系统梳理生成式AI伪造内容检测技术,揭示其对抗鲁棒性短板。
Unmasking Synthetic Realities in Generative AI: A Comprehensive Review of Adversarially Robust Deepfake Detection Systems
- 分两类检测:合成内容用统计异常与特征提取,真实视频用多模态痕迹定位
- 现有方法在受控环境准确率高,但对细微干扰易失效
- 适合关注AI安全、深度伪造防御的研究者与工程师
生成式人工智能的快速发展推动了深度伪造内容的泛滥——包括完全生成的媒体和经过细微编辑的真实素材——对数字安全、虚假信息防控及身份保护构成挑战。本文系统回顾了当前主流深度伪造检测方法,强调可复现实现以保障透明性与验证性。主要分为两类:(1) 针对完全合成内容的检测,依赖统计异常与层级特征提取;(2) 对真实内容中篡改区域的定位,利用视觉伪影与时间不一致性等多模态线索。这些方法涵盖单模态与多模态框架,在受控环境下表现出较高精度与适应性,通过先进学习技术与跨模态融合有效识别篡改。然而全面评估显示,两类方法在对抗鲁棒性方面均存在不足:对精心设计的对抗扰动(细微修改以逃避检测)高度敏感,削弱了实际应用中的可靠性。这一差距凸显了方法开发与演变威胁环境之间的脱节。为此,我们建立一个精选的GitHub仓库,整合开源实现,支持复现与测试。研究强调未来工作亟需优先考虑对抗韧性,倡导可扩展、模态无关的架构,以应对复杂伪造攻击。本综述总结了当前检测技术的优势与缺陷,并为构建更稳健可信的系统指明方向。
原文摘要 · Abstract (English)
The rapid advancement of Generative Artificial Intelligence has fueled deepfake proliferation-synthetic media encompassing fully generated content and subtly edited authentic material-posing challenges to digital security, misinformation mitigation, and identity preservation. This systematic review evaluates state-of-the-art deepfake detection methodologies, emphasizing reproducible implementations for transparency and validation. We delineate two core paradigms: (1) detection of fully synthetic media leveraging statistical anomalies and hierarchical feature extraction, and (2) localization of manipulated regions within authentic content employing multi-modal cues such as visual artifacts and temporal inconsistencies. These approaches, spanning uni-modal and multi-modal frameworks, demonstrate notable precision and adaptability in controlled settings, effectively identifying manipulations through advanced learning techniques and cross-modal fusion. However, comprehensive assessment reveals insufficient evaluation of adversarial robustness across both paradigms. Current methods exhibit vulnerability to adversarial perturbations-subtle alterations designed to evade detection-undermining reliability in real-world adversarial contexts. This gap highlights critical disconnect between methodological development and evolving threat landscapes. To address this, we contribute a curated GitHub repository aggregating open-source implementations, enabling replication and testing. Our findings emphasize urgent need for future work prioritizing adversarial resilience, advocating scalable, modality-agnostic architectures capable of withstanding sophisticated manipulations. This review synthesizes strengths and shortcomings of contemporary deepfake detection while charting paths toward robust trustworthy systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。