用轮廓混合水印主动防御未知换脸技术,提升安全性和通用性。
Towards Generalized Proactive Defense against Face Swapping with Contour-Hybrid Watermark
- 在人脸轮廓区域嵌入融合身份与纹理的混合水印
- 8种换脸技术下检测准确率超越现有主动/被动方法
- 无需训练时接触换脸技术,适合实际部署场景
换脸技术引发隐私与安全担忧,传统检测因伪造痕迹细微而效果有限。本文提出一种主动防御策略,不依赖具体换脸手法进行训练,也不需预先存储大量信息。针对换脸本质是替换身份但保留背景的特性,聚焦面部轮廓区域,嵌入包含轮廓纹理与身份信息的混合水印(CMark)。该水印在保持图像质量的同时,具备强鲁棒性。在8种主流换脸技术上测试显示,本方法显著优于当前最先进的被动与主动检测器,实现安全性与实用性的良好平衡。
原文摘要 · Abstract (English)
Face swapping, recognized as a privacy and security concern, has prompted considerable defensive research. With the advancements in AI-generated content, the discrepancies between the real and swapped faces have become nuanced. Considering the difficulty of forged traces detection, we shift the focus to the face swapping purpose and proactively embed elaborate watermarks against unknown face swapping techniques. Given that the constant purpose is to swap the original face identity while preserving the background, we concentrate on the regions surrounding the face to ensure robust watermark generation, while embedding the contour texture and face identity information to achieve progressive image determination. The watermark is located in the facial contour and contains hybrid messages, dubbed the contour-hybrid watermark (CMark). Our approach generalizes face swapping detection without requiring any swapping techniques during training and the storage of large-scale messages in advance. Experiments conducted across 8 face swapping techniques demonstrate the superiority of our approach compared with state-of-the-art passive and proactive detectors while achieving a favorable balance between the image quality and watermark robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。