arXiv:2503.18678cs.CV2025-03ICCV被引 15

通过主动扰动隐藏人脸身份,有效防范深度伪造换脸攻击

NullSwap: Proactive Identity Cloaking Against Deepfake Face Swapping

  • 提取源图人脸特征,生成针对性扰动以掩盖身份
  • 在纯黑箱环境下使换脸模型无法正确识别源身份
  • 自适应损失权重提升对不同换脸算法的防御能力

针对生成模型进步导致被动检测高质量深度伪造图像效果下降的问题,主动扰动通过在正常图像中插入信号来阻断深度伪造操作。然而现有方法存在视觉失真、对换脸攻击效果有限、依赖白盒/灰盒训练环境等缺陷。本文分析深度伪造换脸本质,提出保护源图像身份而非目标图像的思路,设计NullSwap:利用身份提取模块获取源图人脸特征,通过扰动模块生成身份引导型扰动;浅层特征与扰动在遮蔽模块融合重建图像。为适配不同换脸算法中的身份提取器,引入动态损失权重以自适应平衡身份损失。实验表明,该方法能有效欺骗多种身份识别模型,在防止换脸模型生成正确源身份图像方面优于现有最优主动防御方法。

原文摘要 · Abstract (English)

Suffering from performance bottlenecks in passively detecting high-quality Deepfake images due to the advancement of generative models, proactive perturbations offer a promising approach to disabling Deepfake manipulations by inserting signals into benign images. However, existing proactive perturbation approaches remain unsatisfactory in several aspects: 1) visual degradation due to direct element-wise addition; 2) limited effectiveness against face swapping manipulation; 3) unavoidable reliance on white- and grey-box settings to involve generative models during training. In this study, we analyze the essence of Deepfake face swapping and argue the necessity of protecting source identities rather than target images, and we propose NullSwap, a novel proactive defense approach that cloaks source image identities and nullifies face swapping under a pure black-box scenario. We design an Identity Extraction module to obtain facial identity features from the source image, while a Perturbation Block is then devised to generate identity-guided perturbations accordingly. Meanwhile, a Feature Block extracts shallow-level image features, which are then fused with the perturbation in the Cloaking Block for image reconstruction. Furthermore, to ensure adaptability across different identity extractors in face swapping algorithms, we propose Dynamic Loss Weighting to adaptively balance identity losses. Experiments demonstrate the outstanding ability of our approach to fool various identity recognition models, outperforming state-of-the-art proactive perturbations in preventing face swapping models from generating images with correct source identities.

身份保护深度伪造主动防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。