错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Generative Universal Nullifying Perturbation for Countering Deepfakes Through Combined Unsupervised Feature Aggregation

  • Yuchen Guo,
  • Xi Wang,
  • Xiaomeng Fu,
  • Jin Liu,
  • Zhaoxing Li,
  • Jizhong Han

摘要

Incorporating adversarial perturbations into images to fool Deepfake models is a pivotal strategy in defending against manipulated content. However, most existing methods are image-specific, necessitating iterative optimization of perturbation for each image, which is time-consuming when applied to large-scale images and fails to achieve real-time inference. Meanwhile, even though the Deepfake models may be disrupt, the content of the original images is alerted, impeding the further delivery of information. To address these challenges, we proposed a method for universal nullifying perturbation generation. Our method integrates both pixel-wise and feature-wise information to generate the perturbation that influence the outputs of the Deepfake model, with the goal of preserving the holistic content of the image as much as possible. We present an unsupervised aggregation method to enhance the effectiveness of perturbation generation in leveraging feature information. Additionally, we advocate the use of neural networks for generating universal perturbations, particularly effective in addressing challenging tasks. Experimental results demonstrate that our proposed method achieves state-of-the-art performance, with our universal nullifying perturbation effectively maintaining the visual quality of original images. Moreover, cross-data experiments confirm that our perturbation remains efficient in protecting face images from forgery even in the presence of unknown data. Consequently, our proposed approach offers a robust and efficient solution to combat Deepfake, contributing to the safeguarding of personal privacy and prevention of reputational damage.