{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T03:58:42Z","timestamp":1784001522721,"version":"3.55.0"},"reference-count":36,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2021,11,17]],"date-time":"2021-11-17T00:00:00Z","timestamp":1637107200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Many deepfake-image forensic detectors have been proposed and improved due to the development of synthetic techniques. However, recent studies show that most of these detectors are not immune to adversarial example attacks. Therefore, understanding the impact of adversarial examples on their performance is an important step towards improving deepfake-image detectors. This study developed an anti-forensics case study of two popular general deepfake detectors based on their accuracy and generalization. Herein, we propose the Poisson noise DeepFool (PNDF), an improved iterative adversarial examples generation method. This method can simply and effectively attack forensics detectors by adding perturbations to images in different directions. Our attacks can reduce its AUC from 0.9999 to 0.0331, and the detection accuracy of deepfake images from 0.9997 to 0.0731. Compared with state-of-the-art studies, our work provides an important defense direction for future research on deepfake-image detectors, by focusing on the generalization performance of detectors and their resistance to adversarial example attacks.<\/jats:p>","DOI":"10.3390\/fi13110288","type":"journal-article","created":{"date-parts":[[2021,11,17]],"date-time":"2021-11-17T09:16:11Z","timestamp":1637140571000},"page":"288","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Deepfake-Image Anti-Forensics with Adversarial Examples Attacks"],"prefix":"10.3390","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2647-9019","authenticated-orcid":false,"given":"Li","family":"Fan","sequence":"first","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan 430040, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3135-0447","authenticated-orcid":false,"given":"Wei","family":"Li","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence and Computer Science, Jiangnan University, Wuxi 214000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6079-009X","authenticated-orcid":false,"given":"Xiaohui","family":"Cui","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan 430040, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,11,17]]},"reference":[{"key":"ref_1","unstructured":"(2021, October 12). DeepFakes Faceswap Github Repository. Available online: https:\/\/github.com\/DeepFakes\/faceswap."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Karras, T., Laine, S., and Aila, T. (2019, January 15\u201320). A style-based generator architecture for generative adversarial networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref_3","unstructured":"Mirsky, Y., and Lee, W. (2021, October 12). The Creation and Detection of Deepfakes: A Survey. arXiv, Available online: https:\/\/arxiv.org\/abs\/2004.11138."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1016\/j.inffus.2020.06.014","article-title":"Deepfakes and beyond: A Survey of face manipulation and fake detection","volume":"64","author":"Tolosana","year":"2020","journal-title":"Inf. Fusion."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"3007","DOI":"10.1109\/TPAMI.2018.2868350","article-title":"Representation Learning by Rotating Your Faces","volume":"41","author":"Tran","year":"2019","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_6","unstructured":"Schwartz, O. (2021, October 12). You Thought Fake News Was Bad? The Guardian. Available online: https:\/\/www.theguardian.com\/technology\/2018\/nov\/12\/deep-fakes-fake-news-truth."},{"key":"ref_7","unstructured":"Samuel, S. (2021, October 12). A Guy Made a Deepfake App to Turn Photos of Women into Nudes. It didnfit Go Well. Available online: https:\/\/www.vox.com\/2019\/6\/27\/18761639\/ai-deepfake-deepnude-app-nude-women-porn."},{"key":"ref_8","first-page":"2672","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow","year":"2014","journal-title":"Adv. Neural Inf. Proces. Syst."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Zhu, J., Park, T., Isola, P., and Efros, A.A. (2017, January 22\u201329). Unpaired Image-to-Image Translation Using Cycle-Consistent Adversarial Networks. Proceedings of the 2017 IEEE International Conference on Computer Vision (ICCV), Venice, Italy.","DOI":"10.1109\/ICCV.2017.244"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"532-1","DOI":"10.2352\/ISSN.2470-1173.2019.5.MWSF-532","article-title":"Detecting GAN generated Fake Images using Co-occurrence Matrices","volume":"2019","author":"Nataraj","year":"2019","journal-title":"Electron. Imaging"},{"key":"ref_11","unstructured":"Cozzolino, D., Thies, J., Rssler, A., and Riess, C. (2021, October 12). Forensic Transfer: Weakly-Supervised Domain Adaptation for Forgery Detection. Available online: https:\/\/arxiv.org\/abs\/1812.02510."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"165085","DOI":"10.1109\/ACCESS.2020.3023037","article-title":"Fighting Deepfake by Exposing the Convolutional Traces on Images","volume":"8","author":"Guarnera","year":"2020","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"e3","DOI":"10.23915\/distill.00003","article-title":"Deconvolution and Checkerboard Artifacts","volume":"1","author":"Odena","year":"2016","journal-title":"Distill"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Zhang, X., Karaman, S., and Chang, S.-F. (2019, January 9\u201312). Detecting and Simulating Artifacts in GAN Fake Images. Proceedings of the 2019 IEEE International Workshop on Information Forensics and Security (WIFS), Delft, The Netherlands.","DOI":"10.1109\/WIFS47025.2019.9035107"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Wang, S.-Y., Wang, O., Zhang, R., Owens, A., and Efros, A.A. (2020, January 13\u201319). CNN-Generated Images Are Surprisingly Easy to Spot\u2026 for Now. Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00872"},{"key":"ref_16","unstructured":"Szegedy, C., Zaremba, W., and Sutskever, I. (2014, January 14\u201316). Intriguing properties of neural networks. Proceedings of the International Conference on Learning Representations, Banff, AB, Canada."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Gandhi, A., and Jain, S. (2020, January 19\u201324). Adversarial Perturbations Fool Deepfake Detectors. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9207034"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Hussain, S., Neekhara, P., Jere, M., Koushanfar, F., and McAuley, J. (2021, January 3\u20138). Adversarial Deepfakes: Evaluating Vulnerability of Deepfake Detectors to Adversarial Examples. Proceedings of the 2021 IEEE Winter Conference on Applications of Computer Vision (WACV), Waikoloa, HI, USA.","DOI":"10.1109\/WACV48630.2021.00339"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"151103","DOI":"10.1109\/ACCESS.2019.2946461","article-title":"Generating Adversarial Examples in One Shot with Image-to-Image Translation GAN","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","article-title":"Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey","volume":"6","author":"Akhtar","year":"2018","journal-title":"IEEE Access"},{"key":"ref_21","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015, January 7\u20139). Explaining and Harnessing Adversarial Examples. Proceedings of the International Conference on Learning Representations, San Diego, CA, USA."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S., Fawzi, A., and Fawzi, O. (2017, January 21\u201326). Universal adversarial perturbations. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Farid, H. (2020, January 14\u201319). Evading Deepfake-Image Detectors with White- and Black-Box Attacks. Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), Seattle, WA, USA.","DOI":"10.1109\/CVPRW50498.2020.00337"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Marra, F., Gragnaniello, D., Cozzolino, D., and Verdoliva, L. (2018, January 10\u201312). Detection of GAN-Generated Fake Images Over Social Networks. Proceedings of the 2018 IEEE Conference on Multimedia Information Processing and Retrieval (MIPR), Miami, FL, USA.","DOI":"10.1109\/MIPR.2018.00084"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Yu, N., Davis, L., and Fritz, M. (November, January 27). Attributing Fake Images to GANs: Learning and Analyzing GAN Fingerprints. Proceedings of the 2019 IEEE\/CVF International Conference on Computer Vision (ICCV), Seoul, Korea.","DOI":"10.1109\/ICCV.2019.00765"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_27","unstructured":"Karras, T., Aila, T., and Laine, S. (2017, January 24\u201326). Progressive growing of gans for improved quality, stability, and variation. Proceedings of the International Conference on Learning Representations, Toulon, France."},{"key":"ref_28","unstructured":"Brock, A., Donahue, J., and Simonyan, K. (May, January 30). Large Scale GAN Training for High Fidelity Natural Image Synthesis. Proceedings of the International Conference on Learning Representations, Vancouver, Canada."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Park, T., Liu, M.-Y., Wang, T.-C., and Zhu, J.-Y. (2019, January 16\u201320). Semantic Image Synthesis with Spatially-Adaptive Normalization. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00244"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Choi, Y., Choi, M., and Kim, M. (2018, January 19\u201321). Stargan: Unified generative adversarial networks for multi-domain image-to-image transla-tion. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00916"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Chen, C., Chen, Q., Xu, J., and Koltun, V. (2018, January 18\u201323). Learning to See in the Dark. Proceedings of the 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition; Institute of Electrical and Electronics Engineers (IEEE), Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00347"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Dai, T., Cai, J., Zhang, Y., Xia, S.-T., and Zhang, L. (2019, January 15\u201320). Second-Order Attention Network for Single Image Super-Resolution. Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.01132"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Chen, Q., and Koltun, V. (2017, January 22\u201329). Photographic Image Synthesis with Cascaded Refinement Networks. Proceedings of the 2017 IEEE International Conference on Computer Vision (ICCV), Venice, Italy.","DOI":"10.1109\/ICCV.2017.168"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Li, K., Zhang, T., and Malik, J. (November, January 27). Diverse Image Synthesis from Semantic Layouts via Conditional IMLE. Proceedings of the 2019 IEEE\/CVF International Conference on Computer Vision (ICCV), Seoul, Korea.","DOI":"10.1109\/ICCV.2019.00432"},{"key":"ref_35","unstructured":"Rossler, A., Cozzolino, D., Verdoliva, L., Riess, C., Thies, J., and Nie\u00dfner, M. (November, January 27). Faceforensics++: Learning to detect manipulated facial images. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Korea."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1016\/j.neunet.2019.07.001","article-title":"His-GAN: A histogram-based GAN model to improve data generation quality","volume":"119","author":"Li","year":"2019","journal-title":"Neural Netw."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/13\/11\/288\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:31:38Z","timestamp":1760167898000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/13\/11\/288"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,17]]},"references-count":36,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2021,11]]}},"alternative-id":["fi13110288"],"URL":"https:\/\/doi.org\/10.3390\/fi13110288","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,17]]}}}