{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T18:47:24Z","timestamp":1785005244920,"version":"3.55.0"},"reference-count":39,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2022,1,29]],"date-time":"2022-01-29T00:00:00Z","timestamp":1643414400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>To protect images from the tampering of deepfake, adversarial examples can be made to replace the original images by distorting the output of the deepfake model and disrupting its work. Current studies lack generalizability in that they simply focus on the adversarial examples generated by a model in a domain. To improve the generalization of adversarial examples and produce better attack effects on each domain of multiple deepfake models, this paper proposes a framework of Cross-Domain and Model Adversarial Attack (CDMAA). Firstly, CDMAA uniformly weights the loss function of each domain and calculates the cross-domain gradient. Then, inspired by the multiple gradient descent algorithm (MGDA), CDMAA integrates the cross-domain gradients of each model to obtain the cross-domain perturbation vector, which is used to optimize the adversarial example. Finally, we propose a penalty-based gradient regularization method to pre-process the cross-domain gradients to improve the success rate of attacks. CDMAA experiments on four mainstream deepfake models showed that the adversarial examples generated from CDMAA have the generalizability of attacking multiple models and multiple domains simultaneously. Ablation experiments were conducted to compare the CDMAA components with the methods used in existing studies and verify the superiority of CDMAA.<\/jats:p>","DOI":"10.3390\/fi14020046","type":"journal-article","created":{"date-parts":[[2022,1,29]],"date-time":"2022-01-29T23:02:06Z","timestamp":1643497326000},"page":"46","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["The Framework of Cross-Domain and Model Adversarial Attack against Deepfake"],"prefix":"10.3390","volume":"14","author":[{"given":"Haoxuan","family":"Qiu","sequence":"first","affiliation":[{"name":"College of Information and Cyber Security, People\u2019s Public Security University of China, Beijing 100038, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanhui","family":"Du","sequence":"additional","affiliation":[{"name":"College of Information and Cyber Security, People\u2019s Public Security University of China, Beijing 100038, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianliang","family":"Lu","sequence":"additional","affiliation":[{"name":"College of Information and Cyber Security, People\u2019s Public Security University of China, Beijing 100038, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,1,29]]},"reference":[{"key":"ref_1","unstructured":"(2021, December 10). Faceswap: Deepfakes Software for All. Available online: https:\/\/github.com\/deepfakes\/faceswap."},{"key":"ref_2","first-page":"147","article-title":"Deepfakes and the new disinformation war: The coming age of post-truth geopolitics","volume":"98","author":"Chesney","year":"2019","journal-title":"Foreign Aff."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1177\/1365712718807226","article-title":"Determining authenticity of video evidence in the age of artificial intelligence and in the wake of deepfake videos","volume":"23","author":"Maras","year":"2019","journal-title":"Int. J. Evid. Proof"},{"key":"ref_4","unstructured":"Rossler, A., Cozzolino, D., Verdoliva, L., Riess, C., Thies, J., and Nie\u00dfner, M. (November, January 27). Faceforensics++: Learning to detect manipulated facial images. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Korea."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Bonettini, N., Cannas, E.D., Mandelli, S., Bondi, L., Bestagini, P., and Tubaro, S. (2021, January 10\u201315). Video face manipulation detection through ensemble of cnns. Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR), Milan, Italy.","DOI":"10.1109\/ICPR48806.2021.9412711"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Tariq, S., Lee, S., and Woo, S. (2021, January 19\u201323). One detector to rule them all: Towards a general deepfake attack detection framework. Proceedings of the Web Conference 2021, Ljubljana, Slovenia.","DOI":"10.1145\/3442381.3449809"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Afchar, D., Nozick, V., Yamagishi, J., and Echizen, I. (2018, January 11\u201313). Mesonet: A compact facial video forgery detection network. Proceedings of the 2018 IEEE International Workshop on Information Forensics and Security (WIFS), Hong Kong, China.","DOI":"10.1109\/WIFS.2018.8630761"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Zhao, H., Zhou, W., Chen, D., Wei, T., Zhang, W., and Yu, N. (2021, January 19\u201325). Multi-attentional deepfake detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Online.","DOI":"10.1109\/CVPR46437.2021.00222"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Mittal, T., Bhattacharya, U., Chandra, R., Bera, A., and Manocha, D. (2020, January 12\u201316). Emotions Don\u2019t Lie: An Audio-Visual Deepfake Detection Method using Affective Cues. Proceedings of the 28th ACM international conference on multimedia, Seattle, WA, USA.","DOI":"10.1145\/3394171.3413570"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Chugh, K., Gupta, P., Dhall, A., and Subramanian, R. (2020, January 12\u201316). Not made for each other-audio-visual dissonance-based deepfake detection and localization. Proceedings of the 28th ACM International Conference on Multimedia, Seattle, WA, USA.","DOI":"10.1145\/3394171.3413700"},{"key":"ref_11","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Huang, H., Wang, Y., Chen, Z., Li, Y., Tang, Z., Chu, W., Chen, J., Lin, W., and Ma, K.K. (2021). CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating Deepfakes. arXiv.","DOI":"10.1609\/aaai.v36i1.19982"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Ruiz, N., Bargal, S.A., and Sclaroff, S. (2020). Disrupting deepfakes: Adversarial attacks against conditional image translation networks and facial manipulation systems. European Conference on Computer Vision, Springer.","DOI":"10.1007\/978-3-030-66823-5_14"},{"key":"ref_14","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2016). Adversarial examples in the physical world. arXiv."