用隐蔽水印提前保护视频,让伪造者一动就露馅。
Can Tainted Pixels Expose Deepfake Videos?

- 在人脸区域注入周期性扰动,伪装成自然像素
- 伪造后水印明显,真实视频扰动极小(LPIPS=0.0042)
- 非专家用户也能识别伪造,适合内容安全防护
公开可获取的人脸编辑工具使非专业人士也能制作深度伪造视频。现有防御多为事后检测,且仅针对静态图像。本文提出TaintedPixels,一种主动保护视频的新型方法,通过不对称可见性设计:原始视频中水印不可见,一旦被黑箱工具篡改则立即显现。该方法在人脸区域的蓝色通道注入结构化周期扰动,并在条纹可见性、色彩偏移和视频级LPIPS约束下优化,支持轻量级运动自适应部署。实验覆盖三种主流视频编辑工具和两种检测器,结果表明其能实现最高伪造假阳性率,同时保持扰动极小(LPIPS=0.0042)。300个不同光照、背景与肤色的视频人类评估显示,受保护源视频的怀疑率仅为3.26%,而来自受保护源的伪造视频被识破率高达90.72%,显著高于未受保护源的56.71%。验证了该方法的有效性。
原文摘要 · Abstract (English)
Publicly-acceesible face-manipulation tools have made deepfake creation accessible to non-expert users. Against these, existing defenses are mostly post-hoc, detecting only after forgery has occurred, and operating on still images rather than videos. Research is lacking in i) the proactive protection of published facial videos against black-box manipulation tools, and in (ii) understanding its perceptual effect on human viewers. We introduce TaintedPixels, a proactive video-protection method built around an asymmetric visibility trade-off: the embedded watermark should remain inconspicuous in the published video but become obvious once a downstream tool manipulates the video. TaintedPixels injects structured periodic perturbations into the blue channel of facial regions and refines them under stripe-visibility, color-cast, and video-level LPIPS budgets, with lightweight motion-adaptive deployment. We believe TaintedPixels is the first proactive defense designed specifically against black-box manipulation tools rather than image-level pipelines or specific surrogate generators. Across three publicly available off-the-shelf video manipulation tools and two off-the-shelf detectors, TaintedPixels attains the highest forgery fake rate while keeping perturbations small (LPIPS = 0.0042). Our non-expert human study, conducted on a diverse set of 300 video stimuli spanning different lighting conditions, backgrounds, and skin tones, shows that protected source videos draw a 3.26% suspicion rate, while forgeries from protected sources are identified as fake much more often than forgeries from unprotected sources (90.72% vs. 56.71%). This validates the effectiveness of TaintedPixels.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。