Skip to main navigation Skip to search Skip to main content

IMPERCEPTIBLE ADVERSARIAL EXAMPLES FOR FAKE IMAGE DETECTION

  • Quanyu Liao
  • , Yuezun Li
  • , Xin Wang
  • , Bin Kong
  • , Bin Zhu
  • , Siwei Lyu
  • , Youbing Yin
  • , Qi Song
  • , Xi Wu
  • Chengdu University of Information Technology
  • SUNY Buffalo
  • Keya Medical
  • Microsoft USA

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

13 Scopus citations

Abstract

Fooling people with highly realistic fake images generated with Deepfake or GANs brings a great social disturbance to our society. Many methods have been proposed to detect fake images, but they are vulnerable to adversarial perturbations – intentionally designed noises that can lead to the wrong prediction. Existing methods of attacking fake image detectors usually generate adversarial perturbations to perturb almost the entire image. This is redundant and increases the perceptibility of perturbations. In this paper, we propose a novel method to disrupt the fake image detection by determining key pixels to a fake image detector and attacking only the key pixels, which results in the L0 and the L2 norms of adversarial perturbations much less than those of existing works. Experiments on two public datasets with three fake image detectors indicate that our proposed method achieves state-of-the-art performance in both white-box and black-box attacks.

Original languageEnglish
Title of host publication2021 IEEE International Conference on Image Processing, ICIP 2021 - Proceedings
PublisherIEEE Computer Society
Pages3912-3916
Number of pages5
ISBN (Electronic)9781665441155
DOIs
StatePublished - 2021
Event28th IEEE International Conference on Image Processing, ICIP 2021 - Anchorage, United States
Duration: Sep 19 2021Sep 22 2021

Publication series

NameProceedings - International Conference on Image Processing, ICIP
Volume2021-September
ISSN (Print)1522-4880

Conference

Conference28th IEEE International Conference on Image Processing, ICIP 2021
Country/TerritoryUnited States
CityAnchorage
Period09/19/2109/22/21

Keywords

  • Adversarial Example
  • Deepfake

Fingerprint

Dive into the research topics of 'IMPERCEPTIBLE ADVERSARIAL EXAMPLES FOR FAKE IMAGE DETECTION'. Together they form a unique fingerprint.

Cite this