Malicious Deepfakes have led to a sharp conflict over distinguishing between genuine and forged faces. Although many countermeasures have been developed to detect Deepfakes ex-post, undoubtedly, passive forensics has not considered any preventive measures for the pristine face before foreseeable manipulations. To complete this forensics ecosystem, we thus put forward the proactive solution dubbed SepMark, which provides a unified framework for source tracing and Deepfake detection. SepMark originates from encoder-decoder-based deep watermarking but with two separable decoders. For the first time the deep separable watermarking, SepMark brings a new paradigm to the established study of deep watermarking, where a single encoder embeds one watermark elegantly, while two decoders can extract the watermark separately at different levels of robustness. The robust decoder termed Tracer that resists various distortions may have an overly high level of robustness, allowing the watermark to survive both before and after Deepfake. The semi-robust one termed Detector is selectively sensitive to malicious distortions, making the watermark disappear after Deepfake. Only SepMark comprising of Tracer and Detector can reliably trace the trusted source of the marked face and detect whether it has been altered since being marked; neither of the two alone can achieve this. Extensive experiments demonstrate the effectiveness of the proposed SepMark on typical Deepfakes, including face swapping, expression reenactment, and attribute editing.
翻译:恶意深度伪造技术导致了真假人脸之间的尖锐冲突。尽管已开发出诸多事后检测深度伪造的对策,但被动取证无疑未考虑在可预见的篡改发生前对原始人脸采取任何预防措施。为完善这一取证生态系统,我们提出名为SepMark的主动防御方案,该方案为源追踪与深度伪造检测提供了统一框架。SepMark源于基于编解码器的深度水印技术,但创新性地采用两个可分离解码器。作为首个深度可分离水印方案,SepMark为既有的深度水印研究带来新范式——单一编码器优雅地嵌入一个水印,而两个解码器能在不同鲁棒性层级上分别提取水印。其中名为Tracer的鲁棒解码器可抵抗各类失真,其超高的鲁棒性使水印在深度伪造前后均能存续;名为Detector的半鲁棒解码器则对恶意失真具有选择性敏感特性,使水印在深度伪造后消失。仅有同时包含Tracer与Detector的SepMark能可靠追溯标记人脸的受信任来源,并检测其是否在标记后遭到篡改;二者缺一则无法实现此功能。大量实验表明,所提出的SepMark在典型深度伪造场景(包括换脸、表情重演与属性编辑)中具备有效性。