arXiv:2504.09451cs.CV2025-04被引 12

用分形水印实现深度伪造的主动检测与定位,兼具鲁棒性与可解释性。

FractalForensics: Proactive Deepfake Detection and Localization via Fractal Watermarks

  • 基于分形特性设计参数驱动的水印生成与加密机制。
  • 在常见图像处理下保持鲁棒,在深度伪造操作下敏感,可定位篡改区域。
  • 适用于需要可解释检测结果的场景,如内容审核与版权保护。

通过鲁棒水印实现深度伪造的主动检测近年来受到关注,但现有方法缺乏定位功能和结果可解释性,且水印鲁棒性不稳定。本文提出新型分形水印系统 FractalForensics,利用分形特征设计参数驱动的水印生成与单向加密流程。构建半脆弱水印框架,训练其对正常图像处理保持鲁棒,对深度伪造操作在黑盒环境下敏感。引入“入口到块”策略,将水印矩阵元素隐式嵌入对应图像块位置,实现深度伪造篡改区域的定位。大量实验表明,该方法在常见图像处理和深度伪造攻击下均表现出良好鲁棒性与脆弱性,优于当前最先进的半脆弱水印算法及被动检测器。同时,通过突出被篡改区域,提供主动检测结果的可解释性。

原文摘要 · Abstract (English)

Proactive Deepfake detection via robust watermarks has seen interest ever since passive Deepfake detectors encountered challenges in identifying high-quality synthetic images. However, while demonstrating reasonable detection performance, they lack localization functionality and explainability in detection results. Additionally, the unstable robustness of watermarks can significantly affect the detection performance. In this study, we propose novel fractal watermarks for proactive Deepfake detection and localization, namely FractalForensics. Benefiting from the characteristics of fractals, we devise a parameter-driven watermark generation pipeline that derives fractal-based watermarks and performs one-way encryption of the selected parameters. Subsequently, we propose a semi-fragile watermarking framework for watermark embedding and recovery, trained to be robust against benign image processing operations and fragile when facing Deepfake manipulations in a black-box setting. Moreover, we introduce an entry-to-patch strategy that implicitly embeds the watermark matrix entries into image patches at corresponding positions, achieving localization of Deepfake manipulations. Extensive experiments demonstrate satisfactory robustness and fragility of our approach against common image processing operations and Deepfake manipulations, outperforming state-of-the-art semi-fragile watermarking algorithms and passive detectors for Deepfake detection. Furthermore, by highlighting the areas manipulated, our method provides explainability for the proactive Deepfake detection results.

深度伪造水印技术可解释性图像安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。