Source-linked AI summary
Can Tainted Pixels Expose Deepfake Videos?
Juan Hu, Shaojing Fan, Sanjay Saha, Marc Herrera, Terence Sim
TL;DR
Accessible black-box tools make convincing deepfake videos easy to create, while proactive video protection and its effects on human perception remain underexplored. TaintedPixels embeds structured blue-channel perturbations under perceptual budgets so source videos remain inconspicuous but manipulation exposes artifacts. Across public tools, it achieves strong machine and human detectability while maintaining low perceptual distortion, though its scope excludes future, closed-source, or adaptive attackers.
Problem
Accessible face-manipulation tools enable non-experts to create convincing deepfake videos, while proactive protection of facial videos against black-box tools and its human perceptual effects remain underexplored.
Method
TaintedPixels embeds structured periodic perturbations in facial blue-channel regions and refines them under visibility, color-cast, and video-level LPIPS budgets without requiring downstream-tool information.
Results
90.72% versus 56.71%: human detection of forgeries from protected sources exceeded detection of forgeries from clean sources by 34.01 percentage points.
Takeaways & Limitations
TaintedPixels provides a source-side video defense intended to keep published videos natural while making outputs from public manipulation tools visibly unreliable and easier to detect.
Takeaways & Limitations
The evaluation does not claim universal robustness against future, closed-source, or adaptive forgery models.
Abstract
from arXiv · showhide
Publicly-acceesible face-manipulation tools have made deepfake creation accessible to non-expert users. Against these, existing defenses are mostly post-hoc, detecting only after forgery has occurred, and operating on still images rather than videos. Research is lacking in i) the proactive protection of published facial videos against black-box manipulation tools, and in (ii) understanding its perceptual effect on human viewers. We introduce TaintedPixels, a proactive video-protection method built around an asymmetric visibility trade-off: the embedded watermark should remain inconspicuous in the published video but become obvious once a downstream tool manipulates the video. TaintedPixels injects structured periodic perturbations into the blue channel of facial regions and refines them under stripe-visibility, color-cast, and video-level LPIPS budgets, with lightweight motion-adaptive deployment. We believe TaintedPixels is the first proactive defense designed specifically against black-box manipulation tools rather than image-level pipelines or specific surrogate generators. Across three publicly available off-the-shelf video manipulation tools and two off-the-shelf detectors, TaintedPixels attains the highest forgery fake rate while keeping perturbations small (LPIPS = 0.0042). Our non-expert human study, conducted on a diverse set of 300 video stimuli spanning different lighting conditions, backgrounds, and skin tones, shows that protected source videos draw a 3.26% suspicion rate, while forgeries from protected sources are identified as fake much more often than forgeries from unprotected sources (90.72% vs. 56.71%). This validates the effectiveness of TaintedPixels.
1 Introduction
TaintedPixels addresses the need for proactive protection of facial videos against accessible black-box manipulation tools. It keeps source videos inconspicuous while exposing manipulation artifacts to detectors and human viewers.
- Public face-manipulation tools let non-experts create convincing deepfake videos, increasing risks of impersonation and misinformation.
- Proactive defenses act before dissemination, avoiding the slow and incomplete takedown process associated with post-hoc detection.
- TaintedPixels balances three goals: imperceptible source perturbations, detector-visible signals after manipulation, and suspicious-looking forgeries for human viewers.
- The method embeds structured periodic perturbations in facial blue-channel regions and refines them under stripe-visibility, color-cast, and video-level LPIPS budgets.
- TaintedPixels requires no downstream-tool access or assumptions, generating protection solely from the source video under perceptual constraints.
- The evaluation targets Roop, FaceFusion, and MuseTalk, while explicitly limiting claims to current public tools rather than future, closed-source, or adaptive models.
- The study reports a first human perceptual evaluation showing that forgeries from protected videos are easier to identify by sight.
2 Related Work
Prior work includes disruption-based proactive defenses, provenance watermarks, and research on human perception and dissemination. TaintedPixels differs by protecting videos against off-the-shelf black-box tools while emphasizing post-manipulation artifact exposure and source-side perceptual quality.
- Disruption-based proactive defense: Disruption-based defenses perturb benign media so downstream manipulation models produce less realistic outputs, with prior work varying in robustness, transferability, efficiency, and perceptual quality.
- Disruption-based proactive defense: TaintedPixels shifts from image-level perturbations targeting surrogate generators or identity suppression to video-level protection against off-the-shelf black-box tools.
- Disruption-based proactive defense: Its objective is to expose manipulation-induced artifacts after processing, using structured chromatic perturbations and video-level perceptual constraints rather than generic norm-bounded noise.
- Watermarking and provenance-based defenses: Watermarking and provenance methods support authentication, attribution, source tracing, or proactive detection, typically through verifiable embedded signals.
