从频率偏差入手,提升伪造图像检测的泛化与鲁棒性。
Frequency Bias Matters: Diving into Robust and Generalized Deep Image Forgery Detection
- 通过频率对齐消除真实与伪造图像的频域差异。
- 在12个检测器、8种生成模型上验证效果,提升检测可靠性。
- 兼具攻防能力,适合安全与取证研究者使用。
随着基于GAN等生成模型的深度伪造图像不断挑战数字世界的安全,检测此类伪造内容已成为关键课题。检测器的泛化能力和鲁棒性是其在开放世界中应对未知生成模型和噪声样本时可靠性的核心。尽管已有大量研究致力于提升这两方面性能,但其根本原因尚未充分揭示,且二者之间是否存在关联仍不明确。现有方法多从取证或反取证角度出发,尚无统一手段能同时提升两方面表现。本文从频域视角提供根本解释:深度神经网络检测器存在频率偏差,可能是导致泛化与鲁棒性问题的原因。基于此,我们提出两步频率对齐方法,消除真实与伪造图像间的频域差异,实现双重效益:既可作为强黑盒攻击手段用于反取证,也可作为通用防御策略增强检测器可靠性。我们进一步开发了相应的攻防实现,并在包含12个检测器、8种伪造模型和5项评估指标的实验中验证了其有效性。
原文摘要 · Abstract (English)
As deep image forgery powered by AI generative models, such as GANs, continues to challenge today's digital world, detecting AI-generated forgeries has become a vital security topic. Generalizability and robustness are two critical concerns of a forgery detector, determining its reliability when facing unknown GANs and noisy samples in an open world. Although many studies focus on improving these two properties, the root causes of these problems have not been fully explored, and it is unclear if there is a connection between them. Moreover, despite recent achievements in addressing these issues from image forensic or anti-forensic aspects, a universal method that can contribute to both sides simultaneously remains practically significant yet unavailable. In this paper, we provide a fundamental explanation of these problems from a frequency perspective. Our analysis reveals that the frequency bias of a DNN forgery detector is a possible cause of generalization and robustness issues. Based on this finding, we propose a two-step frequency alignment method to remove the frequency discrepancy between real and fake images, offering double-sided benefits: it can serve as a strong black-box attack against forgery detectors in the anti-forensic context or, conversely, as a universal defense to improve detector reliability in the forensic context. We also develop corresponding attack and defense implementations and demonstrate their effectiveness, as well as the effect of the frequency alignment method, in various experimental settings involving twelve detectors, eight forgery models, and five metrics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。