Active defense method for deep counterfeiting of human face based on stable diffusion model
By performing adversarial optimization on images in the latent space of a stable diffusion model, the problem that existing technologies cannot effectively prevent facial image forgery is solved, high-quality adversarial images are generated, and the effect of active defense is achieved.
Patent Information
- Application Number
- CN202511221749.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-29
AI Technical Summary
Existing deepfake defense methods cannot effectively prevent attacks before facial image forgery occurs, and often introduce visible noise that affects image quality.
A stable diffusion model is used to perform adversarial optimization on images in the latent space. The latent variables are optimized through low-frequency region perturbations and multi-level loss functions to generate adversarial images to interfere with deep fake models while maintaining visual quality.
It achieves effective interference with deep fake models without destroying visual naturalness, generates high-quality adversarial images with concealment and robustness, and achieves active defense effects.
Smart Images

Figure CN120726705A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of active defense against deep fakes of faces, and in particular to an active defense method against deep fakes of faces based on a stable diffusion model. Background Art
[0002] In recent years, the rapid development of image generation technology, particularly the widespread application of generative adversarial networks (GANs), has significantly improved deepfake technology, enabling forged facial images to be highly realistic. These images can not only deceive facial recognition systems but can also be used to create fake videos and fabricate speeches by public figures, posing a serious threat to personal privacy and public safety.
[0003] Existing deepfake defense methods can be broadly categorized into two types: passive detection and active defense. Passive detection methods typically train a binary classifier to identify artifacts produced during the image forgery process, thereby determining the authenticity of facial images. While many existing passive detection techniques demonstrate excellent accuracy, they are essentially post-hoc defenses and are unable to effectively prevent harmful activity or curb the spread of false information before forged content is disseminated.
[0004] In contrast, active defense methods are dedicated to protecting images before forgery occurs, ensuring that even if facial images are used to generate deep fake content, they cannot meet the attacker's purpose. Currently, most mainstream active defense strategies are to directly add Norm-constrained adversarial perturbations are used to attack deepfake models, thereby corrupting the output of the forged image. However, such pixel-based perturbations often introduce visible noise, affecting the visual quality of the protected image. Therefore, an active defense solution that combines high stealth, image fidelity, and anti-counterfeiting effectiveness is urgently needed to effectively defend against deepfake attacks. Summary of the Invention
[0005] Purpose of the invention: In response to the above problems, the purpose of the present invention is to provide an active defense method for deep fake faces based on a stable diffusion model, which improves the visual quality of the protected image by adversarially optimizing the image in the latent space of the diffusion model.
[0006] Technical solution: The present invention's method for actively defending against deep fake facial expressions based on a stable diffusion model includes the following steps: Obtain the original face image, perform latent encoding on the original face image through a stable diffusion model, and obtain the initial latent variable; The initial latent variables are optimized in the low-frequency region to obtain latent variables; The latent variable is optimized based on the visual loss and adversarial loss that fuse pixel-level information and feature-level information to obtain the adversarial latent variable; Dynamically adjust the parameters of the stable diffusion model, denoise the adversarial latent variables based on the adjusted stable diffusion model, and obtain the initial adversarial latent code; Decode the initial adversarial latent code to obtain the final adversarial image; Adversarial images are used to induce deep fake models to generate failed images, achieving the goal of active defense against deep fake attacks.
[0007] Furthermore, the steps of obtaining the initial latent variables include: The original face image Input to the stable diffusion model, encode it through the image encoder in the variational autoencoder in the stable diffusion model, and obtain the initial latent code in the latent space ; Using the deterministic denoising diffusion implicit model inversion sampling method, based on The initial latent code is Iteratively map to high-noise latent code to obtain the initial latent variable that can reconstruct the original image , the formula is: , Where, is the noise residual predicted by the neural network, representing the stable diffusion model in Step 1 is the estimation of the noise, is the time-step dependent attenuation factor given by the noise scheduler.
