{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T02:51:54Z","timestamp":1781059914333,"version":"3.54.1"},"reference-count":71,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T00:00:00Z","timestamp":1733702400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2024,12,31]]},"abstract":"<jats:p>\n            With the significant advances in deep generative models for image and video synthesis, Deepfakes and manipulated media have raised severe societal concerns. Conventional machine learning classifiers for deepfake detection often fail to cope with evolving deepfake generation technology and are susceptible to adversarial attacks. Alternatively, invisible image watermarking is being researched as a proactive defense technique that allows media authentication by verifying an invisible secret message embedded in the image pixels. A handful of invisible image watermarking techniques introduced for media authentication have proven vulnerable to basic image processing operations and watermark removal attacks. In response, we have proposed a semi-fragile image watermarking technique that embeds an invisible secret message into real images for media authentication. Our proposed watermarking framework is designed to be fragile to facial manipulations or tampering while being robust to benign image-processing operations and watermark removal attacks. This is facilitated through a unique architecture of our proposed technique consisting of critic and adversarial networks that enforce high image quality and resiliency to watermark removal efforts, respectively, along with the backbone encoder-decoder and the discriminator networks. This allows images shared over the Internet to retain the verifiable watermark as long as facial manipulations or any other Deepfake modification technique is not applied. Thorough experimental investigations on SOTA facial Deepfake datasets demonstrate that our proposed model can embed a\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\(64\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            -bit secret as an imperceptible image watermark that can be recovered with a high-bit recovery accuracy when benign image processing operations are applied while being non-recoverable when unseen Deepfake manipulations are applied. In addition, our proposed watermarking technique demonstrates high resilience to several white-box and black-box watermark removal attacks. Thus, obtaining state-of-the-art performance.\n          <\/jats:p>","DOI":"10.1145\/3700146","type":"journal-article","created":{"date-parts":[[2024,10,12]],"date-time":"2024-10-12T10:05:41Z","timestamp":1728727541000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Social Media Authentication and Combating Deepfakes Using Semi-Fragile Invisible Image Watermarking"],"prefix":"10.1145","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7254-3207","authenticated-orcid":false,"given":"Aakash Varma","family":"Nadimpalli","sequence":"first","affiliation":[{"name":"Wichita State University, Wichita, KS, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1541-8202","authenticated-orcid":false,"given":"Ajita","family":"Rattani","sequence":"additional","affiliation":[{"name":"University of North Texas, Denton, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_2_2","volume-title":"Proceedings of the CVPR Workshops","author":"Agarwal Shruti","year":"2019","unstructured":"Shruti Agarwal, Hany Farid, Yuming Gu, Mingming He, Koki Nagano, and Hao Li. 2019. Protecting world leaders against deep fakes. In Proceedings of the CVPR Workshops."},{"key":"e_1_3_2_3_2","unstructured":"Akiomik. 2024. GitHub - akiomik\/pilgram: A python library for instagram filters. Retrieved from https:\/\/github.com\/akiomik\/pilgram"},{"key":"e_1_3_2_4_2","first-page":"274","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the International Conference on Machine Learning. PMLR, 274\u2013283."},{"key":"e_1_3_2_5_2","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","volume":"30","author":"Baluja Shumeet","year":"2017","unstructured":"Shumeet Baluja. 2017. Hiding images in plain sight: Deep steganography. In Proceedings of the 31st International Conference on Neural Information Processing Systems. I. Guyon, U. Von Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30. Curran Associates, Inc. Retrieved from https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/838e8afb1ca34354ac209f53d90c3a43-Paper.pdf"},{"key":"e_1_3_2_6_2","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1007\/978-3-031-24628-9_16","volume-title":"Machine Learning for Data Science Handbook: Data Mining and Knowledge Discovery Handbook","author":"Bank Dor","year":"2023","unstructured":"Dor Bank, Noam Koenigstein, and Raja Giryes. 2023. Autoencoders. In Machine Learning for Data Science Handbook: Data Mining and Knowledge Discovery Handbook. Lior Rokach, Oded Maimon, Erez Shmueli (Eds.), Springer, Cham, 353\u2013374."},{"key":"e_1_3_2_7_2","first-page":"2078","article-title":"Digital image watermarking techniques: A review","volume":"2","author":"Begum Mahbuba","year":"2020","unstructured":"Mahbuba Begum and Mohammad Shorif Uddin. 2020. Digital image watermarking techniques: A review. Information 2 (2020). 2078\u20132489","journal-title":"Information"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11071-014-1777-3"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-020-02135-3"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2007.901206"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_12_2","first-page":"5932","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV)","author":"Chan Caroline","year":"2018","unstructured":"Caroline Chan, Shiry Ginosar, Tinghui Zhou, and Alexei A. Efros. 