用人脸特征生成动态水印,主动识别换脸伪造
Facial Features Matter: a Dynamic Watermark based Proactive Deepfake Detection Approach
- 基于128维人脸特征生成不可逆水印,防反推攻击
- 在多种换脸技术下仍保持高检测准确率
- 适合需要主动防御深度伪造的安防与内容平台
当前被动式深度伪造人脸换脸检测方法在模型泛化能力上面临显著瓶颈。而主动检测方法常采用固定水印,与所保护内容关联弱且易受安全威胁。基于人脸特征的动态水印提供了一种有前景的解决方案,因其能提供唯一标识。本文提出一种基于人脸特征的主动深度伪造检测方法(FaceProtect),利用深度伪造操作中人脸特征的变化作为新型检测机制。我们设计了一种基于GAN的一向动态水印生成机制(GODWGM),以128维人脸特征向量为输入,构建从人脸特征到水印的不可逆映射,增强对各类逆向推理攻击的防护能力。此外,提出一种结合隐写术的水印验证策略(WVS),可将代表人脸特征的基准水印与图像同步传输。实验结果表明,所提方法在多种深度伪造技术处理的图像上均保持优异检测性能,具备高度实用性。
原文摘要 · Abstract (English)
Current passive deepfake face-swapping detection methods encounter significance bottlenecks in model generalization capabilities. Meanwhile, proactive detection methods often use fixed watermarks which lack a close relationship with the content they protect and are vulnerable to security risks. Dynamic watermarks based on facial features offer a promising solution, as these features provide unique identifiers. Therefore, this paper proposes a Facial Feature-based Proactive deepfake detection method (FaceProtect), which utilizes changes in facial characteristics during deepfake manipulation as a novel detection mechanism. We introduce a GAN-based One-way Dynamic Watermark Generating Mechanism (GODWGM) that uses 128-dimensional facial feature vectors as inputs. This method creates irreversible mappings from facial features to watermarks, enhancing protection against various reverse inference attacks. Additionally, we propose a Watermark-based Verification Strategy (WVS) that combines steganography with GODWGM, allowing simultaneous transmission of the benchmark watermark representing facial features within the image. Experimental results demonstrate that our proposed method maintains exceptional detection performance and exhibits high practicality on images altered by various deepfake techniques.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。