arXiv:2409.14424cs.CRcs.AI2024-09中稿 · USENIX Security 20…被引 7

给真人照片加隐形干扰,防止被用来生成伪造视频

Dormant: Defending against Pose-driven Human Image Animation

  • 在图像中添加不可见扰动,破坏姿态驱动动画的特征提取
  • 使生成视频出现身份错位、画面扭曲和帧间不一致
  • 对6个商业级服务有效,无需内部信息也能防护

姿态驱动的人像动画已取得显著进展,仅凭一张照片即可生成生动逼真的视频。但这也带来了滥用风险,攻击者可能利用单张图片生成政治、暴力等非法内容视频。为此,我们提出Dormant,一种针对此类技术的新型防护方法。Dormant在人像图像上添加保护性扰动,保持与原图视觉相似性,但导致生成视频质量下降。该扰动旨在诱导外观特征误提取,并造成生成帧间的不连贯。在8种动画方法和4个数据集上的广泛评估表明,Dormant优于6种基线防护方法,使生成视频出现身份错位、视觉失真、明显伪影和帧间不一致。此外,Dormant在6个真实商业服务中也表现出色,即使在完全黑盒访问条件下仍有效。

原文摘要 · Abstract (English)

Pose-driven human image animation has achieved tremendous progress, enabling the generation of vivid and realistic human videos from just one single photo. However, it conversely exacerbates the risk of image misuse, as attackers may use one available image to create videos involving politics, violence, and other illegal content. To counter this threat, we propose Dormant, a novel protection approach tailored to defend against pose-driven human image animation techniques. Dormant applies protective perturbation to one human image, preserving the visual similarity to the original but resulting in poor-quality video generation. The protective perturbation is optimized to induce misextraction of appearance features from the image and create incoherence among the generated video frames. Our extensive evaluation across 8 animation methods and 4 datasets demonstrates the superiority of Dormant over 6 baseline protection methods, leading to misaligned identities, visual distortions, noticeable artifacts, and inconsistent frames in the generated videos. Moreover, Dormant shows effectiveness on 6 real-world commercial services, even with fully black-box access.

图像防护视频生成安全对抗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。