Dodging DeepFake Detection via Implicit Spatial-Domain Notch Filtering

被引:1
|
作者
Huang Y. [1 ]
Juefei-Xu F. [2 ]
Guo Q. [3 ]
Liu Y. [1 ]
Pu G. [4 ]
机构
[1] Institute of High Performance Computing (IHPC) and Centre for Frontier AI Research (CFAR), Agency for Science, Technology and Research (A*STAR)
关键词
DeepFake; DeepFake Detection; DeepFake Evasion; Deepfakes; Detectors; Filtering; Fingerprint recognition; Frequency-domain analysis; Image synthesis; Notch filters;
D O I
10.1109/TCSVT.2023.3325427
中图分类号
学科分类号
摘要
The current high-fidelity generation and high-precision detection of DeepFake images are at an arms race. We believe that producing DeepFakes that are highly realistic and “detection evasive” can serve the ultimate goal of improving future generation DeepFake detection capabilities. In this paper, we propose a simple yet powerful pipeline to reduce the artifact patterns of fake images without hurting image quality by performing implicit spatial-domain notch filtering. We first demonstrate that frequency-domain notch filtering, although famously shown to be effective in removing periodic noise in the spatial domain, is infeasible for our task at hand due to the manual designs required for the notch filters. We, therefore, resort to a learning-based approach to reproduce the notch filtering effects, but solely in the spatial domain. We adopt a combination of adding overwhelming spatial noise for breaking the periodic noise pattern and deep image filtering to reconstruct the noise-free fake images, and we name our method DeepNotch. Deep image filtering provides a specialized filter for each pixel in the noisy image, producing filtered images with high fidelity compared to their DeepFake counterparts. Moreover, we also use the semantic information of the image to generate an adversarial guidance map to add noise intelligently. Our large-scale evaluation on 3 representative DeepFake detection methods (tested on 16 types of DeepFakes) has demonstrated that our technique significantly reduces the accuracy of these 3 fake image detection methods, 36.79% on average and up to 97.02% in the best case. IEEE
引用
收藏
页码:1 / 1
相关论文
共 31 条
  • [1] NONLINEAR SPATIAL-DOMAIN FILTERING OF IMAGE NOISE
    KISHNER, SJ
    [J]. JOURNAL OF THE OPTICAL SOCIETY OF AMERICA, 1971, 61 (11) : 1548 - &
  • [2] Integrated Detection and Tracking via Closed-Loop Radar with Spatial-Domain Matched Illumination
    Nielsen, Pete
    Goodman, Nathan A.
    [J]. 2008 INTERNATIONAL CONFERENCE ON RADAR, VOLS 1 AND 2, 2008, : 485 - 490
  • [3] Spatial-domain image watermarking robust against compression, filtering, cropping, and scaling
    Sebé, F
    Domingo-Ferrer, J
    Herrera, J
    [J]. INFORMATION SECURITY, PROCEEDINGS, 2001, 1975 : 44 - 53
  • [4] Deepfake Detection via Combining Channel and Spatial Attention
    Bayar, Alperen Enes
    Topal, Cihan
    [J]. 2023 31ST SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE, SIU, 2023,
  • [5] NONLOCAL IMAGE DENOISING VIA COLLABORATIVE SPATIAL-DOMAIN LMMSE ESTIMATION
    Wang, Bo
    Xiong, Zixiang
    Zhang, Dongqing
    Yu, Heather
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2014, : 2714 - 2718
  • [6] Domain Generalization via Aggregation and Separation for Audio Deepfake Detection
    Xie, Yuankun
    Cheng, Haonan
    Wang, Yutian
    Ye, Long
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 344 - 358
  • [8] Secure spatial-domain watermarking for images via image features and local statistics
    Tsai, HH
    Wang, WY
    [J]. 8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL VIII, PROCEEDINGS: CONTROL, COMMUNICATION AND NETWORK SYSTEMS, TECHNOLOGIES AND APPLICATIONS, 2004, : 123 - 128
  • [9] Performing deblocking in video coding based on spatial-domain motion-compensated temporal filtering
    Munteanu, Adrian
    Barbarien, Joeri
    Cornelis, Jan
    Schelkens, Peter
    [J]. ADVANCED CONCEPTS FOR INTELLIGENT VISION SYSTEMS, PROCEEDINGS, 2006, 4179 : 364 - 374
  • [10] Implicit Neural Spatial Filtering for Multichannel Source Separation in the Waveform Domain
    Markovic, Dejan
    Defossez, Alexandre
    Richard, Alexander
    [J]. INTERSPEECH 2022, 2022, : 1806 - 1810