Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
The current detectors are not robust enough to adversarial attacks. In this paper, we introduce a robust and universal adversarial attack scheme based on portrait relighting, by estimating and separating the original light distribution, and re-rendering the image with an elaborately-designed one, which can evade spatial-based, frequency-based and biological signal-based DeepFake detectors. We conduct our experiments to evaluate the efficiency, universality and robustness, and the results show that the attack success rate reaches 99.6% in the case of white box, and the optimal attack rate is 69.8% in the case of black box. Besides, the adversarial examples can resist against common image transformations, which shows great robustness and can be deployed in real-world environment.
WESTERLUNDM. The emergence of deepfake technology: A review[J]. Technology Innovation Management Review, 2019, 9(11): 39-52. DOI: 10.22215/timreview/1282 .
[2]
NEEKHARAP, DOLHANSKYB, BITTONJ, et al. Adversarial threats to DeepFake detection: A practical perspective[C]//2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). New York: IEEE Press, 2021: 923-932. DOI: 10.1109/CVPRW53098.2021.00103 .
[3]
MASOODM, NAWAZM, MALIKK M, et al. Deepfakes generation and detection: State-of-the-art, open challenges, countermeasures, and way forward[J]. Applied Intelligence, 2023, 53(4): 3974-4026. DOI: 10.1007/s10489-022-03766-z .
[4]
LEIBOWICZC R, MCGREGORS, OVADYAA. The deepfake detection dilemma: A multistakeholder exploration of adversarial dynamics in synthetic media[C]//Proceedings of the 2021 AAAI/ACM Conference on AI, Ethics, and Society. New York: ACM, 2021: 736-744. DOI: 10.1145/3461702.3462584 .
[5]
HOUA, SARKISM, BIN, et al. Face relighting with geometrically consistent shadows[C]//2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2022: 4207-4216. DOI: 10.1109/CVPR52688.2022.00418 .
[6]
RÖSSLERA, COZZOLINOD, VERDOLIVAL, et al. FaceForensics: Learning to detect manipulated facial images[C]//2019 IEEE/CVF International Conference on Computer Vision (ICCV). New York: IEEE Press, 2020: 1-11. DOI: 10.1109/ICCV.2019.00009 .
[7]
YANGJ C, LIA Y, XIAOS, et al. MTD-net: Learning to detect deepfakes images by multi-scale texture difference[J]. IEEE Transactions on Information Forensics and Security, 2021, 16: 4234-4245. DOI: 10.1109/TIFS.2021.3102487 .
[8]
QIANY Y, YING J, SHENGL, et al. Thinking in frequency: Face forgery detection by mining frequency-aware clues[C]//Computer Vision — ECCV 2020. Cham: Springer International Publishing, 2020: 86-103. DOI: 10.1007/978-3-030-58610-2_6 .
[9]
CIFTCIU A, DEMIRİ, YINL J. How do the hearts of deep fakes beat? Deep fake source detection via interpreting residuals with biological signals[C]//2020 IEEE International Joint Conference on Biometrics (IJCB). New York: ACM, 2020: 1-10. DOI: 10.1109/IJCB48548.2020.9304909 .
[10]
GANDHIA, JAINS. Adversarial perturbations fool deepfake detectors[C]//2020 International Joint Conference on Neural Networks (IJCNN). New York: IEEE Press, 2020: 1-8. DOI: 10.1109/IJCNN48605.2020.9207034 .
[11]
HUANGY H, JUEFEI-XUF, WANGR, et al. FakePolisher: Making DeepFakes more detection-evasive by shallow reconstruction[C]//Proceedings of the 28th ACM International Conference on Multimedia. New York: ACM, 2020: 1217-1226. DOI: 10.1145/3394171.3413732 .
[12]
XIEH, NIJ Q, ZHANGJ, et al. Evading generated-image detectors: A deep dithering approach[J]. Signal Processing, 2022, 197: 108558. DOI: 10.1016/j.sigpro.2022.108558 .
[13]
BASRIR, JACOBSD W. Lambertian reflectance and linear subspaces[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2003, 25(2): 218-233. DOI: 10.1109/TPAMI.2003.1177153 .
[14]
AFCHARD, NOZICKV, YAMAGISHIJ, et al. MesoNet: A compact facial video forgery detection network[C]//2018 IEEE International Workshop on Information Forensics and Security (WIFS). New York: IEEE Press, 2019: 1-7. DOI: 10.1109/WIFS.2018.8630761 .
[15]
WOLTERM, BLANKEF, HEESER, et al. Wavelet-packets for deepfake image analysis and detection[EB/OL]. 2021: arXiv: 2106.09369. DOI: 10.1007/s10994-022-06225-5 .
[16]
HERNANDEZ-ORTEGAJ, TOLOSANAR, FIERREZJ, et al. DeepFakesON-Phys: DeepFakes detection based on heart rate estimation[EB/OL]. 2020: arXiv: 2010.00400. DOI: 10.1109/compsac48688.2020.00031 .
[17]
CARLININ, WAGNERD. Towards evaluating the robustness of neural networks[C]//2017 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2017: 39-57. DOI: 10.1109/SP.2017.49 .
[18]
ZHAOZ, LIUZ, LARSONM. Adversarial color enhancement: Generating unrestricted adversarial images by optimizing a color filter[EB/OL]. 2020: arXiv: 2002.01008. DOI: 10.1109/cvpr42600.2020.00112 .
[19]
HEK M, ZHANGX Y, RENS Q, et al. Deep residual learning for image recognition[C]//2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2016: 770-778. DOI: 10.1109/CVPR.2016.90 .
[20]
CHOLLETF. Xception: deep learning with depthwise separable convolutions[C]//2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2017: 1800-1807. DOI: 10.1109/CVPR.2017.195 .
[21]
SAYEDM, BROSTOWG. Improved handling of motion blur in online object detection[C]//2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2021: 1706-1716. DOI: 10.1109/CVPR46437.2021.00175 .