arXiv:2508.20595cs.CV2025-08中稿 · IEEE IJCNN 2025

用低频扰动主动破坏人脸换脸生成,提升防御效果

Disruptive Attacks on Face Swapping via Low-Frequency Perceptual Perturbations

  • 通过低频扰动直接干扰生成过程,而非仅影响检测
  • 在CelebA-HQ和LFW上显著降低换脸效果,防御成功率高
  • 保留高清细节,输出仍自然可信,适合防御应用

深度伪造技术(基于生成对抗网络)对隐私与社会安全构成重大威胁。现有检测方法多为被动型,仅能事后分析,无法阻止攻击。为此,我们提出一种基于低频感知扰动的主动防御方法,旨在破坏人脸换脸生成过程,降低生成内容的质量与自然度。不同于以往仅影响分类准确率的低频扰动方法,本方法直接作用于深度伪造的生成环节。通过结合频率域与空间域特征,利用离散小波变换(DWT)提取低频分量,生成可引入伪影但保留高频细节的扰动,确保输出视觉上仍合理。设计了包含编码器、扰动生成器和解码器的完整架构。在CelebA-HQ和LFW数据集上的实验表明,该方法显著降低了人脸换脸的有效性,提升了防御成功率,同时保持了良好的视觉质量。

原文摘要 · Abstract (English)

Deepfake technology, driven by Generative Adversarial Networks (GANs), poses significant risks to privacy and societal security. Existing detection methods are predominantly passive, focusing on post-event analysis without preventing attacks. To address this, we propose an active defense method based on low-frequency perceptual perturbations to disrupt face swapping manipulation, reducing the performance and naturalness of generated content. Unlike prior approaches that used low-frequency perturbations to impact classification accuracy,our method directly targets the generative process of deepfake techniques. We combine frequency and spatial domain features to strengthen defenses. By introducing artifacts through low-frequency perturbations while preserving high-frequency details, we ensure the output remains visually plausible. Additionally, we design a complete architecture featuring an encoder, a perturbation generator, and a decoder, leveraging discrete wavelet transform (DWT) to extract low-frequency components and generate perturbations that disrupt facial manipulation models. Experiments on CelebA-HQ and LFW demonstrate significant reductions in face-swapping effectiveness, improved defense success rates, and preservation of visual quality.

深度伪造主动防御低频扰动人脸换脸

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。