A Residual Fingerprint-Based Defense Against Adversarial Deepfakes
Jianguo Jiang, Boquan Li, Shuai Yu, Chao Liu, Shaohua An, Mingqi Liu, Min Yu · 2021
The authenticity and integrity of digital visual media have always been a crucial branch in the domain of multimedia forensics and information security. Currently, the emerging Deepfakes destroy the authenticity and integrity as well as trump up a person's behaviors that do not exist in reality, which pose potential threats to individual, social and even national security. Although multiple well-designed deep neural networks have achieved satisfactory performance on Deepfake detection, by adding imperceptible but purposeful adversarial perturbations to fake images or videos, the crafted adversarial Deepfakes are demonstrated to cause the malfunction of detectors. In response to such threats, little recent research attempts to take defensive measures but shows scarce applicability, and the effective conventional defenses are insufficient to protect the particular Deepfake detectors. Therefore, to defend against adversarial Deepfakes, we propose a residual fingerprint-based defense customized for Deepfake detectors. By analyzing the impacts of adversarial perturbations on detectors, we construct a reconstruction network, and propose novel strategies to degrade the adversarial efficacy as well as extract discriminative residual fingerprints. Ultimately, we transform the extracted residual fingerprints for Deepfake detection. The evaluation results indicate the performance of compromised detectors is regained by our proposed defense, which is qualified for enhancing the security and reliability of multiple Deepfake detectors.