幻影封印:具有身份/上下文保护和取证追踪的主动式深度伪造防御
PhantomSeal: Proactive Deepfakes Defense with Identity/Context Protection and Forensic Tracing
浏览论文内容
中文总结 AI 辅助
针对深度伪造尤其是面部交换攻击挑战,提出幻影封印主动防御,用新颖伪装技术嵌入身份作标识符,引导生成类似所选身份内容,防止面部交换并支持取证追踪,经实验验证其有效性和鲁棒性。
中文摘要 AI 辅助
深度伪造,尤其是面部交换攻击,给科学、工程和社会领域的真实性、安全性和伦理带来重大挑战。虽然现有多数检测/追踪方法是事后操作,但旨在深度伪造生成前进行干预的主动防御在实际效果方面仍很有限。本文提出幻影封印,这是首个能同时保护用户图像身份和上下文不被用于面部交换攻击并支持取证追踪的主动防御。我们提出一种新颖的伪装技术,将选定身份作为隐秘标识符嵌入。该机制引导深度伪造生成过程产生类似所选伪装身份的内容,防止成功的面部交换,同时实现有效的基于特征的取证分析。通过在不同面部交换架构和模型上的大量实验证明了幻影封印的有效性和鲁棒性。例如,它将先进的深度伪造模型SimSwap的攻击成功率降至0.30%,并能正确识别97.97%的被操纵内容。代码可在该https网址获取。
英文摘要
Deepfakes, especially face-swapping attacks, pose significant challenges to authenticity, security, and ethics across science, engineering, and society. While most existing detection/tracing approaches operate post hoc, proactive defenses that aim to intervene before deepfake generation remain limited in terms of real-world effectiveness. In this paper, we present PhantomSeal, the first proactive defense to simultaneously protect both the identity and the context of users' images from being used in face-swapping attacks, while supporting forensic tracing. We present a novel cloaking technique that embeds a selected identity as a stealthy identifier. This mechanism steers the deepfake generation process toward producing content that resembles the chosen cloak identity, thereby preventing successful face-swapping while enabling effective feature-based forensic analysis. The effectiveness and robustness of PhantomSeal is demonstrated in extensive experiments across different face-swapping architectures and models. For example, it reduces the attack success rate of SimSwap, an advanced deepfake model, to 0.30%, and correctly identifies 97.97% of manipulated content. The source codes is available at https://github.com/LiangqinRen/PhantomSeal.