Hiding Faces in Plain Sight: Defending DeepFakes by Disrupting Face Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhu, Delong, Li, Yuezun, Wu, Baoyuan, Zhou, Jiaran, Wang, Zhibo, Lyu, Siwei
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929610337288192
author Zhu, Delong
Li, Yuezun
Wu, Baoyuan
Zhou, Jiaran
Wang, Zhibo
Lyu, Siwei
author_facet Zhu, Delong
Li, Yuezun
Wu, Baoyuan
Zhou, Jiaran
Wang, Zhibo
Lyu, Siwei
contents This paper investigates the feasibility of a proactive DeepFake defense framework, {\em FacePosion}, to prevent individuals from becoming victims of DeepFake videos by sabotaging face detection. The motivation stems from the reliance of most DeepFake methods on face detectors to automatically extract victim faces from videos for training or synthesis (testing). Once the face detectors malfunction, the extracted faces will be distorted or incorrect, subsequently disrupting the training or synthesis of the DeepFake model. To achieve this, we adapt various adversarial attacks with a dedicated design for this purpose and thoroughly analyze their feasibility. Based on FacePoison, we introduce {\em VideoFacePoison}, a strategy that propagates FacePoison across video frames rather than applying them individually to each frame. This strategy can largely reduce the computational overhead while retaining the favorable attack performance. Our method is validated on five face detectors, and extensive experiments against eleven different DeepFake models demonstrate the effectiveness of disrupting face detectors to hinder DeepFake generation.
format Preprint
id arxiv_https___arxiv_org_abs_2412_01101
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Hiding Faces in Plain Sight: Defending DeepFakes by Disrupting Face Detection
Zhu, Delong
Li, Yuezun
Wu, Baoyuan
Zhou, Jiaran
Wang, Zhibo
Lyu, Siwei
Computer Vision and Pattern Recognition
Cryptography and Security
This paper investigates the feasibility of a proactive DeepFake defense framework, {\em FacePosion}, to prevent individuals from becoming victims of DeepFake videos by sabotaging face detection. The motivation stems from the reliance of most DeepFake methods on face detectors to automatically extract victim faces from videos for training or synthesis (testing). Once the face detectors malfunction, the extracted faces will be distorted or incorrect, subsequently disrupting the training or synthesis of the DeepFake model. To achieve this, we adapt various adversarial attacks with a dedicated design for this purpose and thoroughly analyze their feasibility. Based on FacePoison, we introduce {\em VideoFacePoison}, a strategy that propagates FacePoison across video frames rather than applying them individually to each frame. This strategy can largely reduce the computational overhead while retaining the favorable attack performance. Our method is validated on five face detectors, and extensive experiments against eleven different DeepFake models demonstrate the effectiveness of disrupting face detectors to hinder DeepFake generation.
title Hiding Faces in Plain Sight: Defending DeepFakes by Disrupting Face Detection
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2412.01101