用对抗扰动让图像变‘空白画布’,骗过AI识破篡改。
Creating Blank Canvas Against AI-enabled Image Forgery

- 给图像加特定干扰,让SAM模型‘看不见’内容。
- 在多种篡改下,检测准确率超95%。
- 适合数字取证与AI安全研究者使用。
基于AIGC的图像编辑技术极大简化了高真实感图像修改,带来了严重的图像伪造风险。本文提出一种新方法,利用分割一切模型(SAM)进行篡改检测。不同于训练SAM识别篡改区域,我们采取全新策略:将图像转化为神经模型视角下的‘空白画布’,任何修改都会被模型感知。为此,引入对抗扰动使SAM无法‘看见’图像内容,从而在篡改发生时可识别伪造区域。由于SAM具备强大感知能力,普通对抗攻击难以完全欺骗它。因此,我们提出频域感知优化策略,进一步增强其对篡改的定位能力。大量实验表明,该方法在多种篡改场景下均表现优异,检测准确率超过95%。
原文摘要 · Abstract (English)
AIGC-based image editing technology has greatly simplified the realistic-level image modification, causing serious potential risks of image forgery. This paper introduces a new approach to tampering detection using the Segment Anything Model (SAM). Instead of training SAM to identify tampered areas, we propose a novel strategy. The entire image is transformed into a blank canvas from the perspective of neural models. Any modifications to this blank canvas would be noticeable to the models. To achieve this idea, we introduce adversarial perturbations to prevent SAM from ``seeing anything'', allowing it to identify forged regions when the image is tampered with. Due to SAM's powerful perceiving capabilities, naive adversarial attacks cannot completely tame SAM. To thoroughly deceive SAM and make it blind to the image, we introduce a frequency-aware optimization strategy, which further enhances the capability of tamper localization. Extensive experimental results demonstrate the effectiveness of our method.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。