arXiv:2512.15182cs.CV2025-12被引 3

提出可验证真伪的重生成框架,提升检测可靠性与抗攻击能力。

Robust and Calibrated Detection of Authentic Multimedia Content

  • 通过重生成技术判断内容是否真实,控制误报率
  • 在计算资源受限下仍能抵御对手攻击,误报率可控
  • 适用于多模态内容,适合高精度场景的检测需求

生成模型可合成高度逼真的内容(即深度伪造),已被大规模滥用以破坏数字媒体真实性。现有深度伪造检测方法不可靠,原因有二:(i) 事后区分非真实内容往往不可能(如记忆样本存在),导致误报率无上限;(ii) 检测缺乏鲁棒性,攻击者可用极少计算资源近乎完美绕过已知检测器。为此,我们提出一种重生成框架,用于判断样本是否真实或其真实性是否可合理质疑。主要贡献有二:首先,证明所提校准重生成方法是验证真实样本最可靠的方式,同时保持可控的低误报率;其次,展示该方法在相同计算预算下对高效攻击者具备对抗鲁棒性,而此前方法极易被规避。本方法支持多模态,并利用最先进的反演技术。

原文摘要 · Abstract (English)

Generative models can synthesize highly realistic content, so-called deepfakes, that are already being misused at scale to undermine digital media authenticity. Current deepfake detection methods are unreliable for two reasons: (i) distinguishing inauthentic content post-hoc is often impossible (e.g., with memorized samples), leading to an unbounded false positive rate (FPR); and (ii) detection lacks robustness, as adversaries can adapt to known detectors with near-perfect accuracy using minimal computational resources. To address these limitations, we propose a resynthesis framework to determine if a sample is authentic or if its authenticity can be plausibly denied. We make two key contributions focusing on the high-precision, low-recall setting against efficient (i.e., compute-restricted) adversaries. First, we demonstrate that our calibrated resynthesis method is the most reliable approach for verifying authentic samples while maintaining controllable, low FPRs. Second, we show that our method achieves adversarial robustness against efficient adversaries, whereas prior methods are easily evaded under identical compute budgets. Our approach supports multiple modalities and leverages state-of-the-art inversion techniques.

深度伪造检测鲁棒性重生成低误报

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。