[0008] Furthermore, the initial latent variables are optimized in the low-frequency region, and the steps of obtaining the latent variables include: The initial latent variable Applying a two-dimensional discrete cosine transform along the spatial dimension yields frequency domain coding , the formula is: , Where, is the frequency coordinate, are the feature map height and width, represents the number of channels of the latent variables, is the spatial position in the original potential feature ( ), is the spatial index, is the corresponding frequency domain two-dimensional discrete cosine transform coefficient; Coding in the frequency domain of Add disturbance term to the region , get the frequency domain code after perturbation , the formula is: , Where, is the side length of the low-frequency disturbance area; Frequency domain coding Then, through the two-dimensional inverse discrete cosine transform, the optimized latent variables are generated, and the formula is: .
[0009] Furthermore, the latent variables are optimized based on the visual loss and adversarial loss that fuse pixel-level information and feature-level information. The steps of obtaining the adversarial latent variables include: The latent variable Perform denoising and generate adversarial images , the visual loss is calculated based on the original face image and the adversarial image, and the formula is: , Calculate the adversarial loss, the formula is: , Where, is the original face image, is the mean square error, is the cosine distance, and are hyperparameters that adjust the weights of pixel-level and feature-level differences, R(·) is the image feature extraction network, and F(·) is the target deep fake model; The total loss is calculated based on visual loss and adversarial loss, and the formula is: , Where λ is a hyperparameter that adjusts the weight between visual loss and adversarial loss; Use gradient descent algorithm to learn latent variables Perform iterative optimization to obtain adversarial latent variables , the ultimate optimization goal is to make the optimized adversarial latent variables The final adversarial image generated Visually still the same as the original face image Consistent, while minimizing the impact of deepfake models generating capacity.
[0010] Furthermore, the steps of obtaining the initial adversarial latent code include: The adversarial image Input into the deep fake model and calculate the mean square error between the face image generated by the deep fake model and the original face image; According to the mean square error, the piecewise linear interpolation strategy is used to dynamically adjust the total number of reverse sampling steps T of the diffusion model. The rule is: , Where MSE stands for mean square error, is the threshold of mean square error and satisfies , are the minimum and maximum allowed sampling steps respectively; Define the original diffusion factor sequence as ,in represents the original diffusion factor at step T; Define the weight function, the formula is: , Where, Represent the maximum and minimum values of the weight respectively, is the weight adjustment interval; The diffusion factor is dynamically adjusted according to the mean square error. The formula is: ; Using the adjusted total number of sampling steps and diffusion factor sequences , using the DDIM sampling method to sample the adversarial latent variables Perform step-by-step denoising, the formula is: , Where, is the noise prediction output of the noise prediction network U-Net; After step-by-step denoising, the initial adversarial latent code is obtained .
[0011] Furthermore, the steps of obtaining the final adversarial image include: Decoder in variational autoencoder using stable diffusion model Encoding the initial adversarial latent Decode and get the final adversarial image .
[0012] Beneficial effects: Compared with the prior art, the present invention has the following significant advantages: 1. This invention generates adversarial face images that can effectively interfere with deep fake models by optimizing the low-frequency region of the latent code of facial images in the latent space of a stable diffusion model, achieving the goal of active defense against deep fakes without destroying visual naturalness. 2. To further improve the visual quality and defense effect of adversarial images, this paper constructs a multi-level fusion loss function that integrates pixel-level and feature-level information, jointly guiding the adversarial optimization of latent codes in the latent space to achieve the unity of image fidelity and adversarial resistance; 3. In the reconstruction stage, a dynamic diffusion path scheduler is proposed to adaptively control the diffusion process and achieve a balance between image quality and defense capability. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is a framework diagram of the three-stage active defense method of the present invention; Figure 2 This is a visualization of the defense effect of the present invention on the attribute editing model StarGAN; Figure 3 This is a visualization of the defense effect of the present invention against the expression manipulation model GANimation. DETAILED DESCRIPTION
[0014] In order to make the purpose, technical solutions and advantages of this application more clear, this application is further described in detail below with reference to the accompanying drawings and embodiments.
