Scalable Universal Adversarial Watermark Defending Against Facial Forgery

被引:0
|
作者
Qiao, Tong [1 ]
Zhao, Bin [1 ]
Shi, Ran [2 ]
Han, Meng [3 ]
Hassaballah, Mahmoud [4 ,5 ]
Retraint, Florent [6 ]
Luo, Xiangyang [7 ]
机构
[1] Hangzhou Dianzi Univ, Sch Cyberspace, Hangzhou 310018, Peoples R China
[2] Nanjing Univ Sci & Technol, Sch Comp Sci & Engn, Nanjing 210094, Peoples R China
[3] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310058, Peoples R China
[4] Prince Sattam Bin Abdulaziz Univ, Coll Comp Engn & Sci, Dept Comp Sci, Alkharj 16278, Saudi Arabia
[5] South Valley Univ, Dept Comp Sci, Qena 83523, Egypt
[6] Univ Technol Troyes, Lab Comp Sci & Digital Soc, F-10004 Troyes, France
[7] State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China
基金
中国国家自然科学基金;
关键词
Watermarking; Forgery; Predictive models; Generative adversarial networks; Computational modeling; Perturbation methods; Detectors; GAN forgery model; active defense; adversarial watermark; scalability;
D O I
10.1109/TIFS.2024.3460387
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The illegal use of facial forgery models, such as Generative Adversarial Networks (GAN) synthesized contents, has been on the rise, thereby posing great threats to personal reputation and national security. To mitigate these threats, recent studies have proposed the use of adversarial watermarks as countermeasures against GAN, effectively disrupting their outputs. However, the majority of these adversarial watermarks exhibit very limited defense ranges, providing defense against only a single GAN forgery model. Although some universal adversarial watermarks have demonstrated impressive results, they lack the defense scalability as a new-emerging forgery model appears. To address the tough issue, we propose a scalable approach even when the original forgery models are unknown. Specifically, a watermark expansion scheme, which mainly involves inheriting, defense and constraint steps, is introduced. On the one hand, the proposed method can effectively inherit the defense range of the prior well-trained adversarial watermark; on the other hand, it can defend against a new forgery model. Extensive experimental results validate the efficacy of the proposed method, exhibiting superior performance and reduced computational time compared to the state-of-the-arts.
引用
下载
收藏
页码:8998 / 9011
页数:14
相关论文
共 50 条
  • [1] Robust Adversarial Watermark Defending Against GAN Synthesization Attack
    Xu, Shengwang
    Qiao, Tong
    Xu, Ming
    Wang, Wei
    Zheng, Ning
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 351 - 355
  • [2] Defending Against Universal Perturbations With Shared Adversarial Training
    Mummadi, Chaithanya Kumar
    Brox, Thomas
    Metzen, Jan Hendrik
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 4927 - 4936
  • [3] Defending against Universal Adversarial Patches by Clipping Feature Norms
    Yu, Cheng
    Chen, Jiansheng
    Xue, Youze
    Liu, Yuyang
    Wan, Weitao
    Bao, Jiayu
    Ma, Huimin
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 16414 - 16422
  • [4] Inspector for Face Forgery Detection: Defending Against Adversarial Attacks From Coarse to Fine
    Xia, Ruiyang
    Zhou, Dawei
    Liu, Decheng
    Li, Jie
    Yuan, Lin
    Wang, Nannan
    Gao, Xinbo
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2024, 33 : 4432 - 4443
  • [5] Defending Black Box Facial Recognition Classifiers Against Adversarial Attacks
    Theagarajan, Rajkumar
    Bhanu, Bir
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2020), 2020, : 3537 - 3547
  • [6] Improving Robustness of Facial Landmark Detection by Defending against Adversarial Attacks
    Zhu, Congcong
    Li, Xiaoqiang
    Li, Jide
    Dai, Songmin
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 11731 - 11740
  • [7] Adversarial watermark: A robust and reliable watermark against removal
    Wang, Jinwei
    Huang, Wanyun
    Zhang, Jiawei
    Luo, Xiangyang
    Ma, Bin
    Journal of Information Security and Applications, 2024, 82
  • [8] Adversarial watermark: A robust and reliable watermark against removal
    Wang, Jinwei
    Huang, Wanyun
    Zhang, Jiawei
    Luo, Xiangyang
    Ma, Bin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 82
  • [9] Defending Person Detection Against Adversarial Patch Attack by Using Universal Defensive Frame
    Yu, Youngjoon
    Lee, Hong Joo
    Lee, Hakmin
    Ro, Yong Man
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2022, 31 : 6976 - 6990
  • [10] DEFENDING AGAINST UNIVERSAL ATTACK VIA CURVATURE-AWARE CATEGORY ADVERSARIAL TRAINING
    Du, Peilun
    Zheng, Xiaolong
    Liu, Liang
    Ma, Huadong
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 2470 - 2474