StegaFFD: 미세 영역 스티거노그래피 도메인 리프팅을 이용한 개인 정보 보호 안면 위조 탐지
StegaFFD: Privacy-Preserving Face Forgery Detection via Fine-Grained Steganographic Domain Lifting
대부분의 기존 안면 위조 탐지(FFD) 모델은 원본 안면 이미지에 대한 접근을 전제로 합니다. 그러나 실제로는 클라이언트-서버 환경에서 개인적인 안면 데이터가 전송 과정에서 가로채이거나 신뢰할 수 없는 서버에 의해 유출될 수 있습니다. 기존의 개인 정보 보호 방법인 익명화, 암호화 또는 왜곡은 유출을 부분적으로 완화하지만, 종종 심각한 의미론적 왜곡을 초래하여 이미지가 명백하게 보호되었음을 드러냅니다. 이는 공격자에게 경고를 보내어 더 공격적인 전략을 유도하고, 이러한 과정을 고양이와 쥐 게임으로 만듭니다. 또한, 이러한 방법은 이미지 내용을 크게 조작하여, FFD 모델이 인식하기 어려운 저하 또는 인공물을 발생시켜 위조 흔적을 감지하는 데 어려움을 줍니다. 이미지 스티거노그래피의 발전을 바탕으로, 우리는 의심을 피하면서 개인 정보를 보호하는 스티거노그래피 기반 안면 위조 탐지 프레임워크(StegaFFD)를 제안합니다. StegaFFD는 안면 이미지를 자연스러운 커버 이미지 내에 숨기고, 스티거노그래피 도메인에서 직접 위조 탐지를 수행합니다. 그러나 숨겨진 위조 관련 특징은 매우 미세하며, 커버 이미지의 의미론적 요소에 의해 간섭을 받아 상당한 어려움을 야기합니다. 이를 해결하기 위해, 우리는 저주파 특성을 고려한 분해(LFAD) 및 공간-주파수 차등 주의(SFDA)를 제안하여, 저주파 커버 이미지의 간섭을 억제하고 숨겨진 안면 특징의 인식을 향상시킵니다. 또한, 스티거노그래피 도메인 정렬(SDA)을 도입하여 숨겨진 안면 이미지의 표현을 원본 이미지와 일치시켜, 모델이 스티거노그래피 도메인에서 미세한 안면 단서를 인식하는 능력을 향상시킵니다. 일곱 개의 FFD 데이터 세트에 대한 광범위한 실험 결과, StegaFFD는 뛰어난 불투명성을 달성하고, 공격자의 의심을 피하며, 기존의 안면 개인 정보 보호 방법에 비해 FFD 정확도를 더 잘 유지하는 것으로 나타났습니다.
Most existing Face Forgery Detection (FFD) models assume access to raw face images. In practice, under a client-server framework, private facial data may be intercepted during transmission or leaked by untrusted servers. Previous privacy protection approaches, such as anonymization, encryption, or distortion, partly mitigate leakage but often introduce severe semantic distortion, making images appear obviously protected. This alerts attackers, provoking more aggressive strategies and turning the process into a cat-and-mouse game. Moreover, these methods heavily manipulate image contents, introducing degradation or artifacts that may confuse FFD models, which rely on extremely subtle forgery traces. Inspired by advances in image steganography, which enable high-fidelity hiding and recovery, we propose a Stega}nography-based Face Forgery Detection framework (StegaFFD) to protect privacy without raising suspicion. StegaFFD hides facial images within natural cover images and directly conducts forgery detection in the steganographic domain. However, the hidden forgery-specific features are extremely subtle and interfered with by cover semantics, posing significant challenges. To address this, we propose Low-Frequency-Aware Decomposition (LFAD) and Spatial-Frequency Differential Attention (SFDA), which suppress interference from low-frequency cover semantics and enhance hidden facial feature perception. Furthermore, we introduce Steganographic Domain Alignment (SDA) to align the representations of hidden faces with those of their raw counterparts, enhancing the model's ability to perceive subtle facial cues in the steganographic domain. Extensive experiments on seven FFD datasets demonstrate that StegaFFD achieves strong imperceptibility, avoids raising attackers' suspicion, and better preserves FFD accuracy compared to existing facial privacy protection methods.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.