通过微小扰动保护人脸隐私,防止深度伪造换脸攻击
FaceSwapGuard: Safeguarding Facial Privacy from DeepFake Threats through Identity Obfuscation
- 在人脸图像中添加不可察觉的干扰,扰乱身份编码器特征
- 使换脸攻击匹配率从90%降至10%以下,有效混淆身份
- 对人类感知影响极小,适合日常社交平台使用
深度伪造对社会构成重大威胁,其中人脸换脸技术尤为突出,可将目标人脸替换为受害者身份。现有方法虽能降低换脸图像质量,但难以真正破坏身份转换过程。为此,本文提出FaceSwapGuard(FSG),一种新型黑盒防御机制。FSG在用户人脸图像中引入不可察觉的扰动,干扰身份编码器提取的特征。当图像在线共享时,这些扰动使换脸技术生成的身份与原始用户显著不符。大量实验表明,FSG可有效抵御多种换脸技术,将人脸匹配率从无防御时的90%降至10%以下。定性与定量分析均证实其能有效迷惑人类判断,具备实际应用价值。此外,本文还探究了影响FSG性能的关键因素,并评估其对抗各类自适应攻击的鲁棒性。
原文摘要 · Abstract (English)
DeepFakes pose a significant threat to our society. One representative DeepFake application is face-swapping, which replaces the identity in a facial image with that of a victim. Although existing methods partially mitigate these risks by degrading the quality of swapped images, they often fail to disrupt the identity transformation effectively. To fill this gap, we propose FaceSwapGuard (FSG), a novel black-box defense mechanism against deepfake face-swapping threats. Specifically, FSG introduces imperceptible perturbations to a user's facial image, disrupting the features extracted by identity encoders. When shared online, these perturbed images mislead face-swapping techniques, causing them to generate facial images with identities significantly different from the original user. Extensive experiments demonstrate the effectiveness of FSG against multiple face-swapping techniques, reducing the face match rate from 90\% (without defense) to below 10\%. Both qualitative and quantitative studies further confirm its ability to confuse human perception, highlighting its practical utility. Additionally, we investigate key factors that may influence FSG and evaluate its robustness against various adaptive adversaries.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。