2018. Everybody dance now. Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), 5932\u20135941."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.04.014"},{"key":"e_1_3_2_14_2","first-page":"8789","volume-title":"Proceedings of the IEEE CVPR","author":"Choi Yunjey","year":"2017","unstructured":"Yunjey Choi, Min-Je Choi, Mun Su Kim, Jung-Woo Ha, Sunghun Kim, and Jaegul Choo. 2017. StarGAN: Unified generative adversarial networks for multi-domain image-to-image translation. In Proceedings of the IEEE CVPR, 8789\u20138797."},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.195"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/83.650120"},{"key":"e_1_3_2_17_2","unstructured":"Brian Dolhansky Joanna Bitton Ben Pflaum Jikuo Lu Russ Howes Menglin Wang and Cristian Canton Ferrer. 2020. The DeepFake Detection Challenge (DFDC) dataset. arXiv:2006.07397."},{"key":"e_1_3_2_18_2","unstructured":"Xiaoyi Dong Jianmin Bao Dongdong Chen Weiming Zhang Nenghai Yu Dong Chen Fang Wen and Baining Guo. 2020. Identity-driven deepfake detection. arXiv:2012.03930."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781139192903"},{"key":"e_1_3_2_20_2","volume-title":"Proceedings of the 27th International Conference on Neural Information Processing Systems","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In Proceedings of the 27th International Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_21_2","unstructured":"Ian J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572."},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00500"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.5555\/3294771.3294957"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2916751"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ITCC.2004.1286417"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.5555\/3495724.3496298"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.632"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.5555\/1577069.1755843"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-014-2188-7"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00505"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS.2018.8630787"},{"key":"e_1_3_2_33_2","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Workshops","author":"Li Yuezun","year":"2019","unstructured":"Yuezun Li and Siwei Lyu. 2019. Exposing deepfake videos by detecting face warping artifacts. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Workshops."},{"key":"e_1_3_2_34_2","unstructured":"Eugene T. Lin Christine Podilchuk and Edward J. Delp. 2000. Detection of image alterations using semifragile watermarks. In Electronic Imaging. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:2686286"},{"key":"e_1_3_2_35_2","volume-title":"Proceedings of the International Conference on Computer Vision (ICCV)","author":"Liu Ziwei","year":"2015","unstructured":"Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. 2015. Deep learning face attributes in the wild. In Proceedings of the International Conference on Computer Vision (ICCV)."},{"key":"e_1_3_2_36_2","first-page":"13548","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Luo Xiyang","year":"2020","unstructured":"Xiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang, and Peyman Milanfar. 2020. Distortion agnostic deep watermarking. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 13548\u201313557."},{"key":"e_1_3_2_37_2","doi-asserted-by":"crossref","unstructured":"Ferdinando Di Martino and Salvatore Sessa. 2012. Fragile watermarking tamper detection with images compressed by fuzzy transform. Information Sciences 195 (2012) 62\u201390. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:35069151","DOI":"10.1016\/j.ins.2012.01.014"},{"key":"e_1_3_2_38_2","first-page":"320","volume-title":"Proceedings of the International Conference on Pattern Recognition","author":"Nadimpalli Aakash Varma","year":"2022","unstructured":"Aakash Varma Nadimpalli and Ajita Rattani. 2022. GBDF: Gender balanced deepfake dataset towards fair deepfake detection. In Proceedings of the International Conference on Pattern Recognition. Springer, 320\u2013337."},{"key":"e_1_3_2_39_2","first-page":"91","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Nadimpalli Aakash Varma","year":"2022","unstructured":"Aakash Varma Nadimpalli and Ajita Rattani. 2022. On improving cross-dataset generalization of deepfake detectors. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 91\u201399."},{"key":"e_1_3_2_40_2","first-page":"2174","volume-title":"Proceedings of the International Conference on Machine Learning and Applications (ICMLA)","author":"Nadimpalli Aakash Varma","year":"2023","unstructured":"Aakash Varma Nadimpalli and Ajita Rattani. 2023. Facial forgery-based deepfake detection using fine-grained features. In Proceedings of the International Conference on Machine Learning and Applications (ICMLA), 2174\u20132181."},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3625547"},{"key":"e_1_3_2_42_2","unstructured":"Paarth Neekhara Shehzeen Hussain Xinqiao Zhang Ke Huang Julian McAuley and Farinaz Koushanfar. 2022. FaceSigns: Semi-fragile neural watermarks for media authentication and countering deepfakes. arXiv:2204.01960."},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2022.103525"},{"key":"e_1_3_2_44_2","first-page":"7183","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV)","author":"Nirkin Yuval","year":"2019","unstructured":"Yuval Nirkin, Yosi Keller, and Tal Hassner. 2019. FSGAN: Subject agnostic face swapping and reenactment. In Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), 7183\u20137192."