Skip to content
Open access

A Novel Glow Adversarial Attack for Proactive Deepfake Defense

2026 · IEEE Access · Vol 14, pp. 143292-143317 · 0 citations · 70 references

Abstract

The accelerated expansion of deepfakes, fueled by progress in generative adversarial networks, causes growing risks to digital security, personal privacy, and the credibility of online information. Recent proactive defense methods often rely on adversarial noise that introduces noticeable visual artifacts, limiting both imperceptibility and effectiveness. To address these challenges, this study presents GlowAttack, a proactive defense framework that generates perceptually imperceptible adversarial perturbations by adapting illumination-inspired highlight models to image-space facial representations. The generated perturbations blend naturally with facial illumination as subtle glow-like enhancements, improving visual quality while disrupting deepfake synthesis. Specifically, GlowAttack proposes four illumination-inspired perturbation generation strategies derived from classical specular formulations: Ward-Inspired Edge-Aware Attack <inline-formula> <tex-math notation="LaTeX">$\left ({ Glow_{EAW}}\right)$ </tex-math></inline-formula>, Cook–Torrance-Inspired Attack <inline-formula> <tex-math notation="LaTeX">$\left ({ Glow_{GMCT}}\right)$ </tex-math></inline-formula>, Blinn–Phong-Inspired Attack <inline-formula> <tex-math notation="LaTeX">$\left ({ Glow_{CABP}}\right)$ </tex-math></inline-formula>, and Frequency-and-Gradient-Adaptive Phong Attack <inline-formula> <tex-math notation="LaTeX">$\left ({ Glow_{FGAP}}\right)$ </tex-math></inline-formula>. An adaptive parameter optimization mechanism is further introduced to optimize image-space perturbation parameters, enabling the generated adversarial perturbations to adapt to local structural, edge, and frequency information. In-depth analyses of various advanced deepfake generation frameworks show that the proposed GlowAttack achieves improved visual quality while maintaining strong transferability at both the model and class levels, thereby exceeding existing adversarial proactive defences.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.