripniuk, Sahar Abdelnabi, Mario FritzICCV 2021 · 被引用 305 次
- MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG CompressionZhaoyang Jia, Han Fang, Weiming ZhangACM MM 2021 · 被引用 251 次
- Exploiting Fine-Grained Face Forgery Clues via Progressive Enhancement LearningQiqi Gu, Shen Chen, Taiping Yao, Yang Chen 等AAAI 2022 · 被引用 187 次
相关 Paper
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 被引用 74 次
- CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating DeepfakesHao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang 等AAAI 2022 · 被引用 131 次
- The Future Unmarked: Watermark Removal in AI-Generated Images via Next-Frame PredictionHuming Qiu, Zhaoxiang Wang, Mi Zhang, Xiaohan Zhang 等NeurIPS 2025 · 被引用 5 次
- DFPD: Dual-Forgery Proactive Defense against Both Deepfakes and Traditional Image ManipulationsBeijing Chen, Yuting Hong, Ziqiang Li, Zhangjie FuACM MM 2025
- Class-feature Watermark: A Resilient Black-box Watermark Against Model Extraction AttacksYaxin Xiao, Qingqing Ye, Zi Liang, Haoyang Li 等AAAI 2026