- Human perception and social media dynamics: Human difficulty distinguishing realistic manipulations and the rapid spread of manipulated media motivate defenses that account for perception and dissemination.
3 Method
TaintedPixels formulates facial-video protection as a black-box, visibility-budgeted disruption problem: structured blue-channel signals remain unobtrusive before manipulation but become exposed after downstream processing.
- Structured Blue-Channel Perturbation Prior: Blue-channel, face-aware allocation places perturbation energy where downstream tools are more likely to transform it and humans are less sensitive to small variations.Soft face masks avoid boundary discontinuities and encode facial regions as the primary transformed area under black-box conditions.
- Structured Blue-Channel Perturbation Prior: Structured perturbations combine periodic patterns with high-frequency masking and are concentrated in locally textured regions.The high-frequency mask ranks patches so small chromatic changes are less noticeable, while smooth blending preserves spatial coherence.
- Visibility-Budgeted Perturbation Refinement: The optimization balances disruption strength, structural consistency, and source-side visual quality while restricting perturbations to the blue channel and bounding their magnitude.The disruption term is model-agnostic, whereas structural consistency preserves periodic patterns that are more stable under resizing, normalization, and rendering.
- Visibility-Budgeted Perturbation Refinement: The visibility objective penalizes stripe visibility, color cast, and global perceptual distortion only when they exceed content-adaptive budgets.Video-level LPIPS averages perceptual deviation across a temporal window rather than constraining only one frame.
- Overview: The framework protects facial videos without access to manipulation-tool internals, gradients, outputs, APIs, or parameters.It relies only on the source video and perceptual constraints, using facial regions as a weak semantic prior.
- Optimization and Video Generation: Optimized protection is generated with lightweight video processing, then intended to be amplified by manipulation preprocessing and rendering into visible artifacts or reduced realism.The procedure exploits temporal redundancy by optimizing sampled frames and propagating protection to the full video.
4 Experiments
Experiments evaluate TaintedPixels against three public black-box manipulation tools, compare protection effectiveness and robustness, and measure source naturalness and human forgery detection. Across detector, qualitative, ablation, and human-study results, protected videos remain visually natural before manipulation while producing more detectable failures afterward.
- Experimental setup: Three off-the-shelf tools—Roop, FaceFusion, and MuseTalk—serve as black-box manipulation pipelines, with real videos from FaceForensics++ and Celeb-DF used for protection experiments.Only real videos from the two datasets are used; each video receives clean and protected inputs.
- Protection effectiveness: TaintedPixels makes forgeries from protected videos easier to detect than those protected by compared proactive state-of-the-art methods, while retaining a favorable video-LPIPS trade-off despite not achieving the best PSNR or SSIM.The comparison uses public black-box manipulation tools and reports detector-based protection effectiveness alongside source-video quality.
- Robustness: 3.13% and 4.27% reductions in fake-detection accuracy follow re-encoding and H.264 compression, respectively, but the protection signal remains preserved under both operations.Post-processing is applied before manipulation to test robustness under common publishing transformations.
- Qualitative results: Protected videos remain visually close to clean sources, whereas their forged outputs show more noticeable yellowish and purplish facial color distortions than rival methods.Qualitative examples use Roop and show failures after manipulation rather than obvious artifacts in the protected source videos.
- Ablation study: Structured, region-aware, and temporally adaptive perturbations are all critical to effectiveness in ablations averaged over Roop, FaceFusion, and MuseTalk.The ablation evaluates the structured periodic prior, high-frequency mask, face-aware allocation, visibility budget, motion-adaptive scaling, and video-level LPIPS.
- Human perceptual study: 3.26% false alarms occur for protected source videos, while forgeries from protected sources reach a 90.72% human fake-detection rate versus 56.71% for forgeries from clean sources.The human study includes 40 non-expert participants and four video conditions; source and manipulation outcomes use different interpretations of affirmative responses.
5 Conclusion
TaintedPixels is presented as a proactive facial-video defense that keeps structured perturbations inconspicuous before manipulation but exposes them afterward. The method is tool-agnostic, though targeted denoising or heavy compression remains a possible attack.
- TaintedPixels operationalizes an asymmetric visibility trade-off for facial videos: perturbations stay inconspicuous before manipulation and become exposed afterward.
- TaintedPixels requires no information about the downstream manipulation tool, including API access.
- Targeted denoising or heavy compression could remove the perturbation, while low video-level LPIPS is intended to reduce suspicion from attackers.
A Technical appendices and supplementary material
The supplementary material documents implementation settings and auxiliary visibility quantities. Experiments use the initial hyperparameter values, with parameter fine-tuning based on six frames.
- The appendix summarizes the main initial implementation hyperparameters in Table 4.
- All experiments use the initial values in Table 4, while parameters are fine-tuned based on 6 frames.
- Table 5 defines the auxiliary quantities used to characterize visibility-related aspects of the method.