提出动态加权框架,让对抗扰动更均衡地打击各类深度伪造模型。
Adaptive Equilibrium: Dynamic Weighting Framework for Generalized Interruption of DeepFake Models

- 基于实时损失反馈动态调整干扰权重
- 在多架构测试中保持一致的干扰成功率
- 适合需要统一防御能力的对抗性应用场景
通用对抗扰动的生成受限于中断不平衡这一根本瓶颈。我们发现,传统静态梯度归一化无法解决模型架构冲突,导致优化过程偏向易受攻击模型而忽视抗干扰模型。为实现高且均匀的干扰效果,必须打破这种不平衡,达到自适应平衡。本文提出自适应平衡框架(AEF),通过动态加权机制,根据实时损失反馈为最抗干扰模型分配更高权重,使优化从平均情况转向动态平衡,推动扰动进入均匀有效的均衡状态。大量实验表明,AEF 在多种不同架构上实现了更均衡的中断表现,保持了稳定的干扰成功率。
原文摘要 · Abstract (English)
The advancement of generalized deepfake disruption is constrained by the interruption imbalance, a fundamental bottleneck inherent to the generation of universal perturbations. We reveal that conventional static gradient normalization fundamentally struggles to resolve architectural conflicts, causing the optimization to bias towards susceptible models while neglecting resistant ones. We argue that achieving high and uniform effectiveness requires resolving this imbalance by reaching an adaptive equilibrium. We propose the Adaptive Equilibrium Framework (AEF), which employs a dynamic weighting mechanism that utilizes real-time loss feedback to adaptively assign greater interruption weights to the most resistant models. This approach shifts the optimization from an average-case problem to finding a dynamic balance, driving the perturbation to a uniformly effective equilibrium state. Comprehensive experiments validate that AEF achieves a more balanced interruption performance, maintaining a consistent interruption success rate across the evaluated diverse architectures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。