用对抗扰动提前保护人脸,防止扩散模型偷换脸
My Face Is Mine, Not Yours: Facial Protection Against Diffusion Model Face Swapping
- 在人脸图像中添加特定扰动,主动干扰扩散模型生成
- 对多种扩散模型生效,防御效果比传统方法提升37%
- 针对面部区域设计局部扰动,更贴近真实攻击场景
扩散模型驱动的深度伪造技术泛滥,带来未经授权的人脸篡改风险。现有防御多为被动检测,本文提出一种主动防御策略:通过对抗扰动预先保护人脸图像,使其无法被扩散模型用于换脸。现有对抗防护主要针对GAN、AE、VAE等生成架构,难以应对扩散模型的独特特性;且多数方法依赖特定模型结构与权重,适用性差。此外,普遍采用全局扰动,未能针对人脸局部特征进行精准防护。本研究设计了面向扩散模型的区域感知对抗扰动方法,在多个主流扩散模型(如Stable Diffusion、DeepFloyd IF)上验证有效性,可在不损害原图视觉质量的前提下,显著降低换脸成功率。
原文摘要 · Abstract (English)
The proliferation of diffusion-based deepfake technologies poses significant risks for unauthorized and unethical facial image manipulation. While traditional countermeasures have primarily focused on passive detection methods, this paper introduces a novel proactive defense strategy through adversarial attacks that preemptively protect facial images from being exploited by diffusion-based deepfake systems. Existing adversarial protection methods predominantly target conventional generative architectures (GANs, AEs, VAEs) and fail to address the unique challenges presented by diffusion models, which have become the predominant framework for high-quality facial deepfakes. Current diffusion-specific adversarial approaches are limited by their reliance on specific model architectures and weights, rendering them ineffective against the diverse landscape of diffusion-based deepfake implementations. Additionally, they typically employ global perturbation strategies that inadequately address the region-specific nature of facial manipulation in deepfakes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。