Adversarial Attacks on Deepfake Detectors: A GAN‐Based Approach for Generating Imperceptible Perturbations

Huanhuan Bao, Ning Zheng, Ming Xu, Ping Chen · IET Image Processing · 2026

ABSTRACT This paper presents an efficient GAN‐based adversarial attack method to spoof deepfake detectors. While such detectors, built on deep neural networks, show high accuracy in identifying forgeries, they are vulnerable to adversarial perturbations. Our proposed model employs a two‐branch architecture: one branch generates general, image‐independent perturbations, while the other enhances the adversarial efficacy of the reconstructed images. Through joint training, we generate visually realistic outputs that severely degrade detector performance. Experiments on FaceForensics++ demonstrate the effectiveness of the proposed method. It achieves competitive performance by reducing detection accuracy below 16% while maintaining high visual fidelity. The resulting highly imperceptible adversarial samples highlight a significant vulnerability in existing detectors.

Read the paper · More papers on PaperTik