arXiv:2410.04205cs.CVeess.IV2024-10ECCV被引 1

超分辨率攻击可隐藏深度伪造痕迹,但对纯合成图像无效。

Exploring Strengths and Weaknesses of Super-Resolution Attack in Deepfake Detection

论文配图:Exploring Strengths and Weaknesses of Super-Resolution Attack in Deepfake Detection
图 1 · 摘自论文原文
  • 用不同超分辨率技术测试攻击深度伪造检测器的鲁棒性。
  • 超分辨率能有效掩盖生成模型留下的伪影,但无法隐藏纯合成图像痕迹。
  • 建议改进检测器训练方式以增强抗攻击能力,适合安全与检测研究者。

图像篡改技术快速发展,催生出可扭曲现实的可信内容。尽管深度伪造检测器效果良好,但对抗攻击仍可进一步提升伪造复杂度,通过操纵图像以隐藏伪造痕迹或注入使其看似真实的信号。本文深入探索了基于不同超分辨率技术及尺度的超分辨率攻击对深度伪造检测器性能的影响,发现该攻击在不同数据集上表现不一:超分辨率能有效隐藏生成模型引入的伪影,但在完全合成图像中则失效。最后,我们提出改进检测器训练流程的方案,以提升其对这类攻击的鲁棒性。

原文摘要 · Abstract (English)

Image manipulation is rapidly evolving, allowing the creation of credible content that can be used to bend reality. Although the results of deepfake detectors are promising, deepfakes can be made even more complicated to detect through adversarial attacks. They aim to further manipulate the image to camouflage deepfakes' artifacts or to insert signals making the image appear pristine. In this paper, we further explore the potential of super-resolution attacks based on different super-resolution techniques and with different scales that can impact the performance of deepfake detectors with more or less intensity. We also evaluated the impact of the attack on more diverse datasets discovering that the super-resolution process is effective in hiding the artifacts introduced by deepfake generation models but fails in hiding the traces contained in fully synthetic images. Finally, we propose some changes to the detectors' training process to improve their robustness to this kind of attack.

深度伪造对抗攻击超分辨率检测鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。