arXiv:2512.07228cs.CVcs.AI2025-12

提出新方法提升防DeepFake扰动在图像变换下的鲁棒性

Towards Robust Protective Perturbation against DeepFake Face Swapping

  • 用强化学习自适应生成扰动,动态选择关键变换进行防御
  • 在30种变换下平均鲁棒性提升26%,极端变换下最高增30%
  • 适合关注隐私保护与模型抗攻击能力的研究者

DeepFake人脸替换技术可生成高度逼真的身份伪造内容,带来严重隐私与安全风险。现有防御方法通过在图像中嵌入不可见扰动来对抗,但这类扰动常被压缩、缩放等基础操作破坏。本文系统分析了六类共30种图像变换,发现防护鲁棒性对训练所用变换选择极为敏感,标准期望变换(EOT)的均匀采样策略存在根本缺陷。为此,我们提出期望变换的可学习分布框架(EOLT),将变换分布设为可学习组件。EOLT采用策略网络,通过强化学习自动识别关键变换,并生成针对具体样本的扰动,实现对防御瓶颈的显式建模,同时保持良好泛化能力。大量实验表明,该方法显著优于当前最优方案,平均鲁棒性提升26%,在挑战性变换类别上最高达30%提升。

原文摘要 · Abstract (English)

DeepFake face swapping enables highly realistic identity forgeries, posing serious privacy and security risks. A common defence embeds invisible perturbations into images, but these are fragile and often destroyed by basic transformations such as compression or resizing. In this paper, we first conduct a systematic analysis of 30 transformations across six categories and show that protection robustness is highly sensitive to the choice of training transformations, making the standard Expectation over Transformation (EOT) with uniform sampling fundamentally suboptimal. Motivated by this, we propose Expectation Over Learned distribution of Transformation (EOLT), the framework to treat transformation distribution as a learnable component rather than a fixed design choice. Specifically, EOLT employs a policy network that learns to automatically prioritize critical transformations and adaptively generate instance-specific perturbations via reinforcement learning, enabling explicit modeling of defensive bottlenecks while maintaining broad transferability. Extensive experiments demonstrate that our method achieves substantial improvements over state-of-the-art approaches, with 26% higher average robustness and up to 30% gains on challenging transformation categories.

DeepFake防御图像鲁棒性强化学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。