节点文献
基于对抗样本和智能水印的人脸伪造主动防御研究
Active Defense against Face Forgery Based on Adversarial Samples and Intelligent Watermark
【作者】 王瑜;
【导师】 方贤进;
【作者基本信息】 安徽理工大学 , 计算机技术, 2025, 硕士
【摘要】 随着人工智能的快速发展,图像伪造技术不断成熟,真实图像和合成图像之间的界限变得模糊。这为艺术创作打开便捷大门的同时,也为图像真实性带来了巨大的威胁。在此背景下,人脸伪造的主动防御研究应运而生,然而主动防御技术仍存在许多亟待解决的问题。例如,通过向图像中添加对抗样本来干扰伪造模型的生成,但这一操作会降低防伪图像质量。此外,大部分主动防御方法可防御恶性操作生成,但也会破坏良性图像操作,产生失真输出。本文针对以上问题,完成了以下工作:(1)提出一种基于注意力掩码与特征提取的人脸伪造主动防御方法,解决人脸图像在未经授权情况下被伪造或篡改的问题,同时提高防伪图像视觉质量。该方法旨在采取攻击性措施,向图像中加入可干扰伪造模型的对抗样本,从源头上预防图像被伪造,同时提高被保护图像的视觉质量。首先,采用改进的梯度下降法生成对抗扰动并将这些扰动添加至原始图像,使原始图像在经过伪造处理后生成模糊的虚假图像,同时,在生成器中增添注意力掩码,以增强关键特征通道,从而降低复杂背景和光照带来的影响;其次,使用VGG16预训练网络提取图像特征,在特征图层面提升对抗图像的视觉质量。实验表明,所提模型可有效防御人脸伪造,同时提升对抗图像的视觉质量。(2)提出一种基于智能水印的人脸伪造主动防御方法,解决当前主动防御在良性图像操作后失真问题。该方法使用水印作为对抗样本嵌入图像,干扰伪造模型的生成,并且水印的嵌入与提取机制具备良好的可逆性与唯一性,可帮助判别图像版权归属。首先,模型中添加噪声池,模拟JPEG压缩、模糊处理、饱和度调整以及裁剪操作等良性图像操作;其次使用信息损失函数,可根据图像特征和操作类型,动态调整参数,最大限度降低图像操作引发的信息破坏,同时借助对抗性损失函数从像素级对图像进行修复与重构,显著提升图像在复杂操作后的保真性,确保图像的视觉质量和关键信息完整性。实验表明,所提模型防御性能出色,在实际应用场景中也具备切实可行的效果,可有效抵御多种类型的人脸伪造攻击,并且能够高效对抗良性图像操作,有效保障了水印图像的完整性与可用性。图[14]表[8]参[79]
【Abstract】 With the rapid development of artificial intelligence,image forgery technology continues to mature,and the boundary between real images and synthetic images has become blurred.While this opens the door to convenient artistic creation,it also poses a huge threat to the authenticity of images.In this context,active defense research on face forgery has emerged,but there are still many problems to be solved in active defense technology.For example,adversarial samples are added to the image to interfere with the generation of the forged model,but this operation will reduce the quality of the anti-counterfeiting image.In addition,most active defense methods can defend against the generation of malicious operations,but they will also destroy benign image operations and produce distorted outputs.In response to the above problems,this paper has completed the following work:(1)An active face forgery defense method based on attention mask and feature extraction is proposed to solve the problem of unauthorized forgery or tampering of face images and improve the visual quality of anti-counterfeiting images.This method was designed to take offensive measures to interfere with forgery models by adding adversarial examples into the image,so that the image was prevented forgery from the source and the visual quality of the protected image was enhanced.Firstly,an improved gradient descent method was employed to generate and add adversarial perturbations to the original image,resulting in the generation of a blurred false image after forgery processing the original image.At the same time,the attention mask was incorporated into the generator to enhance key feature channels,thereby reducing the influence of complex backgrounds and lighting.Additionally,the VGG16 pretrained network was utilized to extract image features,thereby improving the visual quality of adversarial images at feature map level.The above indicates that the proposed method defends against face image forgery effectively while enhancing the visual quality of adversarial images.(2)An active defense method for face forgery based on intelligent watermark is proposed to solve the problem of distortion of current active defense after benign image operations.This method uses watermark as adversarial sample to embed into the image to interfere with the generation of forgery model.The embedding and extraction mechanism of watermark has good reversibility and uniqueness,which can help to identify the copyright of the image.Firstly,a noise pool is added to the model to simulate benign image operations such as JPEG compression,blur processing,saturation adjustment and cropping operations.Secondly,the information loss function is used to dynamically adjust the parameters according to the image features and operation type to minimize the information damage caused by image operation.At the same time,the adversarial loss function is used to repair and reconstruct the image at the pixel level,which significantly improves the fidelity of the image after complex operations and ensures the visual quality and key information integrity of the image.Experiments show that the proposed model has excellent defense performance and has a practical effect in practical application scenarios.It can effectively resist various types of face forgery attacks and can effectively resist benign image operations,effectively ensuring the integrity and availability of watermarked images.Figure[14]Table[8]Reference[79]
【Key words】 face forgery; active defense; adversarial example; watermark;
- 【网络出版投稿人】 安徽理工大学 【网络出版年期】2025年 10期
- 【分类号】TP391.41;TP309.7