{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T12:24:16Z","timestamp":1770985456599,"version":"3.50.1"},"reference-count":76,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2024,12,25]],"date-time":"2024-12-25T00:00:00Z","timestamp":1735084800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62372452"],"award-info":[{"award-number":["62372452"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Multimedia Comput. Commun. Appl."],"published-print":{"date-parts":[[2025,2,28]]},"abstract":"<jats:p>\n            Deep neural networks have enhanced face synthesis detection in discriminating Artificial Intelligence Generated Content (AIGC). However, their security is threatened by the injection of carefully crafted triggers during model training (i.e., backdoor attacks). Although existing backdoor defenses and manual data selection are able to mitigate those using human-eye-sensitive triggers, such as patches or adversarial noises, the more challenging natural backdoor triggers remain insufficiently researched. To further investigate natural triggers, we propose a novel analysis-by-synthesis backdoor attack against face synthesis detection models, which embeds natural triggers in the latent space. We study such backdoor vulnerability from two perspectives: (1)\n            <jats:italic>Model Discrimination (Optimization-Based Trigger)<\/jats:italic>\n            : we adopt a substitute detection model and find the trigger by minimizing the cross-entropy loss; (2)\n            <jats:italic>Data Distribution (Custom Trigger):<\/jats:italic>\n            we manipulate the uncommon facial attributes in the long-tailed distribution to generate poisoned samples without the supervision from detection models. Furthermore, to evaluate the detection models toward the latest AIGC, we utilize both the state-of-the-art StyleGAN and Stable Diffusion for trigger generation. Finally, these backdoor triggers introduce specific semantic features to the generated poisoned samples (e.g., skin textures and smile), which are more natural and robust. Extensive experiments show that our method is superior over existing pixel space backdoor attacks on three levels: (1)\n            <jats:italic>Attack Success Rate<\/jats:italic>\n            : achieving an attack success rate exceeding 99\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\%\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            , comparable to baseline methods, with less than 0.1\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\%\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            model accuracy drop and under 3\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\%\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            poisoning rate; (2)\n            <jats:italic>Backdoor Defense<\/jats:italic>\n            : showing superior robustness when faced with existing backdoor defenses (e.g., surpassing baseline methods by over 30\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(\\%\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            after a 15\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\({}^{\\circ}\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            rotation); (3)\n            <jats:italic>Human Inspection<\/jats:italic>\n            : being less human-eye-sensitive from a user study with 46 participants and a collection of 2,300 data points.\n          <\/jats:p>","DOI":"10.1145\/3677380","type":"journal-article","created":{"date-parts":[[2024,7,11]],"date-time":"2024-07-11T15:17:34Z","timestamp":1720711054000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Exploiting Backdoors of Face Synthesis Detection with Natural Triggers"],"prefix":"10.1145","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9526-3351","authenticated-orcid":false,"given":"Xiaoxuan","family":"Han","sequence":"first","affiliation":[{"name":"NLPR &amp; MAIS, Institute of Automation, Chinese Academy of Sciences, Beijing, China and School of Artificial Intelligence, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3403-376X","authenticated-orcid":false,"given":"Songlin","family":"Yang","sequence":"additional","affiliation":[{"name":"NLPR &amp; MAIS, Institute of Automation, Chinese Academy of Sciences, Beijing, China and School of Artificial Intelligence, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8598-0831","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"NLPR &amp; MAIS, Institute of Automation, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1019-3884","authenticated-orcid":false,"given":"Ziwen","family":"He","sequence":"additional","affiliation":[{"name":"Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2763-7832","authenticated-orcid":false,"given":"Jing","family":"Dong","sequence":"additional","affiliation":[{"name":"NLPR &amp; MAIS, Institute of Automation, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,25]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"1","volume-title":"Proceedings of the 2018 IEEE International Workshop on Information Forensics and Security (WIFS)","author":"Afchar Darius","year":"2018","unstructured":"Darius Afchar, Vincent Nozick, Junichi Yamagishi, and Isao Echizen. 