提出双阶段防御框架,让反深度伪造技术更持久有效。
Boosting Active Defense Persistence: A Two-Stage Defense Framework Combining Interruption and Poisoning Against Deepfake
- 用双重对抗扰动同时干扰伪造结果和攻击者重训练数据
- 实验显示传统方法在对抗重训练下性能急剧下降,本框架保持稳定
- 适合关注长期防御深度伪造的学者与安全工程师
主动防御策略被用于应对深度伪造技术威胁,但其主要挑战在于缺乏持久性,效果常短暂。攻击者可通过收集受保护样本并重新训练模型绕过防御,导致静态防御在模型重训后失效,严重限制实际应用。我们认为,有效防御不仅要扭曲伪造内容,还需阻断攻击者重训模型的适应能力。为此,提出创新的两阶段防御框架(TSDF)。该框架利用文中设计的强度分离机制,通过双重功能的对抗扰动实现两个目标:一是直接扭曲伪造结果;二是作为污染载体,破坏攻击者重训流程中的数据准备环节。通过污染数据源,TSDF旨在阻止攻击者模型适应防御扰动,从而确保防御长期有效。全面实验表明,传统中断方法在对抗重训练时性能显著下降,而本框架展现出强大的双重防御能力,显著提升主动防御的持久性。代码将公开于 https://github.com/vpsg-research/TSDF。
原文摘要 · Abstract (English)
Active defense strategies have been developed to counter the threat of deepfake technology. However, a primary challenge is their lack of persistence, as their effectiveness is often short-lived. Attackers can bypass these defenses by simply collecting protected samples and retraining their models. This means that static defenses inevitably fail when attackers retrain their models, which severely limits practical use. We argue that an effective defense not only distorts forged content but also blocks the model's ability to adapt, which occurs when attackers retrain their models on protected images. To achieve this, we propose an innovative Two-Stage Defense Framework (TSDF). Benefiting from the intensity separation mechanism designed in this paper, the framework uses dual-function adversarial perturbations to perform two roles. First, it can directly distort the forged results. Second, it acts as a poisoning vehicle that disrupts the data preparation process essential for an attacker's retraining pipeline. By poisoning the data source, TSDF aims to prevent the attacker's model from adapting to the defensive perturbations, thus ensuring the defense remains effective long-term. Comprehensive experiments show that the performance of traditional interruption methods degrades sharply when it is subjected to adversarial retraining. However, our framework shows a strong dual defense capability, which can improve the persistence of active defense. Our code will be available at https://github.com/vpsg-research/TSDF.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。