FakeTracer: Catching Face-swap DeepFakes via Implanting Traces in Training
- URL: http://arxiv.org/abs/2307.14593v2
- Date: Sun, 21 Apr 2024 09:02:36 GMT
- Title: FakeTracer: Catching Face-swap DeepFakes via Implanting Traces in Training
- Authors: Pu Sun, Honggang Qi, Yuezun Li, Siwei Lyu,
- Abstract summary: Face-swap DeepFake is an emerging AI-based face forgery technique.
Due to the high privacy of faces, the misuse of this technique can raise severe social concerns.
We describe a new proactive defense method called FakeTracer to expose face-swap DeepFakes via implanting traces in training.
- Score: 36.158715089667034
- License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
- Abstract: Face-swap DeepFake is an emerging AI-based face forgery technique that can replace the original face in a video with a generated face of the target identity while retaining consistent facial attributes such as expression and orientation. Due to the high privacy of faces, the misuse of this technique can raise severe social concerns, drawing tremendous attention to defend against DeepFakes recently. In this paper, we describe a new proactive defense method called FakeTracer to expose face-swap DeepFakes via implanting traces in training. Compared to general face-synthesis DeepFake, the face-swap DeepFake is more complex as it involves identity change, is subjected to the encoding-decoding process, and is trained unsupervised, increasing the difficulty of implanting traces into the training phase. To effectively defend against face-swap DeepFake, we design two types of traces, sustainable trace (STrace) and erasable trace (ETrace), to be added to training faces. During the training, these manipulated faces affect the learning of the face-swap DeepFake model, enabling it to generate faces that only contain sustainable traces. In light of these two traces, our method can effectively expose DeepFakes by identifying them. Extensive experiments corroborate the efficacy of our method on defending against face-swap DeepFake.
Related papers
- FaceTracer: Unveiling Source Identities from Swapped Face Images and Videos for Fraud Prevention [68.07489215110894]
FaceTracer is a framework specifically designed to trace the identity of the source person from swapped face images or videos.
In experiments, FaceTracer successfully identified the source person in swapped content and enabling the tracing of malicious actors involved in fraudulent activities.
arXiv Detail & Related papers (2024-12-11T04:00:17Z) - Hiding Faces in Plain Sight: Defending DeepFakes by Disrupting Face Detection [56.289631511616975]
This paper investigates the feasibility of a proactive DeepFake defense framework, em FacePosion, to prevent individuals from becoming victims of DeepFake videos.
Based on FacePoison, we introduce em VideoFacePoison, a strategy that propagates FacePoison across video frames rather than applying them individually to each frame.
Our method is validated on five face detectors, and extensive experiments against eleven different DeepFake models demonstrate the effectiveness of disrupting face detectors to hinder DeepFake generation.
arXiv Detail & Related papers (2024-12-02T04:17:48Z) - Deepfake detection in videos with multiple faces using geometric-fakeness features [79.16635054977068]
Deepfakes of victims or public figures can be used by fraudsters for blackmailing, extorsion and financial fraud.
In our research we propose to use geometric-fakeness features (GFF) that characterize a dynamic degree of a face presence in a video.
We employ our approach to analyze videos with multiple faces that are simultaneously present in a video.
arXiv Detail & Related papers (2024-10-10T13:10:34Z) - Deepfake Face Traceability with Disentangling Reversing Network [40.579533545888516]
Deepfake face not only violates the privacy of personal identity, but also confuses the public and causes huge social harm.
Current deepfake detection only stays at the level of distinguishing true and false, and cannot trace the original genuine face corresponding to the fake face.
This paper pioneers an interesting question about face deepfake, active forensics that "know it and how it happened"
arXiv Detail & Related papers (2022-07-08T03:05:28Z) - Restricted Black-box Adversarial Attack Against DeepFake Face Swapping [70.82017781235535]
We introduce a practical adversarial attack that does not require any queries to the facial image forgery model.
Our method is built on a substitute model persuing for face reconstruction and then transfers adversarial examples from the substitute model directly to inaccessible black-box DeepFake models.
arXiv Detail & Related papers (2022-04-26T14:36:06Z) - One Shot Face Swapping on Megapixels [65.47443090320955]
This paper proposes the first Megapixel level method for one shot Face Swapping (or MegaFS for short)
Complete face representation, stable training, and limited memory usage are the three novel contributions to the success of our method.
arXiv Detail & Related papers (2021-05-11T10:41:47Z) - Landmark Breaker: Obstructing DeepFake By Disturbing Landmark Extraction [40.71503677067645]
We describe Landmark Breaker, the first dedicated method to disrupt facial landmark extraction.
Our motivation is that disrupting the facial landmark extraction can affect the alignment of input face so as to degrade the DeepFake quality.
Compared to the detection methods that only work after DeepFake generation, Landmark Breaker goes one step ahead to prevent DeepFake generation.
arXiv Detail & Related papers (2021-02-01T12:27:08Z)
This list is automatically generated from the titles and abstracts of the papers in this site.
This site does not guarantee the quality of this site (including all information) and is not responsible for any consequences.