Robust cross-image adversarial watermark with JPEG resistance for defending against Deepfake models.

Saved in:
Bibliographic Details
Title: Robust cross-image adversarial watermark with JPEG resistance for defending against Deepfake models.
Authors: Lin, Zhiyu1 (AUTHOR), Lin, Hanbin2 (AUTHOR), Lin, Liqiang1 (AUTHOR), Chen, Shuwu1 (AUTHOR), Liu, Xiaolong1,2,3 (AUTHOR) xlliu@fafu.edu.cn
Source: Computer Vision & Image Understanding. Oct2025, Vol. 260, pN.PAG-N.PAG. 1p.
Subjects: Deepfakes, Digital watermarking, Frequency-domain analysis, Image encryption, Computer security, Personal security
Abstract: The widespread convenience of generative models has exacerbated the misuse of attribute-editing-based Deepfake technologies, leading to the proliferation of illegally generated content that severely threatens personal privacy and security. Existing proactive defense strategies mitigate Deepfake attacks by embedding imperceptible adversarial watermarks into the spatial-domain of protected images. However, spatial-domain adversarial watermarks are inherently sensitive to lossy compression operations, which significantly degrades their defense efficacy. To address this limitation, we propose a frequency-domain cross-image adversarial watermark generation scheme to enhance robustness toward JPEG compression. In the proposed method, the adversarial watermark training process is migrated to the frequency domain using a differentiable JPEG module, which explicitly simulates the impact of quantization and compression on perturbation distributions. Furthermore, a fusion module is incorporated to coordinate watermark distributions across images, thereby enhancing the generalization of the defense. Experimental results demonstrate that the generated adversarial watermarks exhibit strong robustness against JPEG compression and effectively disrupt the outputs of Deepfake models. Moreover, the proposed scheme can be directly applied to diverse facial images without retraining, thereby providing reliable protection for real-world image application scenarios. • A JPEG-resistant adversarial watermarking method designed to defend against Deepfake models. • Differentiable JPEG module and cross-image fusion module are introduced to coordinate watermark distributions. • Ensures proactive protection for images while maintaining exceptional resistance to JPEG compression. • Outperforms baseline methods in defending against Deepfake models. [ABSTRACT FROM AUTHOR]
Copyright of Computer Vision & Image Understanding is the property of Academic Press Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 188089723
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Robust cross-image adversarial watermark with JPEG resistance for defending against Deepfake models.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Lin%2C+Zhiyu%22">Lin, Zhiyu</searchLink><relatesTo>1</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Lin%2C+Hanbin%22">Lin, Hanbin</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Lin%2C+Liqiang%22">Lin, Liqiang</searchLink><relatesTo>1</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Chen%2C+Shuwu%22">Chen, Shuwu</searchLink><relatesTo>1</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Liu%2C+Xiaolong%22">Liu, Xiaolong</searchLink><relatesTo>1,2,3</relatesTo> (AUTHOR)<i> xlliu@fafu.edu.cn</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Computer+Vision+%26+Image+Understanding%22">Computer Vision & Image Understanding</searchLink>. Oct2025, Vol. 260, pN.PAG-N.PAG. 1p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Deepfakes%22">Deepfakes</searchLink><br /><searchLink fieldCode="DE" term="%22Digital+watermarking%22">Digital watermarking</searchLink><br /><searchLink fieldCode="DE" term="%22Frequency-domain+analysis%22">Frequency-domain analysis</searchLink><br /><searchLink fieldCode="DE" term="%22Image+encryption%22">Image encryption</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22Personal+security%22">Personal security</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: The widespread convenience of generative models has exacerbated the misuse of attribute-editing-based Deepfake technologies, leading to the proliferation of illegally generated content that severely threatens personal privacy and security. Existing proactive defense strategies mitigate Deepfake attacks by embedding imperceptible adversarial watermarks into the spatial-domain of protected images. However, spatial-domain adversarial watermarks are inherently sensitive to lossy compression operations, which significantly degrades their defense efficacy. To address this limitation, we propose a frequency-domain cross-image adversarial watermark generation scheme to enhance robustness toward JPEG compression. In the proposed method, the adversarial watermark training process is migrated to the frequency domain using a differentiable JPEG module, which explicitly simulates the impact of quantization and compression on perturbation distributions. Furthermore, a fusion module is incorporated to coordinate watermark distributions across images, thereby enhancing the generalization of the defense. Experimental results demonstrate that the generated adversarial watermarks exhibit strong robustness against JPEG compression and effectively disrupt the outputs of Deepfake models. Moreover, the proposed scheme can be directly applied to diverse facial images without retraining, thereby providing reliable protection for real-world image application scenarios. • A JPEG-resistant adversarial watermarking method designed to defend against Deepfake models. • Differentiable JPEG module and cross-image fusion module are introduced to coordinate watermark distributions. • Ensures proactive protection for images while maintaining exceptional resistance to JPEG compression. • Outperforms baseline methods in defending against Deepfake models. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Computer Vision & Image Understanding is the property of Academic Press Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=188089723
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.cviu.2025.104459
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 1
        StartPage: N.PAG
    Subjects:
      – SubjectFull: Deepfakes
        Type: general
      – SubjectFull: Digital watermarking
        Type: general
      – SubjectFull: Frequency-domain analysis
        Type: general
      – SubjectFull: Image encryption
        Type: general
      – SubjectFull: Computer security
        Type: general
      – SubjectFull: Personal security
        Type: general
    Titles:
      – TitleFull: Robust cross-image adversarial watermark with JPEG resistance for defending against Deepfake models.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Lin, Zhiyu
      – PersonEntity:
          Name:
            NameFull: Lin, Hanbin
      – PersonEntity:
          Name:
            NameFull: Lin, Liqiang
      – PersonEntity:
          Name:
            NameFull: Chen, Shuwu
      – PersonEntity:
          Name:
            NameFull: Liu, Xiaolong
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 10
              Text: Oct2025
              Type: published
              Y: 2025
          Identifiers:
            – Type: issn-print
              Value: 10773142
          Numbering:
            – Type: volume
              Value: 260
          Titles:
            – TitleFull: Computer Vision & Image Understanding
              Type: main
ResultId 1