2018. Mesonet: A Compact Facial Video Forgery Detection Network. In Proceedings of the 2018 IEEE International Workshop on Information Forensics and Security (WIFS). IEEE, 1\u20137."},{"key":"e_1_3_1_3_2","unstructured":"Sajjad Ayoubi. 2021. FaceLib: Used for Face Detection Facial Expression AgeGender Estimation and Recognition with PyTorch. Retrieved from https:\/\/github.com\/sajjjadayobi\/FaceLib"},{"key":"e_1_3_1_4_2","first-page":"2938","volume-title":"Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics (AISTATS \u201920)","volume":"108","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to Backdoor Federated Learning. In Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics (AISTATS \u201920), Online, Vol. 108. PMLR, 2938\u20132948."},{"key":"e_1_3_1_5_2","first-page":"101","volume-title":"Proceedings of the 2019 IEEE International Conference on Image Processing (ICIP \u201919)","author":"Barni Mauro","year":"2019","unstructured":"Mauro Barni, Kassem Kallas, and Benedetta Tondi. 2019. A New Backdoor Attack in CNNS by Training Set Corruption without Label Poisoning. In Proceedings of the 2019 IEEE International Conference on Image Processing (ICIP \u201919). IEEE, 101\u2013105."},{"key":"e_1_3_1_6_2","first-page":"4113","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Cao Junyi","year":"2022","unstructured":"Junyi Cao, Chao Ma, Taiping Yao, Shen Chen, Shouhong Ding, and Xiaokang Yang. 2022. End-to-End Reconstruction-Classification Learning for Face Forgery Detection. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 4113\u20134122."},{"key":"e_1_3_1_7_2","unstructured":"Xiaoyu Cao and Neil Zhenqiang Gong. 2021. Understanding the Security of Deepfake Detection. CoRR abs\/2107.02045 (2021). arXiv: 2107.02045. Retrieved from https:\/\/arxiv.org\/abs\/2107.02045"},{"key":"e_1_3_1_8_2","first-page":"4658","volume-title":"Proceedings of the 28th International Joint Conference on Artificial Intelligence (IJCAI \u201919)","author":"Chen Huili","year":"2019","unstructured":"Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. 2019. DeepInspect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural Networks. In Proceedings of the 28th International Joint Conference on Artificial Intelligence (IJCAI \u201919), 4658\u20134664."},{"key":"e_1_3_1_9_2","unstructured":"Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. CoRR abs\/1712.05526 (2017). arXiv: 1712.05526. Retrieved from http:\/\/arxiv.org\/abs\/1712.05526"},{"key":"e_1_3_1_10_2","doi-asserted-by":"crossref","first-page":"1800","DOI":"10.1109\/CVPR.2017.195","volume-title":"Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201917)","author":"Chollet Fran\u00e7ois","year":"2017","unstructured":"Fran\u00e7ois Chollet. 2017. Xception: Deep Learning with Depthwise Separable Convolutions. In Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201917). IEEE Computer Society, 1800\u20131807."},{"key":"e_1_3_1_11_2","first-page":"5780","volume-title":"Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201920)","author":"Dang Hao","year":"2020","unstructured":"Hao Dang, Feng Liu, Joel Stehouwer, Xiaoming Liu, and Anil K. Jain. 2020. On the Detection of Digital Face Manipulation. In Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201920). Computer Vision Foundation \/ IEEE, 5780\u20135789."},{"key":"e_1_3_1_12_2","first-page":"11946","volume-title":"Proceedings of the 2021 IEEE\/CVF International Conference on Computer Vision (ICCV \u201921)","author":"Doan Khoa D.","year":"2021","unstructured":"Khoa D. Doan, Yingjie Lao, Weijie Zhao, and Ping Li. 2021. LIRA: Learnable, Imperceptible and Robust Backdoor Attacks. In Proceedings of the 2021 IEEE\/CVF International Conference on Computer Vision (ICCV \u201921). IEEE, 11946\u201311956."},{"key":"e_1_3_1_13_2","first-page":"7890","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Durall Ricard","year":"2020","unstructured":"Ricard Durall, Margret Keuper, and Janis Keuper. 2020. Watch Your Up-Convolution: CNN Based Generative Deep Neural Networks Are Failing To Reproduce Spectral Distributions. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 7890\u20137899."