Deep Watermarking-based Proactive Defense for Deepfake Detection, Tracing, and Regulation
Yizhi Guo, Bingwen Feng, Xiaotian Wu, Jian Weng, Wei LuCurrent proactive defense mechanisms, though effective, predominantly concentrate on impeding deepfake models rather than regulating them. In light of the pervasive demand for deepfake creation for legitimate purposes, we introduce a proactive deepfake control framework based on a “whitelist” mechanism. This framework conditionally governs deepfake output through the utilization of a key-protected watermark, guaranteeing robustness throughout the entire process. The scheme proposes an encrypted embedder and an encrypted extractor. The former ensures that only the data owner can embed watermarks on their own facial images, while the latter safeguards against watermark leakage while facilitating watermark extraction and matching. Subsequently, the deepfake model is retrained to exclusively accept facial images that contain the specified watermark. Furthermore, a three-stage training strategy is proposed to bolster robustness and ensure watermark traceability. Experimental findings underscore the efficacy and rationality of our approach in regulating deepfake generation. Additionally, the results demonstrate the impressive performance of our scheme in terms of image quality and robustness.