[0015] The active defense method for deep fake face based on the stable diffusion model described in this embodiment includes three stages: inversion, optimization, and reconstruction. In the inversion stage, the real face image is mapped to the latent space of the stable diffusion model to obtain the initial latent variables that can accurately reconstruct the original image; in the optimization stage, the initial latent variables are first converted into the frequency domain through discrete cosine transform, and then the low-frequency area of the latent code is iteratively optimized through the joint constraint of the carefully designed multi-level fusion visual loss and adversarial loss. Finally, the latent variables with adversarial characteristics are obtained through inverse discrete cosine transform. The adversarial latent variables can be reconstructed into an adversarial image that is highly visually consistent with the original image, while effectively interfering with the generation process of the deep fake model; in the reconstruction stage, a dynamic diffusion path scheduler is introduced to adaptively control the diffusion process, and the optimized latent code is denoised and reconstructed using the stable diffusion model to generate the final adversarial image with high visual quality and anti-forgery capability, thereby achieving active defense against deep fake attacks.
[0016] Combine Figure 1 As shown in this example, the specific implementation process of the active face deep forgery defense method based on the stable diffusion model includes the following steps: Step 1: Obtain the original face image, perform latent encoding on the original face image through a stable diffusion model, and obtain the initial latent variable.
[0017] Furthermore, the steps of obtaining the initial latent variables include: The original face image Input to the stable diffusion model, encode it through the image encoder in the variational autoencoder in the stable diffusion model, and obtain the initial latent code in the latent space ; Using the deterministic denoising diffusion implicit model inversion sampling method, based on The initial latent code is Iteratively map to high-noise latent code to obtain the initial latent variable that can reconstruct the original image , the formula is: , Where, is the noise residual predicted by the neural network. In this example, U-Net is used, which represents the stable diffusion model. Step 1 is the estimation of the noise, is the time-step dependent attenuation factor given by the noise scheduler.
[0018] The first stage is the inversion stage. In the inversion stage, the input original face image First, the image encoder in the variational autoencoder (VAE) of the stable diffusion model is Encoded as the initial latent variables in the latent space The image encoder It consists of a series of convolutional neural networks (CNN) stacked together to map the input image from pixel space to a lower-dimensional latent space representation. Subsequently, a deterministic DDIM (Denoising Diffusion Implicit Models) inversion process is used to invert the latent initial latent code. conduct Step 1 backward inference to generate the initial latent variables in the diffusion process , this latent code can be used to accurately reconstruct the original image The process can be expressed as: , , Where Inverse(·) represents the DDIM inversion operation. This inversion process is not performed in pixel space, but rather in the image latent space. This latent space inversion approach not only does not introduce additional noise but also preserves high-level semantic information in the image.
[0019] Specifically, the single-step inversion calculation of DDIM can be defined by the following formula: , in, is the noise residual predicted by the neural network, representing the diffusion model in Step 1 is the estimation of the noise, is the time-step dependent attenuation factor given by the noise scheduler.
[0020] This inversion operation can gradually map the clear image to any intermediate representation in the diffusion trajectory, laying the foundation for subsequent adversarial optimization in the latent space. Through this inversion stage, the initial latent variables with the ability to reconstruct the original image can be obtained. , which will be used in the subsequent optimization phase.
[0021] Step 2: Optimize the initial latent variables in the low-frequency region to obtain the latent variables.
[0022] Furthermore, the initial latent variables are optimized in the low-frequency region, and the steps of obtaining the latent variables include: The initial latent variable Applying a two-dimensional discrete cosine transform along the spatial dimension yields frequency domain coding , the formula is: , Where, is the frequency coordinate, are the feature map height and width, represents the number of channels of the latent variables, is the spatial position in the original potential feature ( ), is the spatial index, is the corresponding frequency domain two-dimensional discrete cosine transform coefficient; Coding in the frequency domain of Add disturbance term to the region , get the frequency domain code after perturbation , the formula is: , Where, is the side length of the low-frequency disturbance area; Frequency domain coding Then, through the two-dimensional inverse discrete cosine transform, the optimized latent variables are generated, and the formula is: .
