发表机构
Yozgat Bozok University; Texas A&M University(约加特博佐克大学; 德克萨斯农工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对深度伪造难以被人类识破的问题,提出DECEIVE框架,通过EEG和眼动实验发现神经生理层面无显著差异,但行为上26.68%的伪造被接受,为防御评估提供基准。
AI 中文摘要
深度伪造已迅速成为对信息完整性和安全性的紧迫威胁,因为它们利用了人类对视觉和听觉感知的信任。然而,关于人类及其潜在的(亚)意识神经生理过程能否可靠地区分深度伪造视频和真实视频,目前知之甚少。我们提出了DECEIVE(深度伪造对认知参与和隐式视觉评估的利用)框架,该框架通过行为学和神经生理学筛查观众,建模深度伪造视频如何被验证为对抗性载荷,以及如何通过选择能逃避检测的载荷来优化攻击。该框架与数据集无关,适用于合成或真实媒体。它本质上具有双重用途:拥有同等测量能力的对手可以迭代候选操作,并保留那些能逃避人类检测的操作。这促使进行开放的、防御性的评估。测量哪些深度伪造能击败人类感知,为攻击者能力设定了一个现实界限,可据此评估检测工具、溯源和水印机制以及面向用户的防护措施。作为实例化,我们进行了一项EEG和眼动追踪研究,参与者观看来自Celeb-DF和精选名人集的真实、深度伪造和相似外貌视频,同时记录行为判断和隐式反应。与先前关于绘画和钓鱼网站研究所暗示的潜意识差异化预期相反,真实视频和深度伪造视频之间未出现统计上显著的神经生理学差异,尽管对相似外貌视频观察到了明显区别。在行为上,参与者接受了26.68%的被操纵片段为真实,对于熟悉身份则上升至31.94%,证实了所研究的深度伪造在DECEIVE框架内是有效的对抗性载荷。
英文摘要
Deepfakes have rapidly emerged as a pressing threat to information integrity and security because they exploit human trust in visual and auditory perception. Yet, little is known about whether humans and their underlying (sub)conscious neuro-physiological processes can reliably distinguish deepfake from real videos. We introduce DECEIVE (Deepfake Exploitation of Cognitive Engagement and Implicit Visual Evaluation), a framework that models how deepfake videos are validated as adversarial payloads through behavioral and neuro-physiological screening of viewers, and how attacks can be refined by selecting payloads that evade detection. The framework is dataset agnostic and applies to synthetic or real media. It is inherently dual-use: an adversary with equivalent measurements could iterate on candidate manipulations and retain those that evade human detection. This motivates open, defensive evaluation. Measuring which deepfakes defeat human perception establishes a realistic bound on attacker capability against which detection tooling, provenance and watermarking mechanisms, and user-facing protections can be assessed. As an instantiation, we conducted an EEG and eye-tracking study in which participants viewed real, deepfake, and look-alike videos drawn from Celeb-DF and a curated celebrity set, while behavioral judgments and implicit responses were recorded. Contrary to expectations of subconscious differentiation suggested by prior work on paintings and phishing websites, no statistically significant neuro-physiological differences emerged between real and deepfake videos, although clear distinctions were observed for look-alike videos. Behaviorally, participants accepted 26.68% of manipulated clips as authentic, rising to 31.94% for familiar identities, confirming the studied deepfakes as effective adversarial payloads within DECEIVE.
CommentsAccepted at the 29th Information Security Conference (ISC 2026)