},{"key":"e_1_3_1_14_2","first-page":"1","volume-title":"Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN \u201920)","author":"Gandhi Apurva","year":"2020","unstructured":"Apurva Gandhi and Shomik Jain. 2020. Adversarial Perturbations Fool Deepfake Detectors. In Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN \u201920). IEEE, 1\u20138."},{"key":"e_1_3_1_15_2","first-page":"113","volume-title":"Proceedings of the 35th Annual Computer Security Applications Conference (ACSAC \u201919)","author":"Gao Yansong","year":"2019","unstructured":"Yansong Gao, Chang Xu, Derui Wang, Shiping Chen, Damith Chinthana Ranasinghe, and Surya Nepal. 2019. STRIP: A Defence against Trojan Attacks on Deep Neural Networks. In Proceedings of the 35th Annual Computer Security Applications Conference (ACSAC \u201919). ACM, 113\u2013125."},{"issue":"2","key":"e_1_3_1_16_2","first-page":"21","article-title":"Deepfake Video Detection via Predictive Representation Learning","volume":"18","author":"Ge Shiming","year":"2022","unstructured":"Shiming Ge, Fanzhao Lin, Chenyu Li, Daichi Zhang, Weiping Wang, and Dan Zeng. 2022. Deepfake Video Detection via Predictive Representation Learning. ACM Trans. Multimedia Comput. Commun. Appl. 18, 2s, Article 115 (Oct 2022), 21 pages.","journal-title":"ACM Trans. Multimedia Comput. Commun. Appl"},{"key":"e_1_3_1_17_2","first-page":"1220","volume-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)","author":"Golestaneh S. Alireza","year":"2022","unstructured":"S. Alireza Golestaneh, Saba Dadsetan, and Kris M. Kitani. 2022. No-Reference Image Quality Assessment via Transformers, Relative Ranking, and Self-Consistency. In Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV). 1220\u20131230."},{"key":"e_1_3_1_18_2","first-page":"2672","volume-title":"Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron C. Courville, and Yoshua Bengio. 2014. Generative Adversarial Nets. In Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems. 2672\u20132680."},{"key":"e_1_3_1_19_2","first-page":"1","volume-title":"Proceedings of the 2021 IEEE International Conference on Multimedia and Expo (ICME \u201921)","author":"Gragnaniello Diego","year":"2021","unstructured":"Diego Gragnaniello, Davide Cozzolino, Francesco Marra, Giovanni Poggi, and Luisa Verdoliva. 2021. Are GAN Generated Images Easy to Detect? A Critical Analysis of the State-Of-The-Art. In Proceedings of the 2021 IEEE International Conference on Multimedia and Expo (ICME \u201921). IEEE, 1\u20136."},{"key":"e_1_3_1_20_2","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"BadNets: Evaluating Backdooring Attacks on Deep Neural Networks","volume":"7","author":"Gu Tianyu","year":"2019","unstructured":"Tianyu Gu, Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2019. BadNets: Evaluating Backdooring Attacks on Deep Neural Networks. IEEE Access 7 (2019), 47230\u201347244.","journal-title":"IEEE Access"},{"key":"e_1_3_1_21_2","first-page":"770","volume-title":"Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201916)","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201916). IEEE Computer Society, 770\u2013778."},{"key":"e_1_3_1_22_2","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020 (NeurIPS \u201920)","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising Diffusion Probabilistic Models. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020 (NeurIPS \u201920), virtual. 6840\u20136851."},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","first-page":"3347","DOI":"10.1109\/WACV48630.2021.00339","volume-title":"Proceedings of the IEEE Winter Conference on Applications of Computer Vision (WACV \u201921)","author":"Hussain Shehzeen","year":"2021","unstructured":"Shehzeen Hussain, Paarth Neekhara, Malhar Jere, Farinaz Koushanfar, and Julian J. McAuley. 2021. Adversarial Deepfakes: Evaluating Vulnerability of Deepfake Detectors to Adversarial Examples. In Proceedings of the IEEE Winter Conference on Applications of Computer Vision (WACV \u201921). IEEE, 3347\u20133356."},{"key":"e_1_3_1_24_2","article-title":"Data Augmentation-based Novel Deep Learning Method for Deepfaked Images Detection","author":"Iqbal Farkhund","year":"2023","unstructured":"Farkhund Iqbal, Ahmed Abbasi, Abdul Rehman Javed, Ahmad Almadhor, Zunera Jalil, Sajid Anwar, and Imad Rida. 2023. Data Augmentation-based Novel Deep Learning Method for Deepfaked Images Detection. ACM Trans. Multimedia Comput. Commun. Appl. (2023). Just Accepted.","journal-title":"ACM Trans. Multimedia Comput. Commun. Appl"},{"key":"e_1_3_1_25_2","first-page":"4093","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201922)","author":"Jia Shuai","year":"2022","unstructured":"Shuai Jia, Chao Ma, Taiping Yao, Bangjie Yin, Shouhong Ding, and Xiaokang Yang. 2022. Exploring Frequency Adversarial Attacks for Face Forgery Detection. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201922). IEEE, 4093\u20134102."},{"key":"e_1_3_1_26_2","volume-title":"Proceedings of the 6th International Conference on Learning Representations (ICLR \u201918)","author":"Karras Tero","year":"2018","unstructured":"Tero Karras, Timo Aila, Samuli Laine, and Jaakko Lehtinen. 2018. Progressive Growing of GANs for Improved Quality, Stability, and Variation. In Proceedings of the 6th International Conference on Learning Representations (ICLR \u201918), OpenReview.net."},{"key":"e_1_3_1_27_2","first-page":"4401","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201919)","author":"Karras Tero","year":"2019","unstructured":"Tero Karras, Samuli Laine, and Timo Aila. 2019. A Style-Based Generator Architecture for Generative Adversarial Networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201919). Computer Vision Foundation \/ IEEE, 4401\u20134410."},{"key":"e_1_3_1_28_2","volume-title":"Proceedings of the 3rd International Conference on Learning Representations (ICLR \u201915)","author":"Kingma Diederik P.","year":"2015","unstructured":"Diederik P. Kingma and Jimmy Ba. 2015. Adam: A Method for Stochastic Optimization. In Proceedings of the 3rd International Conference on Learning Representations (ICLR \u201915)."},{"key":"e_1_3_1_29_2","first-page":"1","volume-title":"Proceedings of the International Joint Conference on Neural Networks (IJCNN \u201922)","author":"Kristanto Adrian","year":"2022","unstructured":"Adrian Kristanto, Shuo Wang, and Carsten Rudolph. 2022. Latent Space-Based Backdoor Attacks Against Deep Neural Networks. In Proceedings of the International Joint Conference on Neural Networks (IJCNN \u201922). IEEE, 1\u201310."},{"key":"e_1_3_1_30_2","first-page":"5789","volume-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201921)","author":"Li Dongze","year":"2021","unstructured":"Dongze Li, Wei Wang, Hongxing Fan, and Jing Dong. 2021c. Exploring Adversarial Fake Images on Face Manifold. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201921), virtual. Computer Vision Foundation \/ IEEE, 5789\u20135798."},{"key":"e_1_3_1_31_2","first-page":"16443","volume-title":"Proceedings of the 2021 IEEE\/CVF International Conference on Computer Vision (ICCV \u201921)","author":"Li Yuezun","year":"2021","unstructured":"Yuezun Li, Yiming Li, Baoyuan Wu, Longkang Li, Ran He, and Siwei Lyu. 2021a. Invisible Backdoor Attack with Sample-Specific Triggers. In Proceedings of the 2021 IEEE\/CVF International Conference on Computer Vision (ICCV \u201921). IEEE, 16443\u201316452."},{"key":"e_1_3_1_32_2","volume-title":"Proceedings of the 9th International Conference on Learning Representations (ICLR \u201921)","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021b. Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. In Proceedings of the 9th International Conference on Learning Representations (ICLR \u201921), Virtual Event. OpenReview.net."},{"key":"e_1_3_1_33_2","unstructured":"Yang Li Songlin Yang Wei Wang and Jing Dong. 2024. SeFi-IDE: Semantic-Fidelity Identity Embedding for Personalized Diffusion-Based Generation. arXiv: 2402.00631."},{"key":"e_1_3_1_34_2","unstructured":"Yiming Li Tongqing Zhai Baoyuan Wu Yong Jiang Zhifeng Li and Shutao Xia. 2020. Rethinking the Trigger of Backdoor Attack. CoRR abs\/2004.04692 (2020). arXiv: 2004.04692. Retrieved from https:\/\/arxiv.org\/abs\/2004.04692"},{"key":"e_1_3_1_35_2","first-page":"128","volume-title":"Proceedings of the European Conference on Computer Vision","author":"Liang Jiahao","year":"2022","unstructured":"Jiahao Liang, Huafeng Shi, and Weihong Deng. 2022. Exploring Disentangled Content Information for Face Forgery Detection. In Proceedings of the European Conference on Computer Vision. Springer, 128\u2013145."},{"key":"e_1_3_1_36_2","first-page":"113","volume-title":"Proceedings of the CCS \u201920: 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event","author":"Lin Junyu","year":"2020","unstructured":"Junyu Lin, Lei Xu, Yingqi Liu, and Xiangyu Zhang. 2020. Composite Backdoor Attack for Deep Neural Network by Mixing Existing Benign Features. In Proceedings of the CCS \u201920: 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event. ACM, 113\u2013131. DOI: 10.1145\/3372297.3423362"},{"key":"e_1_3_1_37_2","first-page":"772","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Liu Honggu","year":"2021","unstructured":"Honggu Liu, Xiaodan Li, Wenbo Zhou, Yuefeng Chen, Yuan He, Hui Xue, Weiming Zhang, and Nenghai Yu. 2021. Spatial-phase shallow learning: rethinking face forgery detection in frequency domain. