arXiv:2510.12468cs.CV2025-10被引 4

提出新方法生成更难被检测的深度伪造图像。

MS-GAGA: Metric-Selective Guided Adversarial Generation Attack

  • 分两阶段:先生成候选攻击样本,再按效果和视觉相似度筛选。
  • 对未见过的检测器攻击成功率提升27%。
  • 适合研究对抗攻击或深度伪造防御的人参考。

我们提出MS-GAGA(Metric-Selective Guided Adversarial Generation Attack),一种用于黑盒环境下针对深度伪造检测器的两阶段可迁移且视觉不可察觉的对抗样本生成框架。第一阶段采用双流攻击模块生成候选样本:MNTD-PGD通过优化梯度计算,在小扰动预算下表现更优;SG-PGD则将扰动集中在视觉显著区域。这种互补设计扩大了对抗搜索空间,提升了跨模型迁移能力。第二阶段引入基于指标的筛选模块,综合评估候选样本在黑盒模型上的攻击成功率及其与原始图像的结构相似性(SSIM)。通过联合优化可迁移性与不可察觉性,MS-GAGA相比现有最优攻击方法,在未见检测器上实现了最高达27%的误分类率提升。

原文摘要 · Abstract (English)

We present MS-GAGA (Metric-Selective Guided Adversarial Generation Attack), a two-stage framework for crafting transferable and visually imperceptible adversarial examples against deepfake detectors in black-box settings. In Stage 1, a dual-stream attack module generates adversarial candidates: MNTD-PGD applies enhanced gradient calculations optimized for small perturbation budgets, while SG-PGD focuses perturbations on visually salient regions. This complementary design expands the adversarial search space and improves transferability across unseen models. In Stage 2, a metric-aware selection module evaluates candidates based on both their success against black-box models and their structural similarity (SSIM) to the original image. By jointly optimizing transferability and imperceptibility, MS-GAGA achieves up to 27% higher misclassification rates on unseen detectors compared to state-of-the-art attacks.

对抗攻击深度伪造生成模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。