Exposing the Limits of Deepfake Detection using novel Facial mole attack: A Perceptual Black- Box Adversarial Attack Study

Qurat Ul Ain, Ali Javed, Khalid Mahmood Malik, Aun Irtaza · 2024

Recently, we have observed an exponential growth in highly realistic deepfake videos, which are often used to spread disinformation, defame individuals, and even influence political outcomes. To combat these manipulated videos, researchers have proposed various deepfake detection techniques. Recent research has revealed that these detection techniques are vulnerable to different adversarial attacks. This paper examines the vulnerability of deepfake detectors to adversarial black-box attacks in terms of performing penetration testing to expose the existing defense benchmarks of current deepfake detectors. We present a perceptual facial mole black-box adversarial attack on deepfake detectors, where the attacker has limited knowledge of the architecture and settings of the detector. The proposed attack is visually natural and transferable based on the attention distraction mechanism, which distracts the model-shared attention patterns from the region of interest to other regions. We illustrate the efficacy of our attack on multiple cutting-edge deepfake detectors. This attack demonstrates that small perceptible perturbations that are visually natural on the facial face can disrupt and reduce the accuracy of the detectors significantly, up to 40.3%, with the highest success rate of 48.7%. Our findings highlight the necessity for proposing effective deepfake detectors that are resistant to black-box attacks.

Read the paper · More papers on PaperTik