Skip to main content
QUICK REVIEW

[論文レビュー] DeepTag: Robust Image Tagging for DeepFake Provenance

Run Wang, Felix Juefei-Xu|arXiv (Cornell University)|Sep 21, 2020
Digital Media Forensic Detection被引用数 12
ひとこと要約

DeepTagは、顔画像に追跡可能なメッセージを埋め込むことで、DeepFakeの出どころを特定するための堅牢なディープラーニングベースの画像タギング手法を提案する。シンプルだが効果的なエンコーダデコーダアーキテクチャを用い、GANベースの改ざんでさえも約90%のメッセージ回復精度を達成する。これにより、DeepFakeに対する予防的防御が可能となる。

ABSTRACT

In recent years, DeepFake is becoming a common threat to our society, due to the remarkable progress of generative adversarial networks (GAN) in image synthesis. Unfortunately, existing studies that propose various approaches, in fighting against DeepFake, to determine if the facial image is real or fake, is still at an early stage. Obviously, the current DeepFake detection method struggles to catchthe rapid progress of GANs, especially in the adversarial scenarios where attackers can evade the detection intentionally, such as adding perturbations to fool DNN-based detectors. While passive detection simply tells whether the image is fake or real, DeepFake provenance, on the other hand, provides clues for tracking the sources in DeepFake forensics. Thus, the tracked fake images could be blocked immediately by administrators and avoid further spread in social networks. In this paper, we investigated the potentials of image tagging in serving the DeepFake provenance. Specifically, we devise a deep learning-based approach, named DeepTag, with a simple yet effective encoder and decoder design to embed message to the facial image, which is to recover the embedded message after various drastic GAN-based DeepFake transformation with high confidence. The embedded message could be employed to represent the identity of facial images, which further contributed to DeepFake detection and provenance. Experimental results demonstrate that our proposed approach could recover the embedded message with an average accuracy of nearly 90%. Our research finding confirms effective privacy-preserving techniques for protecting personal photos from being DeepFaked. Thus, effective proactive defense mechanisms should be developed for fighting against DeepFakes, instead of simply devising DeepFake detection methods that can be mostly ineffective in practice.

研究の動機と目的

  • 受動的DeepFake検出の限界を克服し、偽造画像の出どころを事前に追跡可能にする。
  • 視覚的品質を損なわず、識別可能なメッセージを顔画像に埋め込むプライバシー保護型手法を開発する。
  • DeepFake生成に用いられる極端なGANベースの画像変換に対しても、メッセージの堅牢性を確保する。
  • ソーシャルネットワークにおける悪意ある生成偽造画像のフォレンジック追跡と迅速なブロッキングを支援する。

提案手法

  • 画像生成プロセス中にメッセージを顔画像に埋め込むディープラーニングベースのエンコーダデコーダフレームワークを設計する。
  • エンコーダーは顔画像の潜在表現にウォーターマークのようなメッセージを埋め込み、意味的整合性を保持する。
  • GANベースのDeepFake変換を経た後、デコーダーが画像から埋め込まれたメッセージを再構築する。
  • さまざまな悪意ある歪み下でのメッセージ回復精度を最大化するように、アーキテクチャをエンドツーエンドで訓練する。
  • 深層特徴の不変性を活用し、顕著な画像改ざんに対してもメッセージの正確性を維持する。
  • 最先端のGANによる画像変更に対しても、高い信頼性での回復が可能になるよう最適化されている。

実験結果

リサーチクエスチョン

  • RQ1攻撃的なGANベースの改ざんに対しても、ディープラーニングベースのタギングシステムが顔画像に信頼性高くメッセージを埋め込み、回復できるか?
  • RQ2悪意ある摂動および現実的なDeepFake生成パイプライン下でも、埋め込まれたメッセージの回復はどの程度堅牢か?
  • RQ3埋め込まれたメッセージは、ソーシャルネットワークにおける偽造画像の出どころを追跡する信頼できるプロヴァンスマークとして機能できるか?
  • RQ4このタギング機構は、画像品質とユーザーのプライバシーをどの程度保っているか?
  • RQ5このアプローチは、受動的検出に比べ、DeepFakeに対する予防的防御を可能にするか?

主な発見

  • 提案されたDeepTag手法は、さまざまなGANベースのDeepFake変換下で平均して90%近いメッセージ回復精度を達成する。
  • 極端な画像改ざんに対しても、埋め込まれたメッセージは回復可能であり、強い堅牢性を示している。
  • 埋め込まれたメッセージにより、偽造画像をその出どころと結びつける有効なプロヴァンス追跡が可能になる。
  • 管理者が広範な拡散の前に、既知の偽造画像をブロックできるよう、予防的防御を支援する。
  • 画像品質を保持するとともに、不正なDeepFakeの発生を防ぐプライバシー保護型ソリューションを提供する。
  • 結果から、実世界のDeepFake対策において、受動的検出よりも予防的ウォーターマーキングがより効果的であることが確認された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。