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"313","DOI":"10.1016\/j.crma.2012.03.014","article-title":"Multiple-gradient descent algorithm (MGDA) for multiobjective optimization","volume":"350","year":"2012","journal-title":"Comptes Rendus Math."},{"key":"ref_16","first-page":"2672","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow","year":"2014","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_17","unstructured":"Karras, T., Aila, T., Laine, S., and Lehtinen, J. (2017). Progressive growing of gans for improved quality, stability, and variation. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Karras, T., Laine, S., and Aila, T. (2019, January 15\u201320). A style-based generator architecture for generative adversarial networks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Choi, Y., Choi, M., Kim, M., Ha, J.W., Kim, S., and Choo, J. (2018, January 18\u201323). Stargan: Unified generative adversarial networks for multi-domain image-to-image translation. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00916"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"5464","DOI":"10.1109\/TIP.2019.2916751","article-title":"Attgan: Facial attribute editing by only changing what you want","volume":"28","author":"He","year":"2019","journal-title":"IEEE Trans. Image Process."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Liu, M., Ding, Y., Xia, M., Liu, X., Ding, E., Zuo, W., and Wen, S. (2019, January 15\u201320). STGAN: A unified selective transfer network for arbitrary image attribute editing. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00379"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Zhu, J.Y., Park, T., Isola, P., and Efros, A.A. (2017, January 22\u201329). Unpaired image-to-image translation using cycle-consistent adversarial networks. Proceedings of the IEEE International Conference on Computer Vision, Venice, Italy.","DOI":"10.1109\/ICCV.2017.244"},{"key":"ref_23","unstructured":"Kim, J., Kim, M., Kang, H., and Lee, K. (2019). U-gat-it: Unsupervised generative attentional networks with adaptive layer-instance normalization for image-to-image translation. arXiv."},{"key":"ref_24","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","volume":"25","author":"Krizhevsky","year":"2012","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_25","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv."},{"key":"ref_26","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J. (2018, January 18\u201323). Boosting adversarial attacks with momentum. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref_28","unstructured":"Croce, F., and Hein, M. (2020, January 13\u201318). Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. Proceedings of the International Conference on Machine Learning, PMLR, Online."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kos, J., Fischer, I., and Song, D. (2018, January 24\u201324). Adversarial examples for generative models. Proceedings of the 2018 IEEE Security and Privacy Workshops (spw), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2018.00014"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Yeh, C.Y., Chen, H.W., Tsai, S.L., and Wang, S.D. (2020, January 1\u20135). Disrupting image-translation-based deepfake algorithms with adversarial attacks. Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision Workshops, Snowmass Village, CO, USA.","DOI":"10.1109\/WACVW50321.2020.9096939"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Isola, P., Zhu, J.Y., Zhou, T., and Efros, A.A. (2017, January 21\u201326). Image-to-image translation with conditional adversarial networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.632"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Lv, L. (2021, January 23\u201326). Smart Watermark to Defend against Deepfake Image Manipulation. Proceedings of the 2021 IEEE 6th International Conference on Computer and Communication Systems (ICCCS), Chengdu, China.","DOI":"10.1109\/ICCCS52626.2021.9449287"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Dong, J., and Xie, X. (2021, January 5\u20139). Visually Maintained Image Disturbance Against Deepfake Face Swapping. Proceedings of the 2021 IEEE International Conference on Multimedia and Expo (ICME), Shenzhen, China.","DOI":"10.1109\/ICME51207.2021.9428173"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Fang, Z., Yang, Y., Lin, J., and Zhan, R. (2020, January 18\u201320). Adversarial Attacks For Multi Target Image Translation Networks. Proceedings of the 2020 IEEE International Conference on Progress in Informatics and Computing (PIC), Shanghai, China.","DOI":"10.1109\/PIC50277.2020.9350768"},{"key":"ref_35","unstructured":"Jaggi, M. (2013, January 17\u201319). Revisiting Frank-Wolfe: Projection-free sparse convex optimization. Proceedings of the International Conference on Machine Learning, PMLR, Atlanta, GA, USA."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1002\/nav.3800030109","article-title":"An algorithm for quadratic programming","volume":"3","author":"Frank","year":"1956","journal-title":"Nav. Res. Logist. Q."},{"key":"ref_37","unstructured":"Sener, O., and Koltun, V. (2018). Multi-task learning as multi-objective optimization. arXiv."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Xiao, C., Li, B., Zhu, J.Y., He, W., Liu, M., and Song, D. (2018). Generating adversarial examples with adversarial networks. arXiv.","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref_39","unstructured":"Brendel, W., Rauber, J., and Bethge, M. (2017). Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/2\/46\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:11:08Z","timestamp":1760134268000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/2\/46"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,29]]},"references-count":39,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["fi14020046"],"URL":"https:\/\/doi.org\/10.3390\/fi14020046","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,29]]}}}