AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

FSD-GAN: Generative Adversarial Training for Face Swap Detection via the Latent Noise Fingerprint

School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
Purple Mountain Laboratories, Nanjing 211111, China
School of Computer Science and Engineering, Southeast University, Nanjing 211189, China
Show Author Information

Abstract

Current studies against DeepFake attacks are mostly passive methods that detect specific defects of DeepFake algorithms, lacking generalization ability. Meanwhile, existing active defense methods only focus on defending against face attribute manipulations, and there remain enormous challenges to establishing an active and sustainable defense mechanism for face swap detection. Therefore, we propose a novel training framework called FSD-GAN (Face Swap Detection based on Generative Adversarial Network), immune to the evolution of face swap attacks. Specifically, FSD-GAN contains three modules: the data processing module, the attack module that generates fake faces only used in training, and the defense module that consists of a fingerprint generator and a fingerprint discriminator. We embed the latent noise fingerprints generated by the fingerprint generator into face images, unperceivable to attackers visually and statistically. Once an attacker uses these protected faces to perform face swap attacks, these fingerprints will be transferred from training data (protected faces) to generative models (real-world face swap models), and they also exist in generated results (swapped faces). Our discriminator can easily detect latent noise fingerprints embedded in face images, converting the problem of face swap detection to verifying if fingerprints exist in swapped face images or not. Moreover, we alternately train the attack and defense modules under an adversarial framework, making the defense module more robust. We illustrate the effectiveness and robustness of FSD-GAN through extensive experiments, demonstrating that it can confront various face images, mainstream face swap models, and JPEG compression under different qualities.

Electronic Supplementary Material

Download File(s)
JCST-2304-13337-Highlights.pdf (196 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 397-412

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Ge J-W, Cao J-X, Zhao Z-X, et al. FSD-GAN: Generative Adversarial Training for Face Swap Detection via the Latent Noise Fingerprint. Journal of Computer Science and Technology, 2025, 40(2): 397-412. https://doi.org/10.1007/s11390-024-3337-8

1544

Views

9

Crossref

5

Web of Science

9

Scopus

0

CSCD

Received: 09 May 2023
Accepted: 22 October 2024
Published: 31 March 2025
© Institute of Computing Technology, Chinese Academy of Sciences 2025