[0023] Step 3: Optimize the latent variables based on the visual loss and adversarial loss that fuse pixel-level information and feature-level information to obtain adversarial latent variables.
[0024] Furthermore, the latent variables are optimized based on the visual loss and adversarial loss that fuse pixel-level information and feature-level information. The steps of obtaining the adversarial latent variables include: The latent variable Perform denoising and generate adversarial images , the visual loss is calculated based on the original face image and the adversarial image, and the formula is: , Calculate the adversarial loss, the formula is: , Where, is the original face image, is the mean square error, is the cosine distance, and are hyperparameters that adjust the weights of pixel-level and feature-level differences, R(·) is the image feature extraction network, and F(·) is the target deep fake model; The total loss is calculated based on visual loss and adversarial loss, and the formula is: , Where λ is a hyperparameter that adjusts the weight between visual loss and adversarial loss; Use gradient descent algorithm to learn latent variables Perform iterative optimization to obtain adversarial latent variables , the ultimate optimization goal is to make the optimized adversarial latent variables The final adversarial image generated Visually still the same as the original face image Consistent, while minimizing the impact of deepfake models generating capacity.
[0025] The above steps 2 and 3 are taken as the optimization stage. In the optimization stage, although the initial potential variables obtained in the inversion stage The original image can be reconstructed with high fidelity through the diffusion model, but the initial latent variable It does not have adversarial properties, so it cannot effectively interfere with the forgery process of the deep fake model. In order to achieve the active defense goal, it is necessary to Conduct targeted adversarial optimization to generate adversarial potential variables with attack capabilities .
[0026] In order to improve the concealment and effectiveness of the adversarial disturbance, this embodiment proposes a frequency domain-based adversarial optimization strategy. First, the initial latent variables are transformed into is mapped to a frequency domain representation to impose low perceptual perturbations in the frequency domain, thereby obtaining adversarial latent codes. For the potential code to be optimized, first apply a two-dimensional DCT transform along the spatial dimension (independently for each channel) to obtain the frequency domain code ; After obtaining the frequency domain representation, select the low-frequency region in the spectrum ( Add disturbance term to region , control the disturbance amplitude and impact range; then generate the optimized adversarial latent code through inverse DCT transform .
[0027] This frequency-domain perturbation strategy, by mapping the latent code to the frequency domain and focusing on applying perturbations to low-frequency subbands, has three advantages: first, low-frequency components are less sensitive in visual perception, making the perturbation difficult to be detected by the human eye and more concealed; second, low-frequency information is well preserved in image compression (such as JPEG) and filtering operations, making the perturbation more robust; finally, compared to applying large-scale perturbations in the entire domain or high-frequency domain, optimizing only a small number of key low-frequency coefficients can significantly affect the latent code distribution, thereby improving optimization efficiency and reducing damage to the original image structure.
[0028] Most current active defense methods rely on distorting forged images to destroy the forgery effect, but such methods often introduce obvious structural perturbations, such as black shadows or artifacts, causing the problem of "stigmatization" of facial images, which is particularly significant in the face area. Once such visually distorted facial images are publicly disseminated, they are likely to cause public misunderstanding and negative social impact. To overcome the above problems, this embodiment adopts a defense strategy for failure attacks. Specifically, by optimizing the latent variables, the generated forged image is made as consistent as possible with the original image, thereby losing the "deformation" ability that the forgery should have, achieving the effect of disrupting the target of the deep forgery model.
[0029] In order to further improve the visual quality and defense capability of the protected image, and taking full account of the importance of facial image features, a multi-level fusion visual loss function is proposed in this embodiment. and adversarial loss function , combining pixel and feature information to comprehensively optimize the latent variables. The two guide the optimization process from the two aspects of image fidelity and defense effectiveness. Among them, visual loss Ensure that the generated adversarial image is consistent with the original image in terms of appearance and perception, and the adversarial loss The "adversarial game" with the deep fake model is used to maximize the closeness between the fake image and the original image, thereby making the fake output invalid.
