Exploring Frequency Adversarial Attacks for Face Forgery Detection
Shuai Jia, Chao Ma, Taiping Yao, Bangjie Yin, Shouhong Ding, Xiaokang Yang
摘要
Various facial manipulation techniques have drawn seri-ous public concerns in morality, security, and privacy. Al- though existing face forgery classifiers achieve promising performance on detecting fake images, these methods are vulnerable to adversarial examples with injected impercep- tible perturbations on the pixels. Meanwhile, many face forgery detectors always utilize the frequency diversity be-tween real and fake faces as a crucial clue. In this paper, in- stead of injecting adversarial perturbations into the spatial domain, we propose a frequency adversarial attack method against face forgery detectors. Concretely, we apply dis-crete cosine transform (DCT) on the input images and in-troduce a fusion module to capture the salient region of ad-versary in the frequency domain. Compared with existing adversarial attacks (e.g. FGSM, PGD) in the spatial do-main, our method is more imperceptible to human observers and does not degrade the visual quality of the original images. Moreover, inspired by the idea of meta-learning, we also propose a hybrid adversarial attack that performs at-tacks in both the spatial and frequency domains. Exten-sive experiments indicate that the proposed method fools not only the spatial-based detectors but also the state-of- the-art frequency-based detectors effectively. In addition, the proposed frequency attack enhances the transferability across face forgery detectors as black-box attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- OST: Improving Generalization of DeepFake Detection via One-Shot Test-Time TrainingLiang Chen, Yong Zhang, Yibing Song, Jue Wang 等NeurIPS 2022 · 被引用 102 次
- FreqBlender: Enhancing DeepFake Detection by Blending Frequency KnowledgeHanzhe Li, Jiaran Zhou, Yuezun Li, Baoyuan Wu 等NeurIPS 2024 · 被引用 96 次
- An Analysis of Recent Advances in Deepfake Image Detection in an Evolving Threat LandscapeSifat Muhammad Abdullah, Aravind Cheruvu, Shravya Kanchi, Taejoong Chung 等S&P 2024 · 被引用 42 次
- Imperceptible Adversarial Attack via Invertible Neural NetworksZihan Chen, Ziyue Wang, Jun-Jie Huang, Wentao Zhao 等AAAI 2023 · 被引用 34 次
- Learning to Distill Global Representation for Sparse-View CTZilong Li, Chenglong Ma, Jie Chen, Junping Zhang 等ICCV 2023 · 被引用 22 次
它引用的顶会 Paper14
- FaceForensics++: Learning to Detect Manipulated Facial ImagesAndreas Rössler, Davide Cozzolino, Luisa Verdoliva, Christian Riess 等ICCV 2019 · 被引用 2,966 次
- Local Relation Learning for Face Forgery DetectionShen Chen, Taiping Yao, Yang Chen, Shouhong Ding 等AAAI 2021 · 被引用 340 次
- Dual Contrastive Learning for General Face Forgery DetectionKe Sun, Taiping Yao, Shen Chen, Shouhong Ding 等AAAI 2022 · 被引用 241 次
- Exploiting Fine-Grained Face Forgery Clues via Progressive Enhancement LearningQiqi Gu, Shen Chen, Taiping Yao, Yang Chen 等AAAI 2022 · 被引用 187 次
- Spatiotemporal Inconsistency Learning for DeepFake Video DetectionZhihao Gu, Yang Chen, Taiping Yao, Shouhong Ding 等ACM MM 2021 · 被引用 175 次
相关 Paper
- Evading DeepFake Detectors via Adversarial Statistical ConsistencyYang Hou, Qing Guo, Yihao Huang, Xiaofei Xie 等CVPR 2023
- Spatial-Phase Shallow Learning: Rethinking Face Forgery Detection in Frequency DomainHonggu Liu, Xiaodan Li, Wenbo Zhou, Yuefeng Chen 等CVPR 2021
- Frequency-aware GAN for Adversarial Manipulation GenerationPeifei Zhu, Genki Osada, Hirokatsu Kataoka, Tsubasa TakahashiICCV 2023 · 被引用 13 次
- Evading Forensic Classifiers with Attribute-Conditioned Adversarial FacesFahad Shamshad, Koushik Srivatsan, Karthik NandakumarCVPR 2023
- Face Reconstruction from Facial Templates by Learning Latent Space of a Generator NetworkHatef Otroshi-Shahreza, Sébastien MarcelNeurIPS 2023 · 被引用 48 次
