Investigate Evolutionary Strategies for Black-box Attacks to Deepfake Forensic Systems
Nguyen Thi My Binh, Dao Hoang Long, Nguyen Hong Ngoc, Huỳnh Thị Thanh Bình, Nguyen Khanh Phuong · 2022
Recently, the rising of deepfake generation techniques, cyber security against misinformation has become a popular topic among the research community. To improve the robustness of deepfake detection, attacks such as adversarial examples are studied with the aim to exploring weaknesses and security leaks. While most adversarial example generators are based on the assumption of white-box attack, in this paper, we focus on a more realistic black-box attack scenario using evolutionary approaches. A wide range of evolutionary strategies such as Genetic Algorithm, Particle Swarm Optimization, and Differential Evolution along with their quantum-inspired versions, are evaluated. The black-box attacks are shown to be highly effective against state-of-the-art forensics, exposing a vulnerability in current defense techniques. Analysis of the performance of different evolutionary strategies used for attacking also reveals insights on possible solutions to counter against the attacks.