Inspector for Face Forgery Detection: Defending Against Adversarial Attacks From Coarse to Fine

被引:0
|
作者
Xia, Ruiyang [1 ]
Zhou, Dawei [2 ]
Liu, Decheng [3 ]
Li, Jie [1 ]
Yuan, Lin [4 ]
Wang, Nannan [2 ]
Gao, Xinbo [4 ,5 ]
机构
[1] Xidian Univ, Sch Elect Engn, State Key Lab Integrated Serv Networks, Xian 710071, Shaanxi, Peoples R China
[2] Xidian Univ, Sch Telecommun Engn, State Key Lab Integrated Serv Networks, Xian 710071, Shaanxi, Peoples R China
[3] Xidian Univ, Sch Cyber Engn, State Key Lab Integrated Serv Networks, Xian 710071, Peoples R China
[4] Chongqing Univ Posts & Telecommun, Chongqing Key Lab Image Cognit, Chongqing 400065, Peoples R China
[5] Xidian Univ, Sch Elect Engn, Shaanxi 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
Forgery; Detectors; Perturbation methods; Faces; Accuracy; Training; Iterative methods; Face forgery; adversarial defense; forgery detection;
D O I
10.1109/TIP.2024.3434388
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The emergence of face forgery has raised global concerns on social security, thereby facilitating the research on automatic forgery detection. Although current forgery detectors have demonstrated promising performance in determining authenticity, their susceptibility to adversarial perturbations remains insufficiently addressed. Given the nuanced discrepancies between real and fake instances are essential in forgery detection, previous defensive paradigms based on input processing and adversarial training tend to disrupt these discrepancies. For the detectors, the learning difficulty is thus increased, and the natural accuracy is dramatically decreased. To achieve adversarial defense without changing the instances as well as the detectors, a novel defensive paradigm called Inspector is designed specifically for face forgery detectors. Specifically, Inspector defends against adversarial attacks in a coarse-to-fine manner. In the coarse defense stage, adversarial instances with evident perturbations are directly identified and filtered out. Subsequently, in the fine defense stage, the threats from adversarial instances with imperceptible perturbations are further detected and eliminated. Experimental results across different types of face forgery datasets and detectors demonstrate that our method achieves state-of-the-art performances against various types of adversarial perturbations while better preserving natural accuracy. Code is available on https://github.com/xarryon/Inspector.
引用
收藏
页码:4432 / 4443
页数:12
相关论文
共 50 条
  • [21] DiffDefense: Defending Against Adversarial Attacks via Diffusion Models
    Silva, Hondamunige Prasanna
    Seidenari, Lorenzo
    Del Bimbo, Alberto
    IMAGE ANALYSIS AND PROCESSING, ICIAP 2023, PT II, 2023, 14234 : 430 - 442
  • [22] Defending Against Adversarial Attacks via Neural Dynamic System
    Li, Xiyuan
    Zou, Xin
    Liu, Weiwei
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35, NEURIPS 2022, 2022,
  • [23] Defending non-Bayesian learning against adversarial attacks
    Lili Su
    Nitin H. Vaidya
    Distributed Computing, 2019, 32 : 277 - 289
  • [24] Defending Wireless Receivers Against Adversarial Attacks on Modulation Classifiers
    de Araujo-Filho, Paulo Freitas
    Kaddoum, Georges
    Chiheb Ben Nasr, Mohamed
    Arcoverde, Henrique F.
    Campelo, Divanilson R.
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (21) : 19153 - 19162
  • [25] GNNGUARD: Defending Graph Neural Networks against Adversarial Attacks
    Zhang, Xiang
    Zitnik, Marinka
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [26] Defending against Whitebox Adversarial Attacks via Randomized Discretization
    Zhang, Yuchen
    Liang, Percy
    22ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 89, 2019, 89 : 684 - 693
  • [27] Defending non-Bayesian learning against adversarial attacks
    Su, Lili
    Vaidya, Nitin H.
    DISTRIBUTED COMPUTING, 2019, 32 (04) : 277 - 289
  • [28] Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection
    Liu, Jiang
    Levine, Alexander
    Lau, Chun Pong
    Chellappa, Rama
    Feizi, Soheil
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 14953 - 14962
  • [29] Coarse-to-Fine Face Detection
    Francois Fleuret
    Donald Geman
    International Journal of Computer Vision, 2001, 41 : 85 - 107
  • [30] Coarse-to-fine face detection
    Fleuret, F
    Geman, D
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2001, 41 (1-2) : 85 - 107