<p>The rapid development of generative AI and deepfakes has raised concerns about the authenticity of image content, making the study of deepfake detection increasingly crucial. However, current deepfake detectors are highly susceptible to adversarial attacks, and research on these attacks will directly drive improvements in detection security. Although current adversarial attack techniques have made progress in success rate and cross-model transferability, the generated adversarial samples often contain artifacts discernible to the human eye, resulting in insufficient stealth. We believe that an ideal adversarial attack should balance both high attack efficacy and visual stealth. To this end, we propose a novel adversarial attack framework based on a latent diffusion model, which can produce perturbations that combine high efficacy with stealth. It is worth emphasizing that our work does not present a specific attack method, but rather a general framework compatible with multiple mainstream adversarial attack algorithms. Unlike traditional methods that add perturbations in the pixel space, this framework operates in the latent space of diffusion models and innovatively integrates a spatial attention module to dynamically guide the generation and fusion of perturbations. Experiments show that the adversarial attack methods optimized through this framework significantly outperform baseline methods in terms of stealth and transferability. To comprehensively validate performance, we selected deepfake detectors with different architectures such as ResNet-50 and EfficientNet, as well as diverse forgery datasets generated by Generative Adversarial Networks for testing. Overall experimental results demonstrate that, compared with mainstream adversarial attack methods, our framework achieves a high attack success rate while significantly improving both the imperceptibility and cross-model transferability of adversarial samples.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A universal framework for enhancing imperceptibility in latent diffusion-based adversarial attacks

  • Yu Zhang,
  • Daoqi Huang,
  • Huajun Zhang

摘要

The rapid development of generative AI and deepfakes has raised concerns about the authenticity of image content, making the study of deepfake detection increasingly crucial. However, current deepfake detectors are highly susceptible to adversarial attacks, and research on these attacks will directly drive improvements in detection security. Although current adversarial attack techniques have made progress in success rate and cross-model transferability, the generated adversarial samples often contain artifacts discernible to the human eye, resulting in insufficient stealth. We believe that an ideal adversarial attack should balance both high attack efficacy and visual stealth. To this end, we propose a novel adversarial attack framework based on a latent diffusion model, which can produce perturbations that combine high efficacy with stealth. It is worth emphasizing that our work does not present a specific attack method, but rather a general framework compatible with multiple mainstream adversarial attack algorithms. Unlike traditional methods that add perturbations in the pixel space, this framework operates in the latent space of diffusion models and innovatively integrates a spatial attention module to dynamically guide the generation and fusion of perturbations. Experiments show that the adversarial attack methods optimized through this framework significantly outperform baseline methods in terms of stealth and transferability. To comprehensively validate performance, we selected deepfake detectors with different architectures such as ResNet-50 and EfficientNet, as well as diverse forgery datasets generated by Generative Adversarial Networks for testing. Overall experimental results demonstrate that, compared with mainstream adversarial attack methods, our framework achieves a high attack success rate while significantly improving both the imperceptibility and cross-model transferability of adversarial samples.