Generative Transferable Universal Adversarial Perturbation for Combating Deepfakes

被引:0
|
作者
Guo, Yuchen [1 ,2 ]
Wang, Xi [1 ]
Fu, Xiaomeng [1 ,2 ]
Li, Jin [1 ,2 ]
Li, Zhaoxing [1 ]
Chai, Yesheng [1 ]
Hao, Jizhong [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
关键词
adversarial perturbation; deepfake; face modification; face protection;
D O I
10.1109/CSCWD61410.2024.10580713
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Recently, Deepfake has posed a significant threat to our digital society. This technology allows for the modification of facial identity, expression, and attributes in facial images and videos. The misuse of Deepfake can invade personal privacy, damage individuals' reputations, and have serious consequences. To counter this threat, researchers have proposed active defense methods using adversarial perturbation to distort Deepfake products which can hinder the dissemination of false information. However, the existing methods are primarily based on image-specific approaches, which are inefficient for large-scale data. To address these issues, we propose an end-to-end approach to generate universal perturbations for combating Deepfake. To further cope with diverse Deepfakes, we introduce an adaptive balancing strategy to combat multiple models simultaneously. Specifically, for different scenarios, we propose two types of universal perturbations. Disrupting Universal Perturbation (DUP) leads Deepfake models to generate distorted outputs. In contrast, Lapsing Universal Perturbation (LUP) tries to make the output consistent with the original image, allowing the correct information to continue propagating. Experiments demonstrate the effectiveness and better generalization of our proposed perturbation compared with state-of-the-art methods. Consequently, our proposed method offers a powerful and efficient solution for combating Deepfake, which can help preserve personal privacy and prevent reputational damage.
引用
收藏
页码:1980 / 1985
页数:6
相关论文
共 50 条
  • [1] CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating Deepfakes
    Huang, Hao
    Wang, Yongtao
    Chen, Zhaoyu
    Zhang, Yuze
    Li, Yuheng
    Tang, Zhi
    Chu, Wei
    Chen, Jingdong
    Lin, Weisi
    Ma, Kai-Kuang
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 989 - 997
  • [2] Generative Transferable Adversarial Attack
    Li, Yifeng
    Zhang, Ya
    Zhang, Rui
    Wang, Yanfeng
    ICVIP 2019: PROCEEDINGS OF 2019 3RD INTERNATIONAL CONFERENCE ON VIDEO AND IMAGE PROCESSING, 2019, : 84 - 89
  • [3] Generative Universal Nullifying Perturbation for Countering Deepfakes Through Combined Unsupervised Feature Aggregation
    Guo, Yuchen
    Wang, Xi
    Fu, Xiaomeng
    Liu, Jin
    Li, Zhaoxing
    Han, Jizhong
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING-ICANN 2024, PT II, 2024, 15017 : 289 - 303
  • [4] Defending Against Deepfakes with Ensemble Adversarial Perturbation
    Guan, Weinan
    He, Ziwen
    Wang, Wei
    Dong, Jing
    Peng, Bo
    2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 1952 - 1958
  • [5] TransNoise: Transferable Universal Adversarial Noise for Adversarial Attack
    Wei, Yier
    Gao, Haichang
    Wang, Yufei
    Liu, Huan
    Gao, Yipeng
    Luo, Sainan
    Guo, Qianwen
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT V, 2023, 14258 : 193 - 205
  • [6] Generative Perturbation Network for Universal Adversarial Attacks on Brain-Computer Interfaces
    Jung, Jiyoung
    Moon, HeeJoon
    Yu, Geunhyeok
    Hwang, Hyoseok
    IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2023, 27 (11) : 5622 - 5633
  • [7] Towards Transferable Adversarial Attacks with Centralized Perturbation
    Wu, Shangbo
    Tan, Yu-an
    Wang, Yajie
    Ma, Ruinan
    Ma, Wencong
    Li, Yuanzhang
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 6, 2024, : 6109 - 6116
  • [8] Learning Universal Adversarial Perturbation by Adversarial Example
    Li, Maosen
    Yang, Yanhua
    Wei, Kun
    Yang, Xu
    Huang, Heng
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 1350 - 1358
  • [9] Universal adversarial perturbations generative network
    Wang, Zheng
    Yang, Yang
    Li, Jingjing
    Zhu, Xiaofeng
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2022, 25 (04): : 1725 - 1746
  • [10] Universal adversarial perturbations generative network
    Zheng Wang
    Yang Yang
    Jingjing Li
    Xiaofeng Zhu
    World Wide Web, 2022, 25 : 1725 - 1746