[0030] To extract high-level semantic features from images, this paper uses a pretrained ResNet-50 network as the image feature extraction network. The inputs are the original image and the adversarial image, and the outputs are their features. The distance between image features is measured using cosine distance to reflect consistency at the perceptual level; pixel-level differences are calculated using mean squared error (MSE).
[0031] The two multi-level fusion losses are constrained together to make the generated protected images have both high visual quality and strong adversarial performance. The ultimate optimization goal is to make the optimized latent code Generated protection image Visually still the same as the original image consistent while minimizing the risk of counterfeit models The optimization process perturbs the latent space of facial images rather than directly interfering with the image pixel space, resulting in enhanced stealth and robustness. This allows for effective defense against deepfake attacks while maintaining the naturalness of the image.
[0032] Step 4: Dynamically adjust the parameters of the stable diffusion model, denoise the adversarial latent variables based on the adjusted stable diffusion model, and obtain the initial adversarial latent code.
[0033] Furthermore, the steps of obtaining the initial adversarial latent code include: The adversarial image Input to the deepfake model , computing deep fake models The mean square error between the generated face image and the original face image; According to the mean square error, the piecewise linear interpolation strategy is used to dynamically adjust the total number of reverse sampling steps T of the diffusion model. The rule is: , Where MSE stands for mean square error, is a pre-set threshold, such as set up is 0.01 and satisfies , are the minimum and maximum allowed sampling steps respectively; Define the original diffusion factor sequence as ,in represents the original diffusion factor at step T; Define the weight function, the formula is: , Where, Represent the maximum and minimum values of the weight respectively, is the weight adjustment interval; The diffusion factor is dynamically adjusted according to the mean square error. The formula is: ; Using the adjusted total number of sampling steps and diffusion factor sequences , using the DDIM sampling method to sample the adversarial latent variables Perform step-by-step denoising, the formula is: , Where, is the noise prediction output of the noise prediction network U-Net; After step-by-step denoising, the initial adversarial latent code is obtained .
[0034] Step 5: Decode the initial adversarial latent code to obtain the final adversarial image.
[0035] Furthermore, the steps of obtaining the final adversarial image include: Decoder in variational autoencoder using stable diffusion model Encoding the initial adversarial latent Decode and get the final adversarial image .
[0036] Step 6: Use the adversarial image to induce the deep fake model to generate failed images, thereby achieving the goal of active defense against deep fake attacks.
[0037] The adversarial image Input into the deep fake model, generate failure images, and use the failure images for defense.
[0038] Taking steps 4 to 6 as the reconstruction phase, in order to further improve the defense capability and image quality of the present invention, the present invention proposes a dynamic diffusion path scheduler module in the reconstruction phase to dynamically control the number of diffusion steps and the scheduling parameters of each step during the DDIM denoising process. This module is based on the deterministic diffusion sampling path and combines the feedback information of the deep fake model to achieve the goal of countering latent variables. Personalized sampling scheduling enhances defense flexibility and image stability.
[0039] The dynamic diffusion path scheduler module uses the mean squared error (MSE) between the deep fake model-generated image and the original image as a feedback indicator, calculated as follows: , Where, represents the output image of the deep fake model at the i-th pixel, represents the original image at the i-th pixel, is the total number of image pixels.
[0040] Based on the MSE of the feedback, the dynamic diffusion path scheduler dynamically adjusts the total number of reverse sampling steps of the diffusion model ,The dynamic adjustment strategy of the sampling steps achieves a smooth change of ,sampling steps under different defense requirements, avoids the drastic jump of ,sampling steps, and improves the stability of the defense and ,image quality.
[0041] The dynamic diffusion path scheduler also adjusts the scheduling factor of the diffusion process according to the feedback MSE. Dynamic adjustments are made. When defense effectiveness is poor (MSE is high), the diffusion factor is increased, enhancing the potential perturbation strength; conversely, when defense effectiveness is low, the perturbation is reduced, preserving the visual quality of the image. Through this dynamic path scheduling mechanism, this method adaptively balances "interference capability" and "visual quality" without significantly increasing computational complexity, achieving more practical active defense.
