{"id":"https://openalex.org/W4392011704","doi":"https://doi.org/10.48550/arxiv.2402.11473","title":"Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery Detection","display_name":"Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery Detection","publication_year":2024,"publication_date":"2024-02-18","ids":{"openalex":"https://openalex.org/W4392011704","doi":"https://doi.org/10.48550/arxiv.2402.11473"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2402.11473","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2402.11473","pdf_url":"https://arxiv.org/pdf/2402.11473","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2402.11473","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5009016727","display_name":"Jiawei Liang","orcid":"https://orcid.org/0000-0003-1143-6873"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Liang, Jiawei","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100844339","display_name":"Siyuan Liang","orcid":"https://orcid.org/0000-0001-6819-8293"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liang, Siyuan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014870180","display_name":"Aishan Liu","orcid":"https://orcid.org/0000-0002-4224-1318"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Aishan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084784341","display_name":"Xiaojun Jia","orcid":"https://orcid.org/0000-0002-2018-9344"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jia, Xiaojun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5093973965","display_name":"Junhao Kuang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kuang, Junhao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5068837264","display_name":"Xiaochun Cao","orcid":"https://orcid.org/0000-0001-7141-708X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cao, Xiaochun","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5009016727"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"cited_by_count":3,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11448","display_name":"Face recognition and analysis","score":0.9872999787330627,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11448","display_name":"Face recognition and analysis","score":0.9872999787330627,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9764999747276306,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10828","display_name":"Biometric Identification and Security","score":0.9567000269889832,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9861634969711304},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.7954244613647461},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5828871130943298},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.46453338861465454},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.3628111183643341},{"id":"https://openalex.org/keywords/sociology","display_name":"Sociology","score":0.10150301456451416}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9861634969711304},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.7954244613647461},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5828871130943298},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.46453338861465454},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.3628111183643341},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.10150301456451416},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2402.11473","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2402.11473","pdf_url":"https://arxiv.org/pdf/2402.11473","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},{"id":"doi:10.48550/arxiv.2402.11473","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2402.11473","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2402.11473","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2402.11473","pdf_url":"https://arxiv.org/pdf/2402.11473","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2084397926","display_name":null,"funder_award_id":"21101093","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G343342921","display_name":null,"funder_award_id":"20221101","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4414281452","display_name":null,"funder_award_id":"62025604","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4844321474","display_name":null,"funder_award_id":"202211010","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7570866693","display_name":null,"funder_award_id":"KQTD20221101093559018","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7853006071","display_name":null,"funder_award_id":"110109","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4392011704.pdf","grobid_xml":"https://content.openalex.org/works/W4392011704.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W4320031223","https://openalex.org/W3015678314","https://openalex.org/W4281902577","https://openalex.org/W4200629851","https://openalex.org/W3009072493","https://openalex.org/W4386185023","https://openalex.org/W4317672133","https://openalex.org/W3140988292","https://openalex.org/W4386080799"],"abstract_inverted_index":{"The":[0],"proliferation":[1],"of":[2,16,135],"face":[3,17,49,98,200],"forgery":[4,18,50,99,201],"techniques":[5],"has":[6],"raised":[7],"significant":[8,159],"concerns":[9],"within":[10],"society,":[11],"thereby":[12],"motivating":[13],"the":[14,68,133,136,192],"development":[15],"detection":[19,51,202],"methods.":[20],"These":[21],"methods":[22],"aim":[23],"to":[24,115,131,191],"distinguish":[25],"forged":[26,79],"faces":[27],"from":[28],"genuine":[29],"ones":[30],"and":[31,44,62,109,167],"have":[32],"proven":[33],"effective":[34],"in":[35,48,161,169,199],"practical":[36],"applications.":[37],"However,":[38],"this":[39,83,85,185],"paper":[40,86,186],"introduces":[41],"a":[42,105,111,123,158],"novel":[43,112],"previously":[45],"unrecognized":[46],"threat":[47],"scenarios":[52],"caused":[53],"by":[54,196],"backdoor":[55,95,155,180,197],"attack.":[56],"By":[57],"embedding":[58,125],"backdoors":[59],"into":[60,67,74],"models":[61],"incorporating":[63],"specific":[64],"trigger":[65,107,118],"patterns":[66],"input,":[69],"attackers":[70],"can":[71],"deceive":[72],"detectors":[73,140],"producing":[75],"erroneous":[76],"predictions":[77],"for":[78],"faces.":[80],"To":[81],"achieve":[82],"goal,":[84],"proposes":[87],"\\emph{Poisoned":[88],"Forgery":[89],"Face}":[90],"framework,":[91],"which":[92],"enables":[93],"clean-label":[94],"attacks":[96,198],"on":[97,128,142],"detectors.":[100],"Our":[101,204],"approach":[102,152],"involves":[103],"constructing":[104],"scalable":[106],"generator":[108],"utilizing":[110],"convolving":[113],"process":[114],"generate":[116],"translation-sensitive":[117],"patterns.":[119],"Moreover,":[120],"we":[121],"employ":[122],"relative":[124],"method":[126],"based":[127],"landmark-based":[129],"regions":[130],"enhance":[132],"stealthiness":[134],"poisoned":[137,144],"samples.":[138],"Consequently,":[139],"trained":[141],"our":[143,151,174],"samples":[145],"are":[146],"embedded":[147],"with":[148,157],"backdoors.":[149],"Notably,":[150],"surpasses":[153],"SoTA":[154],"baselines":[156],"improvement":[160],"attack":[162,175],"success":[163],"rate":[164],"(+16.39\\%":[165],"BD-AUC)":[166],"reduction":[168],"visibility":[170],"(-12.65\\%":[171],"$L_\\infty$).":[172],"Furthermore,":[173],"exhibits":[176],"promising":[177],"performance":[178],"against":[179],"defenses.":[181],"We":[182],"anticipate":[183],"that":[184],"will":[187,206],"draw":[188],"greater":[189],"attention":[190],"potential":[193],"threats":[194],"posed":[195],"scenarios.":[203],"codes":[205],"be":[207],"made":[208],"available":[209],"at":[210],"\\url{https://github.com/JWLiang007/PFF}":[211]},"counts_by_year":[{"year":2025,"cited_by_count":3}],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2025-10-10T00:00:00"}
