TraceEvader: Making DeepFakes More Untraceable via Evading the Forgery Model Attribution
Mengjie Wu, Jingui Ma, Run Wang, Sidan Zhang, Ziyou Liang, Boheng Li, Chenhao Lin, Liming Fang, Lina Wang
摘要
In recent few years, DeepFakes are posing serve threats and concerns to both individuals and celebrities, as realistic DeepFakes facilitate the spread of disinformation. Model attribution techniques aim at attributing the adopted forgery models of DeepFakes for provenance purposes and providing explainable results to DeepFake forensics. However, the existing model attribution techniques rely on the trace left in the DeepFake creation, which can become futile if such traces were disrupted. Motivated by our observation that certain traces served for model attribution appeared in both the high-frequency and low-frequency domains and play a divergent role in model attribution. In this work, for the first time, we propose a novel training-free evasion attack, TraceEvader, in the most practical non-box setting. Specifically, TraceEvader injects a universal imitated traces learned from wild DeepFakes into the high-frequency component and introduces adversarial blur into the domain of the low-frequency component, where the added distortion confuses the extraction of certain traces for model attribution. The comprehensive evaluation on 4 state-of-the-art (SOTA) model attribution techniques and fake images generated by 8 generative models including generative adversarial networks (GANs) and diffusion models (DMs) demonstrates the effectiveness of our method. Overall, our TraceEvader achieves the highest average attack success rate of 79% and is robust against image transformations and dedicated denoising techniques as well where the average attack success rate is still around 75%. Our TraceEvader confirms the limitations of current model attribution techniques and calls the attention of DeepFake researchers and practitioners for more robust-purpose model attribution techniques.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Lips Are Lying: Spotting the Temporal Inconsistency between Audio and Visual in Lip-Syncing DeepFakesWeifeng Liu, Tianyi She, Jiawei Liu, Boheng Li 等NeurIPS 2024 · 被引用 57 次
- StealthDiffusion: Towards Evading Diffusion Forensic Detection through Diffusion ModelZiyin Zhou, Ke Sun, Zhongxi Chen, Huafeng Kuang 等ACM MM 2024 · 被引用 7 次
- Untraceable DeepFakes via Traceable Fingerprint EliminationJiewei Lai, Lan Zhang, Chen Tang, Pengcheng Sun 等ICLR 2026
它引用的顶会 Paper14
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 被引用 13,211 次
- Pseudo Numerical Methods for Diffusion Models on ManifoldsLuping Liu, Yi Ren, Zhijie Lin, Zhou ZhaoICLR 2022 · 被引用 861 次
- Leveraging Frequency Analysis for Deep Fake Image RecognitionJoel Frank, Thorsten Eisenhofer, Lea Schönherr, Asja Fischer 等ICML 2020 · 被引用 848 次
- Attributing Fake Images to GANs: Learning and Analyzing GAN FingerprintsNing Yu, Larry Davis, Mario FritzICCV 2019 · 被引用 533 次
- Fourier Spectrum Discrepancies in Deep Network Generated ImagesTarik Dzanic, Karan Shah, Freddie D. WitherdenNeurIPS 2020 · 被引用 235 次
相关 Paper
- Evading DeepFake Detectors via Adversarial Statistical ConsistencyYang Hou, Qing Guo, Yihao Huang, Xiaofei Xie 等CVPR 2023
- FrePGAN: Robust Deepfake Detection Using Frequency-Level PerturbationsYonghyun Jeong, Doyeon Kim, Youngmin Ro, Jongwon ChoiAAAI 2022 · 被引用 159 次
- Deepfake Network Architecture AttributionTianyun Yang, Ziyao Huang, Juan Cao, Lei Li 等AAAI 2022 · 被引用 72 次
- AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake DetectionXiangtao Meng, Li Wang, Shanqing Guo, Lei Ju 等S&P 2024 · 被引用 17 次
- Contrastive Pseudo Learning for Open-World DeepFake AttributionZhimin Sun, Shen Chen, Taiping Yao, Bangjie Yin 等ICCV 2023 · 被引用 42 次
