CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating Deepfakes
Hao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang, Yuheng Li, Zhi Tang, Wei Chu, Jingdong Chen, Weisi Lin, Kai-Kuang Ma
摘要
Malicious applications of deepfakes (i.e., technologies generating target facial attributes or entire faces from facial images) have posed a huge threat to individuals' reputation and security. To mitigate these threats, recent studies have proposed adversarial watermarks to combat deepfake models, leading them to generate distorted outputs. Despite achieving impressive results, these adversarial watermarks have low image-level and model-level transferability, meaning that they can protect only one facial image from one specific deepfake model. To address these issues, we propose a novel solution that can generate a Cross-Model Universal Adversarial Watermark (CMUA-Watermark), protecting a large number of facial images from multiple deepfake models. Specifically, we begin by proposing a cross-model universal attack pipeline that attacks multiple deepfake models iteratively. Then, we design a two-level perturbation fusion strategy to alleviate the conflict between the adversarial watermarks generated by different facial images and models. Moreover, we address the key problem in cross-model optimization with a heuristic approach to automatically find the suitable attack step sizes for different models, further weakening the model-level conflict. Finally, we introduce a more reasonable and comprehensive evaluation method to fully test the proposed method and compare it with existing ones. Extensive experimental results demonstrate that the proposed CMUA-Watermark can effectively distort the fake facial images generated by multiple deepfake models while achieving a better performance than existing methods. Our code is available at https://github.com/VDIGPKU/CMUA-Watermark.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- Disentangled Representation Learning for Multimodal Emotion RecognitionDingkang Yang, Shuai Huang, Haopeng Kuang, Yangtao Du 等ACM MM 2022 · 被引用 260 次
- DENSE: Data-Free One-Shot Federated LearningJie Zhang, Chen Chen, Bo Li, Lingjuan Lyu 等NeurIPS 2022 · 被引用 202 次
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 被引用 74 次
- Learning Modality-Specific and -Agnostic Representations for Asynchronous Multimodal Language SequencesDingkang Yang, Haopeng Kuang, Shuai Huang, Lihua ZhangACM MM 2022 · 被引用 64 次
- Towards Practical Certifiable Patch Defense with Vision TransformerZhaoyu Chen, Bo Li, Jianghe Xu, Shuang Wu 等CVPR 2022 · 被引用 60 次
它引用的顶会 Paper6
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Local Relation Learning for Face Forgery DetectionShen Chen, Taiping Yao, Yang Chen, Shouhong Ding 等AAAI 2021 · 被引用 340 次
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong 等ICCV 2019 · 被引用 115 次
- One Detector to Rule Them All: Towards a General Deepfake Attack Detection FrameworkShahroz Tariq, Sangyup Lee, Simon S. WooWWW 2021 · 被引用 90 次
- Multi-Attentional Deepfake DetectionHanqing Zhao, Wenbo Zhou, Dongdong Chen, Tianyi Wei 等CVPR 2021
相关 Paper
- Proactive Deepfake Detection via Self-Verifiable Semantic WatermarkingPeiqi Jiang, Bohan Lei, Yuhao Sun, Lingyun Yu 等ACM MM 2025
- DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute DistortionEungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong YooCVPR 2026
- LampMark: Proactive Deepfake Detection via Training-Free Landmark Perceptual WatermarksTianyi Wang, Mengxiao Huang, Harry Cheng, Xiao Zhang 等ACM MM 2024 · 被引用 27 次
- UnMarker: A Universal Attack on Defensive Image WatermarkingAndre Kassis, Urs HengartnerS&P 2025
- Certified Neural Network Watermarks with Randomized SmoothingArpit Bansal, Ping-Yeh Chiang, Michael J. Curry, Rajiv Jain 等ICML 2022 · 被引用 64 次
