
Disclaimer: These are my personal notes on this paper. I am in no way related to this paper. All credits go towards the authors.

Adversarial Perturbations Fool Deepfake Detectors

May 15, 2020 - Paper Link - Tags: Deepfake, Detection, Perturbation


Used two different attack that use perturbation (FGSM and CW-L2). Attack did well on the VGG and ResNet models. Tried two different defenses. The Lipschitz Regularization defense improved the results somewhat. The Deep Image Prior stopped the attack really well, but was INCREDIBLY slow (30 minutes per image).



Interesting References

Citation: Gandhi, Apurva, and Shomik Jain. "Adversarial perturbations fool deepfake detectors." arXiv preprint arXiv:2003.10596 (2020).