Robust Identity Perceptual Watermark Against Deepfake Face Swapping

Tianyi Wang,Mengxiao Huang,Harry Cheng,Bin Ma,Yinglong Wang
2024-03-15
Abstract:Notwithstanding offering convenience and entertainment to society, Deepfake face swapping has caused critical privacy issues with the rapid development of deep generative models. Due to imperceptible artifacts in high-quality synthetic images, passive detection models against face swapping in recent years usually suffer performance damping regarding the generalizability issue. Therefore, several studies have been attempted to proactively protect the original images against malicious manipulations by inserting invisible signals in advance. However, the existing proactive defense approaches demonstrate unsatisfactory results with respect to visual quality, detection accuracy, and source tracing ability. In this study, to fulfill the research gap, we propose the first robust identity perceptual watermarking framework that concurrently performs detection and source tracing against Deepfake face swapping proactively. We assign identity semantics regarding the image contents to the watermarks and devise an unpredictable and nonreversible chaotic encryption system to ensure watermark confidentiality. The watermarks are encoded and recovered by jointly training an encoder-decoder framework along with adversarial image manipulations. Falsification and source tracing are accomplished by justifying the consistency between the content-matched identity perceptual watermark and the recovered robust watermark from the image. Extensive experiments demonstrate state-of-the-art detection performance on Deepfake face swapping under both cross-dataset and cross-manipulation settings.
Computer Vision and Pattern Recognition
What problem does this paper attempt to address?
### Problems the Paper Attempts to Solve This paper aims to address the privacy issues brought about by Deepfake face-swapping technology. Specifically, Deepfake technology swaps the facial identity from a source image to a target image, which, while convenient for entertainment and film production, also raises serious privacy concerns. Existing passive detection methods (such as analyzing subtle traces in synthetic images) perform poorly when faced with high-quality synthetic images and lack generalization capability. Additionally, existing active defense methods (such as inserting invisible signals) perform poorly in terms of visual quality, detection accuracy, and source tracking capability. To fill these research gaps, the authors propose a new robust identity-aware watermarking framework that can actively defend against Deepfake face-swapping while achieving detection and source tracking. This framework embeds identity-aware watermarks related to the image content into the original image, ensuring that the watermark can still be recovered after the image is maliciously manipulated, thereby verifying the authenticity and source of the image.