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 772\u2013781."},{"key":"e_1_3_1_38_2","first-page":"273","volume-title":"Research in Attacks, Intrusions, and Defenses - 21st International Symposium (RAID \u201918), Proceedings, Lecture Notes in Computer Science, Vol. 11050","author":"Liu Kang","year":"2018","unstructured":"Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks. In Research in Attacks, Intrusions, and Defenses - 21st International Symposium (RAID \u201918), Proceedings, Lecture Notes in Computer Science, Vol. 11050, Springer, 273\u2013294."},{"key":"e_1_3_1_39_2","first-page":"182","volume-title":"Computer Vision - ECCV 2020 - 16th European Conference, Proceedings, Part X, Lecture Notes in Computer Science","volume":"12355","author":"Liu Yunfei","year":"2020","unstructured":"Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu. 2020. Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks. In Computer Vision - ECCV 2020 - 16th European Conference, Proceedings, Part X, Lecture Notes in Computer Science, Vol. 12355, Springer, 182\u2013199."},{"key":"e_1_3_1_40_2","first-page":"3730","volume-title":"Proceedings of International Conference on Computer Vision (ICCV)","author":"Liu Ziwei","year":"2015","unstructured":"Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. 2015. Deep Learning Face Attributes in the Wild. In Proceedings of International Conference on Computer Vision (ICCV). 3730\u20133738."},{"key":"e_1_3_1_41_2","first-page":"16317","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Luo Yuchen","year":"2021","unstructured":"Yuchen Luo, Yong Zhang, Junchi Yan, and Wei Liu. 2021. Generalizing Face Forgery Detection with High-Frequency Features. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 16317\u201316326."},{"key":"e_1_3_1_42_2","first-page":"122","volume-title":"Computer Vision - ECCV 2018 - 15th European Conference, Proceedings, Part XIV, Lecture Notes in Computer Science","volume":"11218","author":"Ma Ningning","year":"2018","unstructured":"Ningning Ma, Xiangyu Zhang, Hai-Tao Zheng, and Jian Sun. 2018. ShuffleNet V2: Practical Guidelines for Efficient CNN Architecture Design. In Computer Vision - ECCV 2018 - 15th European Conference, Proceedings, Part XIV, Lecture Notes in Computer Science, Vol. 11218, Springer, 122\u2013138."},{"key":"e_1_3_1_43_2","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1109\/CVPR.2017.17","volume-title":"2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201917)","author":"Moosavi-Dezfooli Seyed-Mohsen","year":"2017","unstructured":"Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal Adversarial Perturbations. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201917). IEEE Computer Society, 86\u201394."},{"key":"e_1_3_1_44_2","doi-asserted-by":"crossref","first-page":"2574","DOI":"10.1109\/CVPR.2016.282","volume-title":"2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201916)","author":"Moosavi-Dezfooli Seyed-Mohsen","year":"2016","unstructured":"Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016. DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR \u201916). IEEE Computer Society, 2574\u20132582."},{"key":"e_1_3_1_45_2","first-page":"923","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition Workshops, CVPR Workshops 2021, virtual","author":"Neekhara Paarth","year":"2021","unstructured":"Paarth Neekhara, Brian Dolhansky, Joanna Bitton, and Cristian Canton-Ferrer. 2021. Adversarial Threats to DeepFake Detection: A Practical Perspective. In IEEE Conference on Computer Vision and Pattern Recognition Workshops, CVPR Workshops 2021, virtual. Computer Vision Foundation \/ IEEE, 923\u2013932."},{"key":"e_1_3_1_46_2","first-page":"1","volume-title":"2019 IEEE 10th International Conference on Biometrics Theory, Applications and Systems (BTAS)","author":"Nguyen Huy H","year":"2019","unstructured":"Huy H Nguyen, Fuming Fang, Junichi Yamagishi, and Isao Echizen. 2019a. Multi-task learning for detecting and segmenting manipulated facial images and videos. In 2019 IEEE 10th International Conference on Biometrics Theory, Applications and Systems (BTAS). IEEE, 1\u20138."},{"key":"e_1_3_1_47_2","doi-asserted-by":"crossref","first-page":"2307","DOI":"10.1109\/ICASSP.2019.8682602","volume-title":"ICASSP 2019\u20132019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Nguyen Huy H.","year":"2019","unstructured":"Huy H. Nguyen, Junichi Yamagishi, and Isao Echizen. 2019b. Capsule-Forensics: Using Capsule Networks to Detect Forged Images and Videos. In ICASSP 2019\u20132019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 2307\u20132311."