Initiative Defense against Facial Manipulation
Qidong Huang, Jie Zhang, Wenbo Zhou, Weiming Zhang, Nenghai Yu
摘要
Benefiting from the development of generative adversarial networks (GAN), facial manipulation has achieved significant progress in both academia and industry recently. It inspires an increasing number of entertainment applications but also incurs severe threats to individual privacy and even political security meanwhile. To mitigate such risks, many countermeasures have been proposed. However, the great majority methods are designed in a passive manner, which is to detect whether the facial images or videos are tampered after their wide propagation. These detection-based methods have a fatal limitation, that is, they only work for ex-post forensics but can not prevent the engendering of malicious behavior.
To address the limitation, in this paper, we propose a novel framework of initiative defense to degrade the performance of facial manipulation models controlled by malicious users. The basic idea is to actively inject imperceptible venom into target facial data before manipulation. To this end, we first imitate the target manipulation model with a surrogate model, and then devise a poison perturbation generator to obtain the desired venom. An alternating training strategy are further leveraged to train both the surrogate model and the perturbation generator. Two typical facial manipulation tasks: face attribute editing and face reenactment, are considered in our initiative defense framework. Extensive experiments demonstrate the effectiveness and robustness of our framework in different settings. Finally, we hope this work can shed some light on initiative countermeasures against more adversarial scenarios.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Anti-DreamBooth: Protecting users from personalized text-to-image synthesisThanh Van Le, Hao Phung, Thuan Hoang Nguyen, Quan Dao 等ICCV 2023 · 被引用 144 次
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 被引用 74 次
- LampMark: Proactive Deepfake Detection via Training-Free Landmark Perceptual WatermarksTianyi Wang, Mengxiao Huang, Harry Cheng, Xiao Zhang 等ACM MM 2024 · 被引用 27 次
- SimAC: A Simple Anti-Customization Method for Protecting Face Privacy Against Text-to-Image Synthesis of Diffusion ModelsFeifei Wang, Zhentao Tan, Tianyi Wei, Yue Wu 等CVPR 2024 · 被引用 18 次
- PID: Prompt-Independent Data Protection Against Latent Diffusion ModelsAng Li, Yichuan Mo, Mingjie Li, Yisen WangICML 2024 · 被引用 5 次
它引用的顶会 Paper4
- FaceForensics++: Learning to Detect Manipulated Facial ImagesAndreas Rössler, Davide Cozzolino, Luisa Verdoliva, Christian Riess 等ICCV 2019 · 被引用 2,966 次
- FSGAN: Subject Agnostic Face Swapping and ReenactmentYuval Nirkin, Yosi Keller, Tal HassnerICCV 2019 · 被引用 710 次
- Face X-Ray for More General Face Forgery DetectionLingzhi Li, Jianmin Bao, Ting Zhang, Hao Yang 等CVPR 2020
- On the Detection of Digital Face ManipulationHao Dang, Feng Liu, Joel Stehouwer, Xiaoming Liu 等CVPR 2020
相关 Paper
- Defeating DeepFakes via Adversarial Visual ReconstructionZiwen He, Wei Wang, Weinan Guan, Jing Dong 等ACM MM 2022 · 被引用 27 次
- UnGANable: Defending Against GAN-based Face ManipulationZheng Li, Ning Yu, Ahmed Salem, Michael Backes 等USENIX Security 2023
- DeepProtect: Proactive Face-Swapping Defense using Identity Blending and Attribute DistortionEungi Lee, Seung-hyeok Back, Hyung-Il Kim, Seok Bong YooCVPR 2026
- DFPD: Dual-Forgery Proactive Defense against Both Deepfakes and Traditional Image ManipulationsBeijing Chen, Yuting Hong, Ziqiang Li, Zhangjie FuACM MM 2025
- FaceShield: Defending Facial Image Against Deepfake ThreatsJaehwan Jeong, Sumin In, Sieun Kim, Hannie Shin 等ICCV 2025 · 被引用 3 次