},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","unstructured":"Augustus Odena Vincent Dumoulin and Chris Olah. 2016. Deconvolution and Checkerboard Artifacts. Distill. Retrieved from http:\/\/distill.pub\/2016\/deconv-checkerboard\/","DOI":"10.23915\/distill.00003"},{"key":"e_1_3_2_46_2","first-page":"1","volume-title":"Proceedings of the IEEE International Joint Conference on Biometrics (IJCB)","author":"Peng Bo","year":"2022","unstructured":"Bo Peng, Wei Xiang, Yue Jiang, Wei Wang, Jing Dong, Zhen Sun, Zhen Lei, and Siwei Lyu. 2022. DFGC 2022: The second DeepFake game competition. In Proceedings of the IEEE International Joint Conference on Biometrics (IJCB), 1\u201310."},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","unstructured":"Shelby Pereira and Thierry Pun. 2000. Robust template matching for affine resistant image watermarks. IEEE Transactions on Image Processing: A Publication of the IEEE Signal Processing Society 96 (2000) 1123\u20139. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:1556380","DOI":"10.1109\/83.846253"},{"key":"e_1_3_2_48_2","volume-title":"Proceedings of the 12th International Conference on Learning Representations","author":"Podell Dustin","year":"2024","unstructured":"Dustin Podell, Zion English, Kyle Lacey, Andreas Blattmann, Tim Dockhorn, Jonas M\u00fcller, Joe Penna, and Robin Rombach. 2024. SDXL: Improving latent diffusion models for high-resolution image synthesis. In Proceedings of the 12th International Conference on Learning Representations. Retrieved from https:\/\/openreview.net\/forum?id=di52zR8xgf"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58610-2_6"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCST49569.2021.9717407"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2015.41"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00009"},{"key":"e_1_3_2_53_2","first-page":"265","volume-title":"Applied Cryptography: Protocols, Algorithms, and Source Code in C","author":"Schneier Bruce","year":"1996","unstructured":"Bruce Schneier. 1996. Applied Cryptography: Protocols, Algorithms, and Source Code in C (2nd ed.). John Wiley & Sons, Inc., New York, NY. 265\u2013279.","edition":"2"},{"key":"e_1_3_2_54_2","unstructured":"Richard Shin. 2017. JPEG-Resistant Adversarial Images. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:204804905"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICOSP.2002.1180102"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_2_57_2","first-page":"2117","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Tancik Matthew","year":"2020","unstructured":"Matthew Tancik, Ben Mildenhall, and Ren Ng. 2020. Stegastamp: Invisible hyperlinks in physical photographs. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2117\u20132126."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/3306346.3323035"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/2929464.2929475"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2020.06.014"},{"key":"e_1_3_2_61_2","volume-title":"Proceedings of the International Joint Conference on Artificial Intelligence","author":"Trinh Loc","year":"2021","unstructured":"Loc Trinh and Y. Liu. 2021. An examination of fairness of AI models for deepfake detection. In Proceedings of the International Joint Conference on Artificial Intelligence. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:233481637"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/107"},{"key":"e_1_3_2_63_2","first-page":"14920","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Wang Xueyu","year":"2022","unstructured":"Xueyu Wang, Jiajun Huang, Siqi Ma, Surya Nepal, and Chang Xu. 2022b. DeepFake disrupter: The detector of deepfake is my friend. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 14920\u201314929."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.22215\/timreview\/1282"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSSE.2008.331"},{"key":"e_1_3_2_66_2","unstructured":"Nadirah Zaidi. 2023. As Singapore Faces Deepfake Surge Authorities Warn of Threats from Cybercrime Online Scams. Retrieved from https:\/\/www.channelnewsasia.com\/singapore\/combating-risks-ai-and-deepfakes-experts-cybercrime-3966226"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2603342"},{"key":"e_1_3_2_68_2","first-page":"2185","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Zhao Hanqing","year":"2021","unstructured":"Hanqing Zhao, Tianyi Wei, Wenbo Zhou, Weiming Zhang, Dongdong Chen, and Nenghai Yu. 2021. Multi-attentional deepfake detection. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2185\u20132194."},{"key":"e_1_3_2_69_2","unstructured":"Xuandong Zhao Kexun Zhang Yu-Xiang Wang and Lei Li. 2023. Generative autoencoders as watermark attackers: Analyses of vulnerabilities and threats. arXiv:2306.01953."},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.127593"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_40"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_40"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3700146","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3700146","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:09:49Z","timestamp":1750295389000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3700146"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,9]]},"references-count":71,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,12,31]]}},"alternative-id":["10.1145\/3700146"],"URL":"https:\/\/doi.org\/10.1145\/3700146","relation":{},"ISSN":["2576-5337"],"issn-type":[{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,9]]},"assertion":[{"value":"2024-05-21","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-21","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}