arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ISPCloak:利用互联网服务提供商实现针对深度伪造检测器的无优化物理伪装

ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors

Jiale Zhao, Jiajun Wan, Lei Tang, Ye Qin, Kebing Jin, Jinghui Qin

arXiv 2607.21897首次发表:更新:

发表机构

Guangdong University of Technology; Guizhou Provincial Laboratory of Big Data, State Key Laboratory of Public Big Data, Guizhou University(广东工业大学; 贵州大学大数据省级重点实验室、公共大数据国家重点实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对深度伪造检测器的对抗攻击,提出ISPCloak框架,利用ISP管道,通过投影到RAW域、注入噪声和前向ISP重建等,将真实相机统计先验印在生成图像上,快速生成对抗样本,扰乱检测机制。

AI 中文摘要

生成模型的快速发展引发了对评估深度伪造检测器最坏情况鲁棒性的迫切需求。本文揭示了当前取证范式中的一个基本盲点:现有检测器擅长捕捉数字合成伪像,但当人工智能生成的内容披上真实物理成像特征时,其有效性会大幅下降。我们提出真实照片具有硬件内在统计特征,而纯数据驱动的生成模型中不存在。基于此,我们提出ISPCloak,一种新颖的无优化对抗攻击框架,利用互联网服务提供商(ISP)管道误导深度伪造检测器的判断。该方法先将图像投影到RAW域,再通过注入噪声和进行前向ISP重建,将真实相机的统计先验印在人工智能生成的图像上,协同生成伪像抑制和自适应掩蔽,能超快速生成对抗样本。大量实验表明,嵌入真实物理扰动能从根本上扰乱多种当前检测机制,产生视觉上难以察觉改变的普遍逃避对抗样本。

英文摘要

The rapid advancement of generative models has spurred the critical need to evaluate the worst-case robustness of deepfake detectors. In this paper, we reveal a fundamental blind spot in current forensic paradigms: while existing detectors excel at capturing digital synthesis artifacts, their effectiveness drops drastically when AI-generated content is cloaked in authentic physical imaging characteristics. We posit that genuine photographs inherently possess hardware-intrinsic statistical signatures, which are imperceptible footprints imprinted by optical sensors and Image Signal Processing (ISP) pipelines, and are fundamentally absent in purely data-driven generative models. Driven by this insight, we propose ISPCloak, a novel optimization-free adversarial attack framework that explicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors. Rather than relying on computationally expensive gradient perturbations, our method first employs an Invertible ISP network to project images into the RAW domain. Then, we seamlessly imprint the complex statistical priors of real cameras onto AI-generated images by injecting realistic Poisson-Gaussian sensor noise and conducting forward ISP reconstruction. Synergized with generative artifact suppression and adaptive masking, this streamlined physical simulation enables ultra-fast generation of adversarial examples. Extensive experiments show that embedding authentic physical perturbations fundamentally disrupts a broad range of current detection mechanisms, yielding universally evasive adversarial examples with imperceptible visual alterations.

CommentsAccpted by ACM MM 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