Adversarial Robustness in DeepFake Detection: Enhancing Model Resilience with Defensive Strategies

N Pallavi, T. P. Pallavi, Sushma Bylaiah, Rahul Goutam · 2024

Detection of DeepFakes presents formidable challenges primarily due to adversarial attacks that can dramatically reduce model accuracy. Current detection models are reasonably effective in real scenarios; however, these detectors are vulnerable to adversarial attacks, resulting in misclassifications. The current study examines defensive approaches to strengthen the robustness of DeepFake detection approaches when facing adversarial attacks. Explored several alternatives, including adversarial training, input preprocessing, and model ensembles against a manipulated media dataset. The results demonstrate that the model has predicted image appropriately at average of 86.34% but after the adversarial attacks the prediction of the image was 99.8% inappropriate. although adversarial attacks greatly lower the effectiveness of a model, it is possible to improve the robustness of a model through defense methods, particularly adversarial training in combination with an ensemble method which predicted the image appropriately at an average of 52.06%. However, despite the improvement, the defense methods still fail to protect all adversarial examples. The results illustrate the importance of developing new methods of defense against DeepFake detection in light of future adjustments and variants of an attack.

Read the paper · More papers on PaperTik