English

Feature Extraction Matters More: Universal Deepfake Disruption through Attacking Ensemble Feature Extractors

Computer Vision and Pattern Recognition 2023-03-02 v1 Artificial Intelligence

Abstract

Adversarial example is a rising way of protecting facial privacy security from deepfake modification. To prevent massive facial images from being illegally modified by various deepfake models, it is essential to design a universal deepfake disruptor. However, existing works treat deepfake disruption as an End-to-End process, ignoring the functional difference between feature extraction and image reconstruction, which makes it difficult to generate a cross-model universal disruptor. In this work, we propose a novel Feature-Output ensemble UNiversal Disruptor (FOUND) against deepfake networks, which explores a new opinion that considers attacking feature extractors as the more critical and general task in deepfake disruption. We conduct an effective two-stage disruption process. We first disrupt multi-model feature extractors through multi-feature aggregation and individual-feature maintenance, and then develop a gradient-ensemble algorithm to enhance the disruption effect by simplifying the complex optimization problem of disrupting multiple End-to-End models. Extensive experiments demonstrate that FOUND can significantly boost the disruption effect against ensemble deepfake benchmark models. Besides, our method can fast obtain a cross-attribute, cross-image, and cross-model universal deepfake disruptor with only a few training images, surpassing state-of-the-art universal disruptors in both success rate and efficiency.

Keywords

Cite

@article{arxiv.2303.00200,
  title  = {Feature Extraction Matters More: Universal Deepfake Disruption through Attacking Ensemble Feature Extractors},
  author = {Long Tang and Dengpan Ye and Zhenhao Lu and Yunming Zhang and Shengshan Hu and Yue Xu and Chuanxi Chen},
  journal= {arXiv preprint arXiv:2303.00200},
  year   = {2023}
}
R2 v1 2026-06-28T08:52:57.452Z