[0042] Using the adjusted sampling steps and diffusion factor sequences , a deterministic DDIM reverse sampling method is used to counter the potential coding Perform step-by-step denoising and update the latent variables. This step ensures the determinism of the denoising process and the dynamic adaptability of the path.
[0043] After completing the step-by-step denoising, the initial adversarial latent code is obtained , by stabilizing the variational autoencoder (VAE) decoder in the diffusion model Decode and generate the final adversarial protection image: .
[0044] In this embodiment, through the three-stage process of "inversion-optimization-reconstruction", a protection image with high visual quality and strong anti-attack capability can be generated. While visually highly consistent with the original image, its latent space has been finely tuned to effectively disrupt the deepfake model's forgery process, achieving proactive defense. The resulting image not only exhibits excellent visual quality and semantic consistency, but also significantly reduces the deepfake model's ability to manipulate it. This ensures image practicality while improving security and anti-forgery capabilities, achieving a dual optimization of "image quality" and "anti-counterfeiting capabilities."
[0045] In order to further demonstrate the effectiveness and excellence of the active defense method for deep fake faces based on the stable diffusion model described in the present invention, the following examples are used for illustration. The dataset used in this embodiment is CelebA-HQ, which contains 30,000 high-resolution face images. The image size is first adjusted to 256×256, and 1,000 face images of different identities are randomly selected for evaluation. Defense is performed against two types of deep fake models, namely the attribute editing model StarGAN and the expression manipulation model GANimation. The compared methods are AdvNoise, which directly adds perturbations in the pixel space, and LAE and LOFT, which add perturbations in the GAN latent space. The results of the characteristic cosine similarity index for the defense performance test of the attribute editing model StarGAN are shown in Table 1. The higher the index, the better the model performance.
[0046] Table 1
[0047]
[0048] like Figure 2 As shown in the attribute editing task, the original image underwent significant attribute changes after the StarGAN operation, while the image protected by the defense method described in this invention could not be successfully forged, demonstrating the strong defense capabilities of this invention. As shown in Table 1, the feature cosine similarity corresponding to the five attribute categories is higher than that of other methods, indicating that this invention has superior defense performance to existing methods.
[0049] like Figure 3 As shown in the expression manipulation task, GANimation can effectively manipulate the original image's expressions, while the images protected by this method are virtually unmanipulatable, demonstrating that our method effectively defends against expression manipulation attacks. Furthermore, the Euclidean distance metric quantitatively tested against the expression manipulation model GANimation, as shown in Table 2, shows that the Euclidean distances corresponding to the four expressions obtained using our defense method are all lower than those of other methods.
[0050] Table 2
[0051]
[0052] Table 3
[0053] Table 3 shows the visual quality assessment results of protected images. In terms of image visual quality, the proposed method outperforms the comparison method in four indicators: structural similarity index (SSIM), peak signal-to-noise ratio (PSNR), learned perceptual image patch similarity (LPIPS), and mean square error (MSE). This shows that the images generated by the proposed method are clearer, more realistic, and structurally consistent, with better visual quality.
Claims
1. An active defense method for deep fake face detection based on a stable diffusion model, characterized by: The following steps are involved: Obtain the original face image, perform latent encoding on the original face image through a stable diffusion model, and obtain the initial latent variable; The initial latent variables are optimized in the low-frequency region to obtain latent variables; The latent variable is optimized based on the visual loss and adversarial loss that fuse pixel-level information and feature-level information to obtain the adversarial latent variable; Dynamically adjust the parameters of the stable diffusion model, denoise the adversarial latent variables based on the adjusted stable diffusion model, and obtain the initial adversarial latent code; Decode the initial adversarial latent code to obtain the final adversarial image; Adversarial images are used to induce deep fake models to generate failed images, achieving the goal of active defense against deep fake attacks.
