Publications
Sort:
Open Access Research Article Just Accepted
Towards Robust and Highly Stealthy Proactive Deepfake Defense on Consumer Electronic Devices
Tsinghua Science and Technology
Available online: 10 February 2026
Abstract PDF (6.4 MB) Collect
Downloads:103

The integration of AIGC technologies into consumer electronics has democratized the creation of highly realistic facial deepfakes, posing unprecedented threats to personal identity security and undermining trust in digital ecosystem. Current proactive defense methods primarily operate by injecting perturbations directly into the pixel space of facial images to disrupt deepfake synthesis. However, such pixel-level modifications often introduce noticeable artifacts, making them easily detectable by human observers and vulnerable to common image transformations. To tackle this issue, this paper proposes DiffDefend, a novel three-stage proactive defense framework based on low-frequency perturbations in the diffusion latent space. The framework first employs a stable diffusion model to encode the input image into a latent representation that preserves high-fidelity reconstruction capability. Adversarial perturbations are then introduced specifically into the low-frequency subband of the latent code, which is extracted via discrete wavelet transform (DWT/Discrete Wavelet Transform), and optimized through an adversarial game combining visual and adversarial losses, yielding an adversarial latent representation. Ultimately, the adversarial latent code is reconstructed into an adversarial image leveraging the powerful generative capabilities of the diffusion model, effectively defending against deepfake manipulations. Moreover, we design a multi-level loss that combines pixel-level and semantic-level constraints to enhance the visual quality and defense efficacy of the adversarial image. To evaluate the efficacy of our method, we conduct experiments on two representative deepfake tasks: attribute editing and face reenactment. Experimental results demonstrate that our method achieves superior performance over existing benchmarks in both visual quality and defensive performance.

Total 1