arXiv:2606.31703cs.CV2026-06中稿 · CVPR

通过联合约束潜在空间与空间区域,提升人脸换脸伪造的防御效果。

Phantom: A Unified Face-Swap Deepfake Protection Framework with Latent and Spatial Constraints

论文配图:Phantom: A Unified Face-Swap Deepfake Protection Framework with Latent and Spatial Constraints
图 1 · 摘自论文原文
  • 自适应生成保属性的人脸迁移目标,指导潜在空间优化。
  • 在语义相关面部区域施加掩码扰动,提升防御成功率27.8%以上。
  • 适用于多种换脸场景,兼顾防御效果与图像视觉质量。

人脸换脸深度伪造对个人隐私构成日益严重的威胁。尽管对抗方法在黑盒人脸识别模型上表现良好,但在换脸场景中的应用仍不充分。现有方法依赖固定或随机目标,导致潜在引导模糊;缺乏显式空间约束,使扰动扩散至无关区域。身份风格解耦还抑制了生成过程中的对抗信号。本文提出Phantom,一个统一的换脸伪造防护框架,联合约束扰动在潜在空间和空间域的表现。Phantom自适应合成身份迁移但属性保持的目标,引导身份感知的潜在优化,并将扰动限制在语义相关的面部区域。在UniFace、INSwapper和SimSwap等先进换脸方法上的实验表明,Phantom在躲避攻击场景中分别提升27.8%、25.6%和16.6%的防护成功率,同时改善图像质量。此外,其在冒名攻击场景下也表现出更强泛化能力,防护成功率最高提升10.2%,并提高感知保真度。结果验证了联合利用潜在与空间约束在鲁棒且一致的面部隐私保护中的有效性。

原文摘要 · Abstract (English)

Face-swapping deepfakes pose an escalating threat to personal privacy by enabling unauthorized identity manipulation. While adversarial approaches have demonstrated success against black-box face recognition (FR) models, their applicability to face-swapping scenarios remains underexplored. In particular, reliance on fixed or random targets yields ambiguous latent guidance, and the lack of explicit spatial constraints causes perturbations to spill into identity-irrelevant regions. These issues are further exacerbated by identity-style disentanglement, which suppresses adversarial signals during deepfake generation. In this paper, we present Phantom, a unified face-swap deepfake protection framework that jointly constrains perturbations in latent and spatial domains. Phantom adaptively synthesizes identity-shifted yet attribute-preserving targets to guide identity-aware latent optimization, and applies masked perturbations confined to semantically relevant facial regions. Extensive experiments on state-of-the-art face-swapping deepfakes demonstrate that Phantom improves protection success rates in dodging scenarios by 27.8%, 25.6%, and 16.6% on UniFace, INSwapper, and SimSwap, respectively, while also enhancing visual quality. Furthermore, Phantom generalizes to impersonation scenario, yielding up to 10.2% higher protection while improving perceptual fidelity. These results underscore the effectiveness of jointly leveraging latent and spatial constraints for robust and coherent facial privacy protection.

深度伪造防护人脸换脸对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。