发表机构
Shanghai Jiao Tong University(上海交通大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对运动感知深度伪造(MAD)这一新型深度伪造威胁,构建首个专用基准,提出MoDA防御框架,实现高检测与归因准确率,且具备良好的零样本迁移及抗攻击性能。
AI 中文摘要
基于姿态引导的扩散模型如今可合成完整的运动人体,催生了一类新型深度伪造:运动感知深度伪造(Motion Aware Deepfake, MAD),其受众已达数亿。为更好理解这一新兴威胁,我们构建了首个MAD专用基准与测量框架,包含超150万帧,混合了来自6个可控生成器的1363个真实视频与30122个合成视频,具备逼真扰动与开放世界评估划分。随后我们剖析MAD,发现尽管这些视频具备全局一致性,却存在微弱但可靠的线索:由于模型依赖有限输入帧进行运动合成,必须预测并模拟运动边界处的连贯运动,从而产生高频伪影及模型特有的频谱指纹。基于对数据集的分析结果,我们提出MoDA,首个专为检测与归因MAD视频设计的防御框架。MoDA通过跨域对齐与多尺度聚合将空间语义与含隐写分析信息的频率特征相结合,在分布内检测准确率达94.8%,跨数据集检测准确率达89.1%,较现有工作提升10%至25%;模型归因准确率达91.5%。MoDA在两个未见过的商业MAD平台生成的200个片段上准确率达81.94%,展现出良好的零样本迁移能力;在从开放互联网收集的1200个未见过的MAD视频片段(共5.5万帧)上检测准确率达78.13%。在白盒、灰盒与黑盒自适应攻击下,MoDA维持相对稳定的检测与归因性能,而基线模型的准确率则迅速下降。
英文摘要
Pose-guided diffusion models can now synthesize entire human figures in motion, spawning a new class of deepfakes: Motion Aware Deepfake (MAD) that have already reached hundreds of millions of viewers. To better understand this emerging threat, we construct the first MAD-specific benchmark and measurement framework, containing over 1.5 million frames that mix 1,363 real and 30,122 synthetic videos from six controllable generators, with realistic perturbations and open-world evaluation splits. Then, we dissect MAD and discover that, despite their global coherence, these videos betray faint yet reliable cues: because the model relies on limited input frames for motion synthesis, it must predict and simulate coherent movement at motion boundaries, thereby producing high-frequency artifacts along with model-specific spectral fingerprints. Based on the observations obtained from analysis on dataset, we propose MoDA, the first defense framework tailored to detect and attribute MAD videos. MoDA couples spatial semantics with steganalysis-rich frequency features via cross-domain alignment and multi-scale aggregation, achieving 94.8% in-distribution and 89.1% cross-dataset detection accuracy gains of 10% to 25% over prior work and 91.5% model attribution accuracy. MoDA achieves 81.94% accuracy on 200 clips produced by two unseen commercial MAD platforms, indicating promising zero-shot transfer, and 78.13% detection accuracy on 1,200 unseen MAD video clips (55k frames in total) collected from the open Internet. Under white-box, gray-box, and black-box adaptive attacks, MoDA maintains relatively stable detection and attribution performance while the accuracies of the baselines drop rapidly.