FaceShield: Defending Facial Image against Deepfake Threats

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jeong, Jaehwan, In, Sumin, Kim, Sieun, Shin, Hannie, Jeong, Jongheon, Yoon, Sang Ho, Chung, Jaewook, Kim, Sangpil
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909971345571840
author Jeong, Jaehwan
In, Sumin
Kim, Sieun
Shin, Hannie
Jeong, Jongheon
Yoon, Sang Ho
Chung, Jaewook
Kim, Sangpil
author_facet Jeong, Jaehwan
In, Sumin
Kim, Sieun
Shin, Hannie
Jeong, Jongheon
Yoon, Sang Ho
Chung, Jaewook
Kim, Sangpil
contents The rising use of deepfakes in criminal activities presents a significant issue, inciting widespread controversy. While numerous studies have tackled this problem, most primarily focus on deepfake detection. These reactive solutions are insufficient as a fundamental approach for crimes where authenticity is disregarded. Existing proactive defenses also have limitations, as they are effective only for deepfake models based on specific Generative Adversarial Networks (GANs), making them less applicable in light of recent advancements in diffusion-based models. In this paper, we propose a proactive defense method named FaceShield, which introduces novel defense strategies targeting deepfakes generated by Diffusion Models (DMs) and facilitates defenses on various existing GAN-based deepfake models through facial feature extractor manipulations. Our approach consists of three main components: (i) manipulating the attention mechanism of DMs to exclude protected facial features during the denoising process, (ii) targeting prominent facial feature extraction models to enhance the robustness of our adversarial perturbation, and (iii) employing Gaussian blur and low-pass filtering techniques to improve imperceptibility while enhancing robustness against JPEG compression. Experimental results on the CelebA-HQ and VGGFace2-HQ datasets demonstrate that our method achieves state-of-the-art performance against the latest deepfake models based on DMs, while also exhibiting transferability to GANs and showcasing greater imperceptibility of noise along with enhanced robustness. Code is available here: https://github.com/kuai-lab/iccv25_faceshield
format Preprint
id arxiv_https___arxiv_org_abs_2412_09921
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle FaceShield: Defending Facial Image against Deepfake Threats
Jeong, Jaehwan
In, Sumin
Kim, Sieun
Shin, Hannie
Jeong, Jongheon
Yoon, Sang Ho
Chung, Jaewook
Kim, Sangpil
Computer Vision and Pattern Recognition
The rising use of deepfakes in criminal activities presents a significant issue, inciting widespread controversy. While numerous studies have tackled this problem, most primarily focus on deepfake detection. These reactive solutions are insufficient as a fundamental approach for crimes where authenticity is disregarded. Existing proactive defenses also have limitations, as they are effective only for deepfake models based on specific Generative Adversarial Networks (GANs), making them less applicable in light of recent advancements in diffusion-based models. In this paper, we propose a proactive defense method named FaceShield, which introduces novel defense strategies targeting deepfakes generated by Diffusion Models (DMs) and facilitates defenses on various existing GAN-based deepfake models through facial feature extractor manipulations. Our approach consists of three main components: (i) manipulating the attention mechanism of DMs to exclude protected facial features during the denoising process, (ii) targeting prominent facial feature extraction models to enhance the robustness of our adversarial perturbation, and (iii) employing Gaussian blur and low-pass filtering techniques to improve imperceptibility while enhancing robustness against JPEG compression. Experimental results on the CelebA-HQ and VGGFace2-HQ datasets demonstrate that our method achieves state-of-the-art performance against the latest deepfake models based on DMs, while also exhibiting transferability to GANs and showcasing greater imperceptibility of noise along with enhanced robustness. Code is available here: https://github.com/kuai-lab/iccv25_faceshield
title FaceShield: Defending Facial Image against Deepfake Threats
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2412.09921