被污染的像素能否揭露深度伪造视频?
Can Tainted Pixels Expose Deepfake Videos?
浏览论文内容
中文总结 AI 辅助
本文提出主动视频保护方法TaintedPixels,通过在人脸视频蓝色通道注入扰动,可抵御黑盒操纵工具,实验显示其能提升伪造识别率,验证了主动防御的有效性。
中文摘要 AI 辅助
公开可用的人脸操纵工具已让非专业用户也能创建深度伪造内容。针对这类工具,现有防御大多是事后防御,仅在伪造发生后进行检测,且仅对静态图像而非视频操作。目前研究存在两点不足:一是缺乏针对发布的人脸视频抵御黑盒操纵工具的主动保护;二是缺乏对其感知效果(对人类观察者)的理解。本文提出TaintedPixels,一种主动视频保护方法,基于非对称可见性权衡设计:嵌入的水印在发布视频中应保持不显眼,而一旦下游工具操纵该视频则会变得明显。TaintedPixels将结构化周期性扰动注入人脸区域的蓝色通道,并在条纹可见度、色偏和视频级LPIPS预算下进行优化,采用轻量运动自适应部署。我们认为TaintedPixels是首个专门针对黑盒操纵工具设计的主动防御,而非针对图像级流水线或特定代理生成器。在三种公开可用的现成视频操纵工具和两种现成检测器上,TaintedPixels实现了最高的伪造率,同时保持扰动极小(LPIPS=0.0042)。我们对300个涵盖不同光照条件、背景和肤色的多样视频刺激开展非专业人类研究,结果显示:受保护的源视频的怀疑率为3.26%,而来自受保护源的伪造品被识别为伪造的比例远高于来自未受保护源的伪造品(90.72% vs. 56.71%),这验证了TaintedPixels的有效性。
英文摘要
Publicly-acceesible face-manipulation tools have made deepfake creation accessible to non-expert users. Against these, existing defenses are mostly post-hoc, detecting only after forgery has occurred, and operating on still images rather than videos. Research is lacking in i) the proactive protection of published facial videos against black-box manipulation tools, and in (ii) understanding its perceptual effect on human viewers. We introduce TaintedPixels, a proactive video-protection method built around an asymmetric visibility trade-off: the embedded watermark should remain inconspicuous in the published video but become obvious once a downstream tool manipulates the video. TaintedPixels injects structured periodic perturbations into the blue channel of facial regions and refines them under stripe-visibility, color-cast, and video-level LPIPS budgets, with lightweight motion-adaptive deployment. We believe TaintedPixels is the first proactive defense designed specifically against black-box manipulation tools rather than image-level pipelines or specific surrogate generators. Across three publicly available off-the-shelf video manipulation tools and two off-the-shelf detectors, TaintedPixels attains the highest forgery fake rate while keeping perturbations small (LPIPS = 0.0042). Our non-expert human study, conducted on a diverse set of 300 video stimuli spanning different lighting conditions, backgrounds, and skin tones, shows that protected source videos draw a 3.26% suspicion rate, while forgeries from protected sources are identified as fake much more often than forgeries from unprotected sources (90.72% vs. 56.71%). This validates the effectiveness of TaintedPixels.