QIU Haoxuan, DU Yanhui, LU Tianliang. Design of DAPGD of Adversarial Attack Algorithm Against Deepfake[J]. Computer Engineering and Applications, 2022, 58(24): 97-106.
[1] CHOI Y,CHOI M,KIM M,et al.StarGAN:unified generative adversarial networks for multi-domain image-to-image translation[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition,2018:8789-8797.
[2] CHOI Y,UH Y,YOO J,et al.StarGAN v2:diverse image synthesis for multiple domains[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:8188-8197.
[3] ISOLA P,ZHU J Y,ZHOU T,et al.Image-to-image translation with conditional adversarial networks[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition,2017:1125-1134.
[4] PUMAROLA A,AGUDO A,MARTINEZ A M,et al.GANimation:anatomically-aware facial animation from a single image[C]//European Conference on Computer Vision.Cham:Springer,2018:818-833.
[5] WANG T C,LIU M Y,ZHU J Y,et al.High-resolution image synthesis and semantic manipulation with conditional GANs[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition,2018:8798-8807.
[6] ZAKHAROV E,SHYSHEYA A,BURKOV E,et al.Few-shot adversarial learning of realistic neural talking head models[C]//2019 IEEE/CVF International Conference on Computer Vision(ICCV),2019:9459-9468.
[7] ZHU J Y,PARK T,ISOLA P,et al.Unpaired image-to-image translation using cycle-consistent adversarial networks[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition,2017:2223-2232.
[8] CHESNEY R,CITRON D.Deepfakes and the new disinformation war[J].Foreign Affairs,2019,98(1):147-155.
[9] WANG R,JUEFEI-XU F,MA L,et al.FakeSpotter:a simple yet robust baseline for spotting AI-synthesized fake faces[C]//29th International Joint Conference on Artificial Intelligence,2020:3444-3451.
[10] WANG S Y,WANG O,ZHANG R,et al.CNN-generated images are surprisingly easy to spot...for now[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:8695-8704.
[11] COZZOLINO D,POGGI G,VERDOLIVA L.Recasting residual-based local descriptors as convolutional neural networks:an application to image forgery detection[J].arXiv:1703.04615,2017.
[12] MCCLOSKEY S,CHEN C,YU J.Focus manipulation detection via photometric histogram analysis[C]//2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition(CVPR),2018:1674-1682.
[13] SZEGEDY C,ZAREMBA W,SUTSKEVER I,et al.Intriguing properties of neural networks[C]//2nd International Conference on Learning Representations,2014.
[14] NGUYEN A,YOSINSKI J,CLUNE J.Deep neural networks are easily fooled:high confidence predictions for unrecognizable images[C]//2015 IEEE Conference on Computer Vision and Pattern Recognition(CVPR),2015:427-436.
[15] FAWZI A,MOOSAVI-DEZFOOLI S M,FROSSARD P.Robustness of classifiers:from adversarial to random noise[J].Advances in Neural Information Processing Systems,2016,29:1632-1640.
[16] FAWZI A,FAWZI O,FROSSARD P.Analysis of classifiers’ robustness to adversarial perturbations[J].Machine Learning,2018,107(3):481-508.
[17] GOODFELLOW I J,SHLENS J,SZEGEDY C.Explaining and harnessing adversarial examples[C]//International Conference on Learning Representations,2015.
[18] YEH C Y,CHEN H W,TSAI S L,et al.Disrupting image-translation-based deepfake algorithms with adversarial attacks[C]//Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision Workshops,2020:53-62.
[19] M?DRY A,MAKELOV A,SCHMIDT L,et al.Towards deep learning models resistant to adversarial attacks[J].arXiv:1706.06083,2017.
[20] LIU P,SUN L,MAO X Q,et al.A CycleGAN adversarial attack method based on output diversification initialization[J].Journal of Physics:Conference Series,2021,1948(1):012041.
[21] HUANG Q,ZHANG J,ZHOU W,et al.Initiative defense against facial manipulation[C]//Proceedings of the AAAI Conference on Artificial Intelligence,2021:1619-1627.
[22] KURAKIN A,GOODFELLOW I,BENGIO S.Adversarial examples in the physical world[J].arXiv:1607.02533,2016.
[23] CROCE F,HEIN M.Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks[C]//International Conference on Machine Learning,2020:2206-2216.
[24] RUIZ N,BARGAL S A,SCLAROFF S.Disrupting deepfakes:adversarial attacks against conditional image translation networks and facial manipulation systems[C]//European Conference on Computer Vision.Cham:Springer,2020:236-251.