Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery Detection

Jiawei Liang,Siyuan Liang,Aishan Liu,Xiaojun Jia,Junhao Kuang,Xiaochun Cao
2024-02-18
Abstract:The proliferation of face forgery techniques has raised significant concerns within society, thereby motivating the development of face forgery detection methods. These methods aim to distinguish forged faces from genuine ones and have proven effective in practical applications. However, this paper introduces a novel and previously unrecognized threat in face forgery detection scenarios caused by backdoor attack. By embedding backdoors into models and incorporating specific trigger patterns into the input, attackers can deceive detectors into producing erroneous predictions for forged faces. To achieve this goal, this paper proposes \emph{Poisoned Forgery Face} framework, which enables clean-label backdoor attacks on face forgery detectors. Our approach involves constructing a scalable trigger generator and utilizing a novel convolving process to generate translation-sensitive trigger patterns. Moreover, we employ a relative embedding method based on landmark-based regions to enhance the stealthiness of the poisoned samples. Consequently, detectors trained on our poisoned samples are embedded with backdoors. Notably, our approach surpasses SoTA backdoor baselines with a significant improvement in attack success rate (+16.39\% BD-AUC) and reduction in visibility (-12.65\% $L_\infty$). Furthermore, our attack exhibits promising performance against backdoor defenses. We anticipate that this paper will draw greater attention to the potential threats posed by backdoor attacks in face forgery detection scenarios. Our codes will be made available at \url{
Computer Vision and Pattern Recognition
What problem does this paper attempt to address?
### What problem does this paper attempt to solve? This paper primarily explores the new threats posed by backdoor attacks in facial forgery detection and proposes a method called "Poisoned Forgery Face" (PFF) to achieve clean-label backdoor attacks. #### Main Issues: 1. **Security of Facial Forgery Detection**: With the development of facial forgery technology, although various detection methods can distinguish between real and fake faces, these methods are susceptible to adversarial examples. This paper focuses on the possibility of embedding backdoor attacks during the training phase, causing the model to make incorrect predictions on forged faces under specific trigger patterns. 2. **Challenges of Backdoor Attacks**: Existing backdoor attack methods face two main challenges in the context of facial forgery detection: - **Label Conflict**: Current detection methods generate forged faces through image transformation during training. When a backdoor trigger is embedded in a real face, the transformed forged face will also carry a similar trigger pattern, leading to label conflict. - **Concealment of Trigger Patterns**: In facial forgery detection, the trigger pattern must be sufficiently concealed to avoid being noticed by users. Existing backdoor attack methods are inadequate in this regard. #### Solutions: 1. **Proposing the PFF Framework**: This framework addresses the above challenges by designing an extensible trigger generator and a relative embedding method, achieving effective backdoor attacks on existing facial forgery detection methods. 2. **Experimental Validation**: Extensive experiments validate the effectiveness of the PFF method, particularly its superior performance in cross-dataset evaluations compared to existing methods. This paper aims to reveal potential security risks in facial forgery detection and provide an effective backdoor attack solution.