},{"key":"e_1_3_1_48_2","first-page":"3454","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020 (NeurIPS \u201920)","author":"Nguyen Tuan Anh","year":"2020","unstructured":"Tuan Anh Nguyen and Anh Tuan Tran. 2020. Input-Aware Dynamic Backdoor Attack. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020 (NeurIPS \u201920), virtual. 3454\u20133464."},{"key":"e_1_3_1_49_2","volume-title":"9th International Conference on Learning Representations (ICLR \u201921), Virtual Event","author":"Nguyen Tuan Anh","year":"2021","unstructured":"Tuan Anh Nguyen and Anh Tuan Tran. 2021. WaNet - Imperceptible Warping-based Backdoor Attack. In 9th International Conference on Learning Representations (ICLR \u201921), Virtual Event. OpenReview.net."},{"key":"e_1_3_1_50_2","first-page":"1","volume-title":"11th International Workshop on Biometrics and Forensics (IWBF \u201923)","author":"Papa Lorenzo","year":"2023","unstructured":"Lorenzo Papa, Lorenzo Faiella, Luca Corvitto, Luca Maiano, and Irene Amerini. 2023. On the Use of Stable Diffusion for Creating Realistic Faces: From Generation to Detection. In 11th International Workshop on Biometrics and Forensics (IWBF \u201923). IEEE, 1\u20136."},{"key":"e_1_3_1_51_2","doi-asserted-by":"crossref","first-page":"1828","DOI":"10.1145\/3503161.3547972","volume-title":"MM \u201922: The 30th ACM International Conference on Multimedia","author":"Parihar Rishubh","year":"2022","unstructured":"Rishubh Parihar, Ankit Dhiman, Tejan Karmali, and Venkatesh R. 2022. Everything Is There in Latent Space: Attribute Editing and Attribute Style Manipulation by StyleGAN Latent Space Exploration. In MM \u201922: The 30th ACM International Conference on Multimedia. ACM, 1828\u20131836."},{"issue":"6","key":"e_1_3_1_52_2","doi-asserted-by":"crossref","first-page":"3673","DOI":"10.1109\/TCSVT.2021.3106047","article-title":"A Unified Framework for High Fidelity Face Swap and Expression Reenactment","volume":"32","author":"Peng Bo","year":"2021","unstructured":"Bo Peng, Hongxing Fan, Wei Wang, Jing Dong, and Siwei Lyu. 2021. A Unified Framework for High Fidelity Face Swap and Expression Reenactment. IEEE Transactions on Circuits and Systems for Video Technology 32, 6 (2021), 3673\u20133684.","journal-title":"IEEE Transactions on Circuits and Systems for Video Technology"},{"key":"e_1_3_1_53_2","first-page":"86","volume-title":"European Conference on Computer Vision","author":"Qian Yuyang","year":"2020","unstructured":"Yuyang Qian, Guojun Yin, Lu Sheng, Zixuan Chen, and Jing Shao. 2020. Thinking in Frequency: Face Forgery Detection by Mining Frequency-Aware Clues. In European Conference on Computer Vision. Springer, 86\u2013103."},{"key":"e_1_3_1_54_2","first-page":"10674","volume-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201922)","author":"Rombach Robin","year":"2022","unstructured":"Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Bj\u00f6rn Ommer. 2022. High-Resolution Image Synthesis with Latent Diffusion Models. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201922). IEEE, 10674\u201310685."},{"key":"e_1_3_1_55_2","first-page":"1","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"Rossler Andreas","year":"2019","unstructured":"Andreas Rossler, Davide Cozzolino, Luisa Verdoliva, Christian Riess, Justus Thies, and Matthias Nie\u00c3\u0178ner. 2019. Faceforensics++: Learning to Detect Manipulated Facial Images. In Proceedings of the IEEE\/CVF International Conference on Computer Vision. 1\u201311."},{"key":"e_1_3_1_56_2","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1016\/0167-2789(92)90242-F","article-title":"Nonlinear Total Variation Based Noise Removal Algorithms","volume":"60","author":"Rudin Leonid I.","year":"1992","unstructured":"Leonid I. Rudin, S. Osher, and Emad Fatemi. 1992. Nonlinear Total Variation Based Noise Removal Algorithms. Physica D: Nonlinear Phenomena 60 (1992), 259\u2013268.","journal-title":"Physica D: Nonlinear Phenomena"},{"key":"e_1_3_1_57_2","first-page":"703","volume-title":"7th IEEE European Symposium on Security and Privacy, EuroS & P 2022","author":"Salem Ahmed","year":"2022","unstructured":"Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang. 2022. Dynamic Backdoor Attacks Against Machine Learning Models. In 7th IEEE European Symposium on Security and Privacy, EuroS & P 2022. IEEE, 703\u2013718."},{"issue":"3","key":"e_1_3_1_58_2","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1109\/TBIOM.2021.3132132","article-title":"FaceHack: Attacking Facial Recognition Systems Using Malicious Facial Characteristics","volume":"4","author":"Sarkar Esha","year":"2022","unstructured":"Esha Sarkar, Hadjer Benkraouda, Gopika Krishnan, Homer Gamil, and Michail Maniatakos. 