提出高效视频防御框架,保护人脸视频免遭3D个性化换脸攻击
Efficient and Robust Video Defense Framework against 3D-field Personalized Talking Face
- 通过扰动3D信息获取过程实现防护,保持视频高保真
- 相比最快基线提速47倍,且抗缩放和净化攻击
- 适合关注隐私安全的视频生成研究者使用
当前先进的3D场视频参考说话人脸生成(TFG)方法能实时生成高保真个性化人脸视频,但存在个人肖像被恶意滥用的隐私风险。现有图像级防御需对每帧添加2D扰动,计算成本高、视频质量严重下降,无法有效破坏3D信息。为此,我们提出一种新型高效视频防御框架,通过在3D信息获取阶段施加扰动,在保持高保真度的同时抵御3D-field TFG攻击。具体包括:(1) 相似性引导的参数共享机制提升效率;(2) 多尺度双域注意力模块联合优化空间-频率扰动。大量实验表明,该框架具备强防御能力,相较最快基线提速47倍,且对缩放操作和先进净化攻击保持鲁棒性,消融实验验证了设计有效性。项目开源地址:https://github.com/Richen7418/VDF。
原文摘要 · Abstract (English)
State-of-the-art 3D-field video-referenced Talking Face Generation (TFG) methods synthesize high-fidelity personalized talking-face videos in real time by modeling 3D geometry and appearance from reference portrait video. This capability raises significant privacy concerns regarding malicious misuse of personal portraits. However, no efficient defense framework exists to protect such videos against 3D-field TFG methods. While image-based defenses could apply per-frame 2D perturbations, they incur prohibitive computational costs, severe video quality degradation, failing to disrupt 3D information for video protection. To address this, we propose a novel and efficient video defense framework against 3D-field TFG methods, which protects portrait video by perturbing the 3D information acquisition process while maintain high-fidelity video quality. Specifically, our method introduces: (1) a similarity-guided parameter sharing mechanism for computational efficiency, and (2) a multi-scale dual-domain attention module to jointly optimize spatial-frequency perturbations. Extensive experiments demonstrate that our proposed framework exhibits strong defense capability and achieves a 47x acceleration over the fastest baseline while maintaining high fidelity. Moreover, it remains robust against scaling operations and state-of-the-art purification attacks, and the effectiveness of our design choices is further validated through ablation studies. Our project is available at https://github.com/Richen7418/VDF.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。