Evading Forensic Classifiers with Attribute-Conditioned Adversarial Faces
Fahad Shamshad, Koushik Srivatsan, Karthik Nandakumar
摘要
The ability of generative models to produce highly realistic synthetic face images has raised security and ethical concerns. As a first line of defense against such fake faces, deep learning based forensic classifiers have been developed. While these forensic models can detect whether a face image is synthetic or real with high accuracy, they are also vulnerable to adversarial attacks. Although such attacks can be highly successful in evading detection by forensic classifiers, they introduce visible noise patterns that are detectable through careful human scrutiny. Additionally, these attacks assume access to the target model(s) which may not always be true. Attempts have been made to directly perturb the latent space of GANs to produce adversarial fake faces that can circumvent forensic classifiers. In this work, we go one step further and show that it is possible to successfully generate adversarial fake faces with a specified set of attributes (e.g., hair color, eye size, race, gender, etc.). To achieve this goal, we leverage the state-of-the-art generative model StyleGAN with disentangled representations, which enables a range of modifications without leaving the manifold of natural images. We propose a framework to search for adversarial latent codes within the feature space of StyleGAN, where the search can be guided either by a text prompt or a reference image. We also propose a metalearning based optimization strategy to achieve transferable performance on unknown target models. Extensive experiments demonstrate that the proposed approach can produce semantically manipulated adversarial fake faces, which are true to the specified attribute set and can successfully fool forensic face classifiers, while remaining undetectable by humans. Code: https://github.com/ koushiksrivats/face_attribute_attack.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh 等ICML 2021 · 被引用 47,906 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- StyleCLIP: Text-Driven Manipulation of StyleGAN ImageryOr Patashnik, Zongze Wu, Eli Shechtman, Daniel Cohen-Or 等ICCV 2021 · 被引用 1,437 次
- Attributing Fake Images to GANs: Learning and Analyzing GAN FingerprintsNing Yu, Larry Davis, Mario FritzICCV 2019 · 被引用 533 次
- Unsupervised Discovery of Interpretable Directions in the GAN Latent SpaceAndrey Voynov, Artem BabenkoICML 2020 · 被引用 459 次
相关 Paper
- Exploring Adversarial Fake Images on Face ManifoldDongze Li, Wei Wang, Hongxing Fan, Jing DongCVPR 2021
- ImU: Physical Impersonating Attack for Face Recognition System with Natural Style ChangesShengwei An, Yuan Yao, Qiuling Xu, Shiqing Ma 等S&P 2023
- Everything is There in Latent Space: Attribute Editing and Attribute Style Manipulation by StyleGAN Latent Space ExplorationRishubh Parihar, Ankit Dhiman, Tejan Karmali, Venkatesh Babu R.ACM MM 2022 · 被引用 21 次
- Attribute-specific Control Units in StyleGAN for Fine-grained Image ManipulationRui Wang, Jian Chen, Gang Yu, Li Sun 等ACM MM 2021 · 被引用 13 次
- Adaptive Nonlinear Latent Transformation for Conditional Face EditingZhizhong Huang, Siteng Ma, Junping Zhang, Hongming ShanICCV 2023 · 被引用 13 次
