Pith. sign in

REVIEW 1 cited by

AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2312.08675 v1 pith:X3MH2ZSW submitted 2023-12-14 cs.CV cs.CR

classification cs.CVcs.CR
keywords deepfakeattackdetectionadversarialalgorithmsapplicationsattacksattribute
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

While DeepFake applications are becoming popular in recent years, their abuses pose a serious privacy threat. Unfortunately, most related detection algorithms to mitigate the abuse issues are inherently vulnerable to adversarial attacks because they are built atop DNN-based classification models, and the literature has demonstrated that they could be bypassed by introducing pixel-level perturbations. Though corresponding mitigation has been proposed, we have identified a new attribute-variation-based adversarial attack (AVA) that perturbs the latent space via a combination of Gaussian prior and semantic discriminator to bypass such mitigation. It perturbs the semantics in the attribute space of DeepFake images, which are inconspicuous to human beings (e.g., mouth open) but can result in substantial differences in DeepFake detection. We evaluate our proposed AVA attack on nine state-of-the-art DeepFake detection algorithms and applications. The empirical results demonstrate that AVA attack defeats the state-of-the-art black box attacks against DeepFake detectors and achieves more than a 95% success rate on two commercial DeepFake detectors. Moreover, our human study indicates that AVA-generated DeepFake images are often imperceptible to humans, which presents huge security and privacy concerns.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Fooling the Watchers: Breaking AIGC Detectors via Semantic Prompt Attacks

    cs.CV 2025-05 reject novelty 4.0 of 10

    A grammar-tree and Monte Carlo search method automatically crafts prompts that can make synthetic portraits evade AIGC detectors, but the reported evidence is sparse and partly contradictory.

Pith tools