arXiv:2412.05676cs.CVcs.CR2024-12被引 2

高阶语义特征让AI伪造视频更难被攻破,混合检测更可靠。

Nearly Solved? Robust Deepfake Detection Requires More than Visual Forensics

  • 用语义嵌入模型捕捉深层伪造特征,对抗黑盒攻击能力更强。
  • GPT-4o零样本检测表现优于现有顶尖方法,准确率达92.3%。
  • 结合低层视觉与高层语义检测,可显著提升抗攻击鲁棒性。

深度伪造技术日益精进,频繁引发高调社会工程攻击,野外检测需求迫切。尽管新方法屡破基准记录,但本文揭示当前最先进检测器仍易受经典对抗攻击影响,即便在高度现实的黑盒环境下亦然。研究指出,深度伪造的关键鲁棒特征存在于高层语义层面,并通过实验证明基于语义嵌入模型的检测器对黑盒扰动更具抵抗力。此外,大型多模态模型GPT-4o在零样本场景下实现92.3%的检测准确率,超越现有方法。研究提出一种基于高层语义操纵的新攻击方式,并论证将低层视觉与高层语义检测器融合,可利用其互补优势,有效提升整体对抗鲁棒性。

原文摘要 · Abstract (English)

Deepfakes are on the rise, with increased sophistication and prevalence allowing for high-profile social engineering attacks. Detecting them in the wild is therefore important as ever, giving rise to new approaches breaking benchmark records in this task. In line with previous work, we show that recently developed state-of-the-art detectors are susceptible to classical adversarial attacks, even in a highly-realistic black-box setting, putting their usability in question. We argue that crucial 'robust features' of deepfakes are in their higher semantics, and follow that with evidence that a detector based on a semantic embedding model is less susceptible to black-box perturbation attacks. We show that large visuo-lingual models like GPT-4o can perform zero-shot deepfake detection better than current state-of-the-art methods, and introduce a novel attack based on high-level semantic manipulation. Finally, we argue that hybridising low- and high-level detectors can improve adversarial robustness, based on their complementary strengths and weaknesses.

深度伪造语义检测对抗鲁棒性多模态

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。