Exploring the Adversarial Robustness of Face Forgery Detection with Decision-based Black-box Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Zhaoyu, Li, Bo, Jiang, Kaixun, Wu, Shuang, Ding, Shouhong, Zhang, Wenqiang
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908645700141056
author Chen, Zhaoyu
Li, Bo
Jiang, Kaixun
Wu, Shuang
Ding, Shouhong
Zhang, Wenqiang
author_facet Chen, Zhaoyu
Li, Bo
Jiang, Kaixun
Wu, Shuang
Ding, Shouhong
Zhang, Wenqiang
contents Face forgery generation technologies generate vivid faces, which have raised public concerns about security and privacy. Many intelligent systems, such as electronic payment and identity verification, rely on face forgery detection. Although face forgery detection has successfully distinguished fake faces, recent studies have demonstrated that face forgery detectors are very vulnerable to adversarial examples. Meanwhile, existing attacks rely on network architectures or training datasets instead of the predicted labels, which leads to a gap in attacking deployed applications. To narrow this gap, we first explore the decision-based attacks on face forgery detection. We identify challenges in directly applying existing decision-based attacks, such as perturbation initialization failure and reduced image quality. To overcome these issues, we propose cross-task perturbation to handle initialization failures by utilizing the high correlation of face features on different tasks. Additionally, inspired by the use of frequency cues in face forgery detection, we introduce the frequency decision-based attack. This attack involves adding perturbations in the frequency domain while constraining visual quality in the spatial domain. Finally, extensive experiments demonstrate that our method achieves state-of-the-art attack performance on FaceForensics++, CelebDF, and industrial APIs, with high query efficiency and guaranteed image quality. Further, the fake faces by our method can pass face forgery detection and face recognition, which exposes the security problems of face forgery detectors.
format Preprint
id arxiv_https___arxiv_org_abs_2310_12017
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Exploring the Adversarial Robustness of Face Forgery Detection with Decision-based Black-box Attacks
Chen, Zhaoyu
Li, Bo
Jiang, Kaixun
Wu, Shuang
Ding, Shouhong
Zhang, Wenqiang
Computer Vision and Pattern Recognition
Computers and Society
Face forgery generation technologies generate vivid faces, which have raised public concerns about security and privacy. Many intelligent systems, such as electronic payment and identity verification, rely on face forgery detection. Although face forgery detection has successfully distinguished fake faces, recent studies have demonstrated that face forgery detectors are very vulnerable to adversarial examples. Meanwhile, existing attacks rely on network architectures or training datasets instead of the predicted labels, which leads to a gap in attacking deployed applications. To narrow this gap, we first explore the decision-based attacks on face forgery detection. We identify challenges in directly applying existing decision-based attacks, such as perturbation initialization failure and reduced image quality. To overcome these issues, we propose cross-task perturbation to handle initialization failures by utilizing the high correlation of face features on different tasks. Additionally, inspired by the use of frequency cues in face forgery detection, we introduce the frequency decision-based attack. This attack involves adding perturbations in the frequency domain while constraining visual quality in the spatial domain. Finally, extensive experiments demonstrate that our method achieves state-of-the-art attack performance on FaceForensics++, CelebDF, and industrial APIs, with high query efficiency and guaranteed image quality. Further, the fake faces by our method can pass face forgery detection and face recognition, which exposes the security problems of face forgery detectors.
title Exploring the Adversarial Robustness of Face Forgery Detection with Decision-based Black-box Attacks
topic Computer Vision and Pattern Recognition
Computers and Society
url https://arxiv.org/abs/2310.12017