2022. FaceHack: Attacking Facial Recognition Systems Using Malicious Facial Characteristics. IEEE Trans. Biom. Behav. Identity Sci. 4, 3 (2022), 361\u2013372.","journal-title":"IEEE Trans. Biom. Behav. Identity Sci"},{"key":"e_1_3_1_59_2","doi-asserted-by":"crossref","first-page":"336","DOI":"10.1007\/s11263-019-01228-7","article-title":"Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization","volume":"128","author":"Selvaraju Ramprasaath R.","year":"2016","unstructured":"Ramprasaath R. Selvaraju, Abhishek Das, Ramakrishna Vedantam, Michael Cogswell, Devi Parikh, and Dhruv Batra. 2016. Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization. International Journal of Computer Vision 128 (2016), 336\u2013359.","journal-title":"International Journal of Computer Vision"},{"key":"e_1_3_1_60_2","doi-asserted-by":"crossref","first-page":"9240","DOI":"10.1109\/CVPR42600.2020.00926","volume-title":"2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201920)","author":"Shen Yujun","year":"2020","unstructured":"Yujun Shen, Jinjin Gu, Xiaoou Tang, and Bolei Zhou. 2020. Interpreting the Latent Space of GANs for Semantic Face Editing. In 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201920). Computer Vision Foundation \/ IEEE, 9240\u20139249."},{"key":"e_1_3_1_61_2","volume-title":"3rd International Conference on Learning Representations (ICLR \u201915), Conference Track Proceedings","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In 3rd International Conference on Learning Representations (ICLR \u201915), Conference Track Proceedings."},{"key":"e_1_3_1_62_2","first-page":"6105","volume-title":"Proceedings of the 36th International Conference on Machine Learning (ICML \u201919), Proceedings of Machine Learning Research","volume":"97","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc V. Le. 2019. EfficientNet: Rethinking Model Scaling for Convolutional Neural Networks. In Proceedings of the 36th International Conference on Machine Learning (ICML \u201919), Proceedings of Machine Learning Research, Vol. 97. PMLR, 6105\u20136114."},{"key":"e_1_3_1_63_2","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1016\/j.inffus.2020.06.014","article-title":"Deepfakes and Beyond: A Survey of Face Manipulation and Fake Detection","volume":"64","author":"Tolosana Ruben","year":"2020","unstructured":"Ruben Tolosana, Ruben Vera-Rodriguez, Julian Fierrez, Aythami Morales, and Javier Ortega-Garcia. 2020. Deepfakes and Beyond: A Survey of Face Manipulation and Fake Detection. Information Fusion 64 (2020), 131\u2013148.","journal-title":"Information Fusion"},{"key":"e_1_3_1_64_2","doi-asserted-by":"crossref","first-page":"707","DOI":"10.1109\/SP.2019.00031","volume-title":"2019 IEEE Symposium on Security and Privacy (SP \u201919)","author":"Wang Bolun","year":"2019","unstructured":"Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2019. Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. In 2019 IEEE Symposium on Security and Privacy (SP \u201919). IEEE, 707\u2013723."},{"key":"e_1_3_1_65_2","first-page":"14923","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Wang Chengrui","year":"2021","unstructured":"Chengrui Wang and Weihong Deng. 2021. Representative forgery mining for fake face detection. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 14923\u201314932."},{"key":"e_1_3_1_66_2","doi-asserted-by":"crossref","first-page":"8692","DOI":"10.1109\/CVPR42600.2020.00872","volume-title":"2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201920)","author":"Wang Sheng-Yu","year":"2020","unstructured":"Sheng-Yu Wang, Oliver Wang, Richard Zhang, Andrew Owens, and Alexei A. Efros. 2020. CNN-Generated Images Are Surprisingly Easy to Spot\u2026 for Now. In 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201920). Computer Vision Foundation\/IEEE, 8692\u20138701."},{"issue":"6","key":"e_1_3_1_67_2","first-page":"20","article-title":"Deep Convolutional Pooling Transformer for Deepfake Detection","volume":"19","author":"Wang Tianyi","year":"2023","unstructured":"Tianyi Wang, Harry Cheng, Kam Pui Chow, and Liqiang Nie. 2023. Deep Convolutional Pooling Transformer for Deepfake Detection. ACM Trans. Multimedia Comput. Commun. Appl. 19, 6, Article 179 (May 2023), 20 pages.","journal-title":"ACM Trans. Multimedia Comput. Commun. Appl"},{"key":"e_1_3_1_68_2","volume-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201923)","author":"Wu Qiucheng","year":"2023","unstructured":"Qiucheng Wu, Yujian Liu, Handong Zhao, Ajinkya Kale, Trung Bui, Tong Yu, Zhe Lin, Yang Zhang, and Shiyu Chang. 2023. Uncovering the Disentanglement Capability in Text-to-Image Diffusion Models. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR \u201923). IEEE, 1900\u20131910."