Uncovering and Mitigating Destructive Multi-Embedding Attacks in Deepfake Proactive Forensics

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Jia, Lixin, Sun, Haiyang, Guo, Zhiqing, Diao, Yunfeng, Ma, Dan, Yang, Gaobo
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917104626696192
author Jia, Lixin
Sun, Haiyang
Guo, Zhiqing
Diao, Yunfeng
Ma, Dan
Yang, Gaobo
author_facet Jia, Lixin
Sun, Haiyang
Guo, Zhiqing
Diao, Yunfeng
Ma, Dan
Yang, Gaobo
contents With the rapid evolution of deepfake technologies and the wide dissemination of digital media, personal privacy is facing increasingly serious security threats. Deepfake proactive forensics, which involves embedding imperceptible watermarks to enable reliable source tracking, serves as a crucial defense against these threats. Although existing methods show strong forensic ability, they rely on an idealized assumption of single watermark embedding, which proves impractical in real-world scenarios. In this paper, we formally define and demonstrate the existence of Multi-Embedding Attacks (MEA) for the first time. When a previously protected image undergoes additional rounds of watermark embedding, the original forensic watermark can be destroyed or removed, rendering the entire proactive forensic mechanism ineffective. To address this vulnerability, we propose a general training paradigm named Adversarial Interference Simulation (AIS). Rather than modifying the network architecture, AIS explicitly simulates MEA scenarios during fine-tuning and introduces a resilience-driven loss function to enforce the learning of sparse and stable watermark representations. Our method enables the model to maintain the ability to extract the original watermark correctly even after a second embedding. Extensive experiments demonstrate that our plug-and-play AIS training paradigm significantly enhances the robustness of various existing methods against MEA.
format Preprint
id arxiv_https___arxiv_org_abs_2508_17247
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Uncovering and Mitigating Destructive Multi-Embedding Attacks in Deepfake Proactive Forensics
Jia, Lixin
Sun, Haiyang
Guo, Zhiqing
Diao, Yunfeng
Ma, Dan
Yang, Gaobo
Computer Vision and Pattern Recognition
With the rapid evolution of deepfake technologies and the wide dissemination of digital media, personal privacy is facing increasingly serious security threats. Deepfake proactive forensics, which involves embedding imperceptible watermarks to enable reliable source tracking, serves as a crucial defense against these threats. Although existing methods show strong forensic ability, they rely on an idealized assumption of single watermark embedding, which proves impractical in real-world scenarios. In this paper, we formally define and demonstrate the existence of Multi-Embedding Attacks (MEA) for the first time. When a previously protected image undergoes additional rounds of watermark embedding, the original forensic watermark can be destroyed or removed, rendering the entire proactive forensic mechanism ineffective. To address this vulnerability, we propose a general training paradigm named Adversarial Interference Simulation (AIS). Rather than modifying the network architecture, AIS explicitly simulates MEA scenarios during fine-tuning and introduces a resilience-driven loss function to enforce the learning of sparse and stable watermark representations. Our method enables the model to maintain the ability to extract the original watermark correctly even after a second embedding. Extensive experiments demonstrate that our plug-and-play AIS training paradigm significantly enhances the robustness of various existing methods against MEA.
title Uncovering and Mitigating Destructive Multi-Embedding Attacks in Deepfake Proactive Forensics
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2508.17247