2. The active defense method for deep fake face detection based on the stable diffusion model according to claim 1 is characterized in that: The steps to obtain the initial latent variables include: The original face image Input to the stable diffusion model, encode it through the image encoder in the variational autoencoder in the stable diffusion model, and obtain the initial latent code in the latent space ; Using the deterministic denoising diffusion implicit model inversion sampling method, based on The initial latent code is Iteratively map to high-noise latent code to obtain the initial latent variable that can reconstruct the original image , the formula is: , Where, is the noise residual predicted by the neural network, representing the stable diffusion model in Step 1 is the estimation of the noise, is the time-step dependent attenuation factor given by the noise scheduler.
3. The active defense method for deep fake face detection based on the stable diffusion model according to claim 2 is characterized in that: The steps of optimizing the initial latent variables in the low-frequency region to obtain the latent variables include: The initial latent variable Applying a two-dimensional discrete cosine transform along the spatial dimension yields frequency domain coding , the formula is: , Where, is the frequency coordinate, are the feature map height and width, represents the number of channels of the latent variables, is the spatial position in the original potential feature ( ), is the spatial index, is the corresponding frequency domain two-dimensional discrete cosine transform coefficient; Coding in the frequency domain of Add disturbance term to the region , get the frequency domain code after perturbation , the formula is: , Where, is the side length of the low-frequency disturbance area; Frequency domain coding Then, through the two-dimensional inverse discrete cosine transform, the optimized latent variables are generated, and the formula is: 。 4. The method for actively defending against deep fakes of human faces based on a stable diffusion model according to claim 3, characterized in that: The steps of optimizing the latent variable based on the visual loss and adversarial loss that fuse pixel-level information and feature-level information to obtain the adversarial latent variable include: The latent variable Perform denoising and generate adversarial images , the visual loss is calculated based on the original face image and the adversarial image, and the formula is: , Calculate the adversarial loss, the formula is: , Where, is the original face image, is the mean square error, is the cosine distance, and are hyperparameters that adjust the weights of pixel-level and feature-level differences, R(·) is the image feature extraction network, and F(·) is the target deep fake model; The total loss is calculated based on visual loss and adversarial loss, and the formula is: , Where λ is a hyperparameter that adjusts the weight between visual loss and adversarial loss; Use gradient descent algorithm to learn latent variables Perform iterative optimization to obtain adversarial latent variables , the ultimate optimization goal is to make the optimized adversarial latent variables The final adversarial image generated Visually still the same as the original face image Consistent, while minimizing the impact of deepfake models generating capacity.
5. The method for actively defending against deep fake faces based on a stable diffusion model according to claim 4, characterized in that: The steps to obtain the initial adversarial latent code include: The adversarial image Input into the deep fake model and calculate the mean square error between the face image generated by the deep fake model and the original face image; According to the mean square error, the piecewise linear interpolation strategy is used to dynamically adjust the total number of reverse sampling steps T of the diffusion model. The rule is: , Where MSE stands for mean square error, is the threshold of mean square error and satisfies , are the minimum and maximum allowed sampling steps respectively; Define the original diffusion factor sequence as ,in represents the original diffusion factor at step T; Define the weight function, the formula is: , Where, Represent the maximum and minimum values of the weight respectively, is the weight adjustment interval; The diffusion factor is dynamically adjusted according to the mean square error. The formula is: ; Using the adjusted total number of sampling steps and diffusion factor sequences , using the DDIM sampling method to sample the adversarial latent variables Perform step-by-step denoising, the formula is: , Where, is the noise prediction output of the noise prediction network U-Net; After step-by-step denoising, the initial adversarial latent code is obtained .
6. The method for actively defending against deep fake facial expressions based on a stable diffusion model according to any one of claims 1 to 5, characterized in that: The steps to obtain the final adversarial image include: Decoder in variational autoencoder using stable diffusion model Encoding the initial adversarial latent Decode and get the final adversarial image .
Citation Information
Patent Citations
Texture synthesis method based on diffusion model and reweighting strategy
CN118196227A
Human face active defense method for portrait protection
CN118262401A
Attack resisting method based on diffusion model
CN119047536A
Active defense method for deeply counterfeited face by using physical countermeasure watermark
CN119831822A