},{"key":"e_1_3_1_69_2","first-page":"6522","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"38","author":"Yang Songlin","year":"2024","unstructured":"Songlin Yang, Wei Wang, Yushi Lan, Xiangyu Fan, Bo Peng, Lei Yang, and Jing Dong. 2024. Learning Dense Correspondence for Nnerf-Based Face Reenactment. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 6522\u20136530."},{"key":"e_1_3_1_70_2","doi-asserted-by":"crossref","first-page":"7718","DOI":"10.1145\/3581783.3611765","volume-title":"Proceedings of the 31st ACM International Conference on Multimedia","author":"Yang Songlin","year":"2023","unstructured":"Songlin Yang, Wei Wang, Jun Ling, Bo Peng, Xu Tan, and Jing Dong. 2023a. Context-Aware Talking-Head Video Editing. In Proceedings of the 31st ACM International Conference on Multimedia. 7718\u20137727."},{"key":"e_1_3_1_71_2","first-page":"1","volume-title":"ICASSP 2023\u20132023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Yang Songlin","year":"2023","unstructured":"Songlin Yang, Wei Wang, Bo Peng, and Jing Dong. 2023b. Designing A 3d-Aware Stylenerf Encoder for Face Editing. In ICASSP 2023\u20132023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 1\u20135."},{"key":"e_1_3_1_72_2","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Ying Zhenqiang","year":"2020","unstructured":"Zhenqiang Ying, Haoran Niu, Praful Gupta, Dhruv Mahajan, Deepti Ghadiyaram, and Alan Bovik. 2020. From Patches to Pictures (PaQ-2-PiQ): Mapping the Perceptual Space of Picture Quality. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)."},{"issue":"4","key":"e_1_3_1_73_2","first-page":"23","article-title":"Detection of AI-Manipulated Fake Faces via Mining Generalized Features","volume":"18","author":"Yu Yang","year":"2022","unstructured":"Yang Yu, Rongrong Ni, Wenjie Li, and Yao Zhao. 2022. Detection of AI-Manipulated Fake Faces via Mining Generalized Features. ACM Trans. Multimedia Comput. Commun. Appl. 18, 4, Article 94 (Mar 2022), 23 pages.","journal-title":"ACM Trans. Multimedia Comput. Commun. Appl"},{"key":"e_1_3_1_74_2","doi-asserted-by":"crossref","first-page":"1499","DOI":"10.1109\/LSP.2016.2603342","article-title":"Joint Face Detection and Alignment Using Multitask Cascaded Convolutional Networks","volume":"23","author":"Zhang Kaipeng","year":"2016","unstructured":"Kaipeng Zhang, Zhanpeng Zhang, Zhifeng Li, and Yu Qiao. 2016. Joint Face Detection and Alignment Using Multitask Cascaded Convolutional Networks. IEEE Signal Processing Letters 23 (2016), 1499\u20131503.","journal-title":"IEEE Signal Processing Letters"},{"key":"e_1_3_1_75_2","article-title":"Backdoor Two-Stream Video Models on Federated Learning","author":"Zhao Jing","year":"2024","unstructured":"Jing Zhao, Hongwei Yang, Hui He, Jie Peng, Weizhe Zhang, Jiangqun Ni, Arun Kumar Sangaiah, and Aniello Castiglione. 2024. Backdoor Two-Stream Video Models on Federated Learning. ACM Trans. Multimedia Comput. Commun. Appl. (Mar 2024). Just Accepted.","journal-title":"ACM Trans. Multimedia Comput. Commun. Appl"},{"key":"e_1_3_1_76_2","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1145\/3374664.3375751","volume-title":"CODASPY \u201920: Tenth ACM Conference on Data and Application Security and Privacy","author":"Zhong Haoti","year":"2020","unstructured":"Haoti Zhong, Cong Liao, Anna Cinzia Squicciarini, Sencun Zhu, and David J. Miller. 2020. Backdoor Embedding in Convolutional Neural Network Models via Invisible Perturbation. In CODASPY \u201920: Tenth ACM Conference on Data and Application Security and Privacy. ACM, 97\u2013108."},{"key":"e_1_3_1_77_2","unstructured":"zllrunning. 2019. face-parsing.PyTorch. Using modified BiSeNet for face parsing in PyTorch. Retrieved from https:\/\/github.com\/zllrunning\/face-parsing.PyTorch"}],"container-title":["ACM Transactions on Multimedia Computing, Communications, and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3677380","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3677380","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:04:22Z","timestamp":1750291462000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3677380"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,25]]},"references-count":76,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,2,28]]}},"alternative-id":["10.1145\/3677380"],"URL":"https:\/\/doi.org\/10.1145\/3677380","relation":{},"ISSN":["1551-6857","1551-6865"],"issn-type":[{"value":"1551-6857","type":"print"},{"value":"1551-6865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,25]]},"assertion":[{"value":"2023-12-31","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-07-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-25","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}