用真实相机噪声骗过深度伪造检测,无需复杂优化
ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors

- 通过可逆ISP将生成图像转为RAW域,注入真实传感器噪声
- 在不改变视觉外观的前提下,使多种检测器失效率超90%
- 适合研究伪造防御、媒体安全或物理仿真的人士
生成模型的快速发展催生了对深度伪造检测器最坏情况鲁棒性的迫切需求。本文揭示了现有取证范式的一个根本盲点:当人工智能生成内容被赋予真实物理成像特征时,现有检测器的效果急剧下降。我们提出,真实照片天然携带由光学传感器和图像信号处理(ISP)流水线留下的硬件内在统计签名,而纯数据驱动的生成模型中完全缺失这些特征。基于此,我们设计了ISPCloak——一种无需优化的对抗攻击框架,通过操控ISP流水线误导检测器判断。该方法首先利用可逆ISP网络将图像映射至原始(RAW)域,再通过注入真实的泊松-高斯传感器噪声并执行正向ISP重建,无缝嵌入真实相机的复杂统计先验。结合生成伪影抑制与自适应掩码策略,该流程实现超高速对抗样本生成。大量实验表明,嵌入真实物理扰动可从根本上破坏多种主流检测机制,生成普遍可逃避且视觉不可察觉的对抗样本。
原文摘要 · Abstract (English)
The rapid advancement of generative models has spurred the critical need to evaluate the worst-case robustness of deepfake detectors. In this paper, we reveal a fundamental blind spot in current forensic paradigms: while existing detectors excel at capturing digital synthesis artifacts, their effectiveness drops drastically when AI-generated content is cloaked in authentic physical imaging characteristics. We posit that genuine photographs inherently possess hardware-intrinsic statistical signatures, which are imperceptible footprints imprinted by optical sensors and Image Signal Processing (ISP) pipelines, and are fundamentally absent in purely data-driven generative models. Driven by this insight, we propose ISPCloak, a novel optimization-free adversarial attack framework that explicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors. Rather than relying on computationally expensive gradient perturbations, our method first employs an Invertible ISP network to project images into the RAW domain. Then, we seamlessly imprint the complex statistical priors of real cameras onto AI-generated images by injecting realistic Poisson-Gaussian sensor noise and conducting forward ISP reconstruction. Synergized with generative artifact suppression and adaptive masking, this streamlined physical simulation enables ultra-fast generation of adversarial examples. Extensive experiments show that embedding authentic physical perturbations fundamentally disrupts a broad range of current detection mechanisms, yielding universally evasive adversarial examples with imperceptible visual alterations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。