Assessing Backdoor Risk in Deepfake Detection
摘要
Deepfake images and videos are spreading in cyberspace, threatening individuals and society. Although well-designed deep learning models have achieved satisfactory performance in detecting deepfakes, they face security risks. Compared with deep learning attacks on artificial intelligence systems, backdoor attacks on deepfake detectors have received limited attention. This chapter describes a backdoor risk assessment method for deepfake detectors. It highlights the vulnerabilities of deepfake detectors against backdoor attacks introduced by poisoning training data. Furthermore, it assesses the risk posed by these attacks on five benchmark deepfake detectors. The risk assessment results demonstrate that deepfake detectors are exposed to common but very harmful backdoor risks that must be mitigated.