How Generalizable are Deepfake Image Detectors? An Empirical Study

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Boquan, Sun, Jun, Poskitt, Christopher M., Wang, Xingmei
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916455352631296
author Li, Boquan
Sun, Jun
Poskitt, Christopher M.
Wang, Xingmei
author_facet Li, Boquan
Sun, Jun
Poskitt, Christopher M.
Wang, Xingmei
contents Deepfakes are becoming increasingly credible, posing a significant threat given their potential to facilitate fraud or bypass access control systems. This has motivated the development of deepfake detection methods, in which deep learning models are trained to distinguish between real and synthesized footage. Unfortunately, existing detectors struggle to generalize to deepfakes from datasets they were not trained on, but little work has been done to examine why or how this limitation can be addressed. Especially, those single-modality deepfake images reveal little available forgery evidence, posing greater challenges than detecting deepfake videos. In this work, we present the first empirical study on the generalizability of deepfake detectors, an essential goal for detectors to stay one step ahead of attackers. Our study utilizes six deepfake datasets, five deepfake image detection methods, and two model augmentation approaches, confirming that detectors do not generalize in zero-shot settings. Additionally, we find that detectors are learning unwanted properties specific to synthesis methods and struggling to extract discriminative features, limiting their ability to generalize. Finally, we find that there are neurons universally contributing to detection across seen and unseen datasets, suggesting a possible path towards zero-shot generalizability.
format Preprint
id arxiv_https___arxiv_org_abs_2308_04177
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle How Generalizable are Deepfake Image Detectors? An Empirical Study
Li, Boquan
Sun, Jun
Poskitt, Christopher M.
Wang, Xingmei
Computer Vision and Pattern Recognition
Cryptography and Security
Deepfakes are becoming increasingly credible, posing a significant threat given their potential to facilitate fraud or bypass access control systems. This has motivated the development of deepfake detection methods, in which deep learning models are trained to distinguish between real and synthesized footage. Unfortunately, existing detectors struggle to generalize to deepfakes from datasets they were not trained on, but little work has been done to examine why or how this limitation can be addressed. Especially, those single-modality deepfake images reveal little available forgery evidence, posing greater challenges than detecting deepfake videos. In this work, we present the first empirical study on the generalizability of deepfake detectors, an essential goal for detectors to stay one step ahead of attackers. Our study utilizes six deepfake datasets, five deepfake image detection methods, and two model augmentation approaches, confirming that detectors do not generalize in zero-shot settings. Additionally, we find that detectors are learning unwanted properties specific to synthesis methods and struggling to extract discriminative features, limiting their ability to generalize. Finally, we find that there are neurons universally contributing to detection across seen and unseen datasets, suggesting a possible path towards zero-shot generalizability.
title How Generalizable are Deepfake Image Detectors? An Empirical Study
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2308.04177