用隐写技术隐藏人脸,检测时无需还原,隐私安全且不被察觉。
StegaFFD: Privacy-Preserving Face Forgery Detection via Fine-Grained Steganographic Domain Lifting
- 将人脸隐写到自然图像中,在隐写域直接检测伪造痕迹。
- 提出低频抑制与频域差分注意力机制,提升隐蔽特征识别能力。
- 适合注重隐私保护又需保持检测精度的面部伪造检测场景。
现有面部伪造检测(FFD)模型通常假设可访问原始人脸图像。在客户端-服务器架构下,私密人脸数据可能在传输中被截获或由不可信服务器泄露。以往的隐私保护方法如匿名化、加密或失真虽部分缓解泄露风险,但常引入明显语义畸变,易引起攻击者警觉,导致攻防对抗升级。同时,这些方法对图像内容的大幅修改会引入退化或伪影,干扰依赖细微伪造痕迹的FFD模型。受图像隐写技术高保真隐藏与恢复的启发,我们提出基于隐写的面部伪造检测框架(StegaFFD),将人脸图像嵌入自然载体图中,并在隐写域直接执行检测,避免还原过程。然而,隐藏的伪造特征极其微弱,且受载体语义干扰严重。为此,我们设计低频感知分解(LFAD)和空间-频率差分注意力(SFDA),抑制低频载体语义干扰,增强对隐藏人脸特征的感知。此外,引入隐写域对齐(SDA),使隐写后人脸表征与原始表征对齐,提升模型在隐写域中捕捉细微人脸线索的能力。在七个FFD数据集上的大量实验表明,StegaFFD实现了强不可感知性,不引发攻击者怀疑,且相比现有隐私保护方法更有效地保持了检测准确率。
原文摘要 · Abstract (English)
Most existing Face Forgery Detection (FFD) models assume access to raw face images. In practice, under a client-server framework, private facial data may be intercepted during transmission or leaked by untrusted servers. Previous privacy protection approaches, such as anonymization, encryption, or distortion, partly mitigate leakage but often introduce severe semantic distortion, making images appear obviously protected. This alerts attackers, provoking more aggressive strategies and turning the process into a cat-and-mouse game. Moreover, these methods heavily manipulate image contents, introducing degradation or artifacts that may confuse FFD models, which rely on extremely subtle forgery traces. Inspired by advances in image steganography, which enable high-fidelity hiding and recovery, we propose a Stega}nography-based Face Forgery Detection framework (StegaFFD) to protect privacy without raising suspicion. StegaFFD hides facial images within natural cover images and directly conducts forgery detection in the steganographic domain. However, the hidden forgery-specific features are extremely subtle and interfered with by cover semantics, posing significant challenges. To address this, we propose Low-Frequency-Aware Decomposition (LFAD) and Spatial-Frequency Differential Attention (SFDA), which suppress interference from low-frequency cover semantics and enhance hidden facial feature perception. Furthermore, we introduce Steganographic Domain Alignment (SDA) to align the representations of hidden faces with those of their raw counterparts, enhancing the model's ability to perceive subtle facial cues in the steganographic domain. Extensive experiments on seven FFD datasets demonstrate that StegaFFD achieves strong imperceptibility, avoids raising attackers' suspicion, and better preserves FFD accuracy compared to existing facial privacy protection methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。