Pith. sign in

REVIEW 4 cited by

FaceSigns: Semi-Fragile Neural Watermarks for Media Authentication and Countering Deepfakes

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2204.01960 v1 pith:RRO7LTQH submitted 2022-04-05 cs.CV cs.AIstat.ML

classification cs.CVcs.AIstat.ML
keywords imagemediadeepfakedeepfakesfacesignsmanipulationssemi-fragiletechniques
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Deepfakes and manipulated media are becoming a prominent threat due to the recent advances in realistic image and video synthesis techniques. There have been several attempts at combating Deepfakes using machine learning classifiers. However, such classifiers do not generalize well to black-box image synthesis techniques and have been shown to be vulnerable to adversarial examples. To address these challenges, we introduce a deep learning based semi-fragile watermarking technique that allows media authentication by verifying an invisible secret message embedded in the image pixels. Instead of identifying and detecting fake media using visual artifacts, we propose to proactively embed a semi-fragile watermark into a real image so that we can prove its authenticity when needed. Our watermarking framework is designed to be fragile to facial manipulations or tampering while being robust to benign image-processing operations such as image compression, scaling, saturation, contrast adjustments etc. This allows images shared over the internet to retain the verifiable watermark as long as face-swapping or any other Deepfake modification technique is not applied. We demonstrate that FaceSigns can embed a 128 bit secret as an imperceptible image watermark that can be recovered with a high bit recovery accuracy at several compression levels, while being non-recoverable when unseen Deepfake manipulations are applied. For a set of unseen benign and Deepfake manipulations studied in our work, FaceSigns can reliably detect manipulated content with an AUC score of 0.996 which is significantly higher than prior image watermarking and steganography techniques.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. LampMark: Proactive Deepfake Detection via Training-Free Landmark Perceptual Watermarks

    cs.CV 2024-11 conditional novelty 7.0 of 10

    LampMark embeds a landmark-derived watermark into face images and detects deepfakes by comparing the recovered watermark to the current landmarks, achieving AUCs above 98% across seven manipulations.

  2. Combating Falsification of Speech Videos with Live Optical Signatures (Extended Version)

    cs.CV 2025-04 conditional novelty 6.0 of 10

    A speaker-deployed projector embeds cryptographically hashed features of the speaker's identity and lip motion into the scene, and any recording can be verified by comparing those features to the video content.

  3. Facial Features Matter: a Dynamic Watermark based Proactive Deepfake Detection Approach

    cs.CV 2024-11 reject novelty 5.0 of 10

    A proactive deepfake detector that generates watermarks from 128-dim facial embeddings and validates images by comparing recovered vs re-mapped watermarks.

  4. Deep Data Hiding for ICAO-Compliant Face Images: A Survey

    cs.CV 2025-08 conditional novelty 4.0 of 10

    A survey of deep data hiding methods for ICAO-compliant face images concludes that only a subset of current deep watermarking and steganography models meet the combined requirements of imperceptibility, selective robu...

Pith tools