AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake Detection

被引:0
|
作者
Meng, Xiangtao [1 ]
Wang, Li [1 ]
Guo, Shanqing [1 ]
Ju, Lei [1 ]
Zhao, Qingchuan [2 ]
机构
[1] Shandong Univ, Jinan, Peoples R China
[2] City Univ Hong Kong, Hong Kong, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1109/SP54263.2024.00155
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While DeepFake applications are becoming popular in recent years, their abuses pose a serious privacy threat. Unfortunately, most related detection algorithms to mitigate the abuse issues are inherently vulnerable to adversarial attacks because they are built atop DNN-based classification models, and the literature has demonstrated that they could be bypassed by introducing pixel-level perturbations. Though corresponding mitigation has been proposed, we have identified a new attribute-variation-based adversarial attack (AVA) that perturbs the latent space via a combination of Gaussian prior and semantic discriminator to bypass such mitigation. It perturbs the semantics in the attribute space of DeepFake images, which are inconspicuous to human beings (e.g., mouth open) but can result in substantial differences in DeepFake detection. We evaluate our proposed AVA attack on nine state-of-the-art DeepFake detection algorithms and applications. The empirical results demonstrate that AVA attack defeats the state-of-the-art black box attacks against DeepFake detectors and achieves more than a 95% success rate on two commercial DeepFake detectors. Moreover, our human study indicates that AVA-generated DeepFake images are often imperceptible to humans, which presents huge security and privacy concerns.
引用
收藏
页码:74 / 90
页数:17
相关论文
共 50 条
  • [11] Residue-Based Natural Language Adversarial Attack Detection
    Raina, Vyas
    Gales, Mark
    NAACL 2022: THE 2022 CONFERENCE OF THE NORTH AMERICAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS: HUMAN LANGUAGE TECHNOLOGIES, 2022, : 3836 - 3848
  • [12] Clustering-based attack detection for adversarial reinforcement learning
    Majadas, Ruben
    Garcia, Javier
    Fernandez, Fernando
    APPLIED INTELLIGENCE, 2024, 54 (03) : 2631 - 2647
  • [13] A DoS attack detection method based on adversarial neural network
    Li, Yang
    Wu, Haiyan
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [14] Clustering-based attack detection for adversarial reinforcement learning
    Rubén Majadas
    Javier García
    Fernando Fernández
    Applied Intelligence, 2024, 54 : 2631 - 2647
  • [15] Network Intrusion Detection System based on Generative Adversarial Network for Attack Detection
    Das, Abhijit
    Balakrishnan, S. G.
    Pramod
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (11) : 757 - 766
  • [16] Anomaly Detection of Deepfake Audio Based on Real Audio Using Generative Adversarial Network Model
    Song, Daeun
    Lee, Nayoung
    Kim, Jiwon
    Choi, Eunjung
    IEEE ACCESS, 2024, 12 : 184311 - 184326
  • [17] Background estimation and motion saliency detection using total variation-based video decomposition
    Bhattacharya, Saumik
    Venkatsh, K. S.
    Gupta, Sumana
    SIGNAL IMAGE AND VIDEO PROCESSING, 2017, 11 (01) : 113 - 121
  • [18] Background estimation and motion saliency detection using total variation-based video decomposition
    Saumik Bhattacharya
    K. S. Venkatsh
    Sumana Gupta
    Signal, Image and Video Processing, 2017, 11 : 113 - 121
  • [19] Energy Ratio Variation-Based Structural Damage Detection Using Convolutional Neural Network
    Wu, Chuan-Sheng
    Peng, Yang-Xia
    Zhuo, De-Bing
    Zhang, Jian-Qiang
    Ren, Wei
    Feng, Zhen-Yang
    APPLIED SCIENCES-BASEL, 2022, 12 (20):
  • [20] Active Attack Detection Based on Interpretable Channel Fingerprint and Adversarial Autoencoder
    Ji, Zijie
    Yang, Binbing
    Yeoh, Phee Lep
    Zhang, Yan
    He, Zunwen
    Li, Yonghui
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 4993 - 4998