Adversarial Attack on Deepfake Detection Using RL Based Texture Patches Conference

Fernandes, SL, Jha, SK. (2020). Adversarial Attack on Deepfake Detection Using RL Based Texture Patches . EURO-PAR 2011 PARALLEL PROCESSING, PT 1, 12535 LNCS 220-235. 10.1007/978-3-030-66415-2_14

cited authors

  • Fernandes, SL; Jha, SK

abstract

  • The advancements in GANs have made creating deepfake videos a relatively easy task. Considering the threat that deepfake videos pose for manipulating political opinion, recent research has focused on ways to better detect deepfake videos. Even though researchers have had some success in detecting deepfake videos, it has been found that these detection systems can be attacked. The key contributions of this paper are (a) a deepfake dataset created using a commercial website, (b) validation of the efficacy of DeepExplainer and heart rate detection from the face for differentiating real faces from adversarial attacks, and (c) the proposal of an attack on the FaceForensics++ deepfake detection system using a state-of-the-art reinforcement learning-based texture patch attack. To the best of our knowledge, we are the first to successfully attack FaceForensics++ on our commercial deepfake dataset and DeepfakeTIMIT dataset.

publication date

  • January 1, 2020

published in

Digital Object Identifier (DOI)

International Standard Book Number (ISBN) 13

start page

  • 220

end page

  • 235

volume

  • 12535 LNCS