arXiv:2509.07178cs.CV2025-09被引 2

人脸增强会降低深度伪造检测准确率,可能被用于逃避识别。

Realism to Deception: Investigating Deepfake Detectors Against Face Enhancement

  • 用传统图像处理和GAN方法测试增强对检测器的影响。
  • 基础滤镜使误检率升至64.63%,GAN技术更高达75.12%。
  • 提醒需开发更鲁棒的检测模型,适合安全与取证研究者。

人脸增强技术虽提升视觉质量,但会无意间扭曲生物特征,显著降低深度伪造检测器的准确性。本研究假设此类技术在改善感知效果的同时,会削弱检测性能。通过系统评估常用的人脸增强方法是否具备反取证作用,我们使用传统图像处理与先进的GAN增强技术,检验了深伪检测器的鲁棒性。重点分析了朴素、空间与频域检测方法的效果。此外,通过对抗训练实验,评估模型暴露于增强变换后是否能提升鲁棒性。在FaceForensics++、DeepFakeDetection和CelebDF-v2数据集上的实验表明,即使基础增强滤镜也能显著降低检测准确率,最高误检率(ASR)达64.63%;而GAN-based技术进一步利用这些漏洞,最高达到75.12%。结果证明,人脸增强可有效充当反取证工具,凸显了开发更具韧性与适应性的溯源方法的必要性。

原文摘要 · Abstract (English)

Face enhancement techniques are widely used to enhance facial appearance. However, they can inadvertently distort biometric features, leading to significant decrease in the accuracy of deepfake detectors. This study hypothesizes that these techniques, while improving perceptual quality, can degrade the performance of deepfake detectors. To investigate this, we systematically evaluate whether commonly used face enhancement methods can serve an anti-forensic role by reducing detection accuracy. We use both traditional image processing methods and advanced GAN-based enhancements to evaluate the robustness of deepfake detectors. We provide a comprehensive analysis of the effectiveness of these enhancement techniques, focusing on their impact on Naïve, Spatial, and Frequency-based detection methods. Furthermore, we conduct adversarial training experiments to assess whether exposure to face enhancement transformations improves model robustness. Experiments conducted on the FaceForensics++, DeepFakeDetection, and CelebDF-v2 datasets indicate that even basic enhancement filters can significantly reduce detection accuracy achieving ASR up to 64.63\%. In contrast, GAN-based techniques further exploit these vulnerabilities, achieving ASR up to 75.12\%. Our results demonstrate that face enhancement methods can effectively function as anti-forensic tools, emphasizing the need for more resilient and adaptive forensic methods.

深度伪造反取证人脸识别GAN

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。