Bibliographic Details
| Title: |
Robust cross-image adversarial watermark with JPEG resistance for defending against Deepfake models. |
| Authors: |
Lin, Zhiyu1 (AUTHOR), Lin, Hanbin2 (AUTHOR), Lin, Liqiang1 (AUTHOR), Chen, Shuwu1 (AUTHOR), Liu, Xiaolong1,2,3 (AUTHOR) xlliu@fafu.edu.cn |
| Source: |
Computer Vision & Image Understanding. Oct2025, Vol. 260, pN.PAG-N.PAG. 1p. |
| Subjects: |
Deepfakes, Digital watermarking, Frequency-domain analysis, Image encryption, Computer security, Personal security |
| Abstract: |
The widespread convenience of generative models has exacerbated the misuse of attribute-editing-based Deepfake technologies, leading to the proliferation of illegally generated content that severely threatens personal privacy and security. Existing proactive defense strategies mitigate Deepfake attacks by embedding imperceptible adversarial watermarks into the spatial-domain of protected images. However, spatial-domain adversarial watermarks are inherently sensitive to lossy compression operations, which significantly degrades their defense efficacy. To address this limitation, we propose a frequency-domain cross-image adversarial watermark generation scheme to enhance robustness toward JPEG compression. In the proposed method, the adversarial watermark training process is migrated to the frequency domain using a differentiable JPEG module, which explicitly simulates the impact of quantization and compression on perturbation distributions. Furthermore, a fusion module is incorporated to coordinate watermark distributions across images, thereby enhancing the generalization of the defense. Experimental results demonstrate that the generated adversarial watermarks exhibit strong robustness against JPEG compression and effectively disrupt the outputs of Deepfake models. Moreover, the proposed scheme can be directly applied to diverse facial images without retraining, thereby providing reliable protection for real-world image application scenarios. • A JPEG-resistant adversarial watermarking method designed to defend against Deepfake models. • Differentiable JPEG module and cross-image fusion module are introduced to coordinate watermark distributions. • Ensures proactive protection for images while maintaining exceptional resistance to JPEG compression. • Outperforms baseline methods in defending against Deepfake models. [ABSTRACT FROM AUTHOR] |
|
Copyright of Computer Vision & Image Understanding is the property of Academic Press Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) |
| Database: |
Engineering Source |