Key Takeaways & Executive Findings
- •• Proposes a Full-Defense Framework (FDF) that integrates passive detection and proactive defense against deepfake. • Introduces separable watermarks (SepMark) with a robust decoder for source tracing and a semi-robust decoder sensitive to malicious distortions. • Employs cross-domain feature fusion of spatial and frequency channels to improve discrimination between deepfake content and watermark removal attacks. • Achieves dual functionality: copyright protection and deepfake detection even when watermarks are absent, offering a comprehensive defense solution.
Abstract
Deepfake poses significant threats to various fields, including politics, journalism, and entertainment. Although many defense methods against deepfake have been proposed based on either passive detection or proactive defense, few have achieved both passive detection and proactive defense. To address this issue, we propose a full-defense framework (FDF) based on cross-domain feature fusion and separable watermarks (SepMark) to achieve copyright protection and deepfake detection, combining the ideas of passive detection and proactive defense. The proactive defense module consists of one encoder and two separable decoders, where the encoder embeds one watermark into the protected face, and two decoders separately extract two watermarks with different robustness. The robust watermark can reliably trace the trusted marked face while the semi-robust watermark is sensitive to malicious distortions that make the watermark disappear after deepfake or watermark removal attack. The passive detection module fuses spatial- and frequency-domain features to further differentiate between deepfake content and watermark removal attacks in the absence of watermarks. The proposed cross-domain feature fusion involves substituting the “secondary” channels of spatial-domain features with the “primary” channels of frequency-domain features. Subsequently, the “primary” channels of spatial-domain features are used to replace the “secondary” channels of frequency-domain features. Extensive experiments demonstrate that our approach not only offers proactive defense mechanisms by using extracted watermarks, i.e., source tracing and copyright protection, but also achieves passive detection when there are no watermarks, to further differentiate between deepfake content and watermark removal attacks, thereby offering a full-defense approach.
1. Introduction
The rapid advancement of deepfake technology poses significant threats to individual privacy and societal trust. As synthetic media generation evolves, the risk of misinformation increases, raising concerns about digital content integrity and media credibility. This evolution threatens fields like journalism and privacy protection.
In response, research on deepfake defense has grown, focusing on passive detection and proactive defense techniques. Passive detection relies mainly on convolutional neural networks (CNNs) and recurrent neural networks (RNNs). Several approaches have been proposed, including two-stream CNNs to capture tampering artifacts and local noise residuals, CNNs combined with visual Transformers, Transformer-based self-supervised learning, and spatial-temporal contrastive learning. However, passive detection methods often struggle with post-processed forgeries and compressed social media content, motivating the need for integrated defense strategies that combine passive and proactive mechanisms.
Loading authentic research manuscript (Pages 1–5)...
Hui SHI, Guibin WANG, Yanni LI, Rujia QI (2025). Full-defense framework: multi-level deepfake detection and source tracing. Frontiers of Information Technology & Electronic Engineering. https://doi.org/10.1631/FITEE_2401012
Research & Educational Purpose Only:The translations, structured abstracts, analytical annotations, and data reports provided by SinoTechIntel are intended exclusively for academic research, internal corporate R&D, and educational benchmarking. They do not constitute formal engineering, chemical safety, legal, or professional advice.
Copyright & Intellectual Property Notice: Original copyright of the underlying source articles and experimental data remains with the respective authors, institutions, and original publishing journals. SinoTechIntel claims intellectual property only over its proprietary translations, analytical syntheses, and AEO structured enhancements in accordance with international fair use and academic citation principles.
Frequently Asked Questions
What is the full-defense framework (FDF)?
FDF is a unified deepfake defense system that combines passive detection and proactive defense. It uses a proactive module to embed separable watermarks for source tracing and a passive module to detect deepfake content even when watermarks are absent, differentiating between deepfake and watermark removal attacks.
How do separable watermarks (SepMark) work?
SepMark consists of one encoder and two separable decoders. The encoder embeds a single watermark into the protected face, while the two decoders extract a robust watermark for reliable source tracing and a semi-robust watermark that disappears after deepfake or watermark removal attacks, thus detecting malicious distortions.
What is cross-domain feature fusion in FDF?
Cross-domain feature fusion integrates spatial-domain and frequency-domain features by swapping their primary and secondary channels. This enhances the passive detection module's ability to discriminate between authentic content, deepfake content, and watermark removal attacks.
How does FDF differ from other deepfake defenses?
Most defenses focus on either passive detection or proactive watermarking. FDF uniquely combines both: it provides proactive source tracing and copyright protection via watermarks, while also achieving passive detection when watermarks are missing, thereby offering a comprehensive full-defense approach.
What applications can benefit from FDF?
FDF is suitable for protecting digital media integrity in journalism, legal evidence, online content verification, and entertainment. It enables copyright protection, source tracing, and reliable detection of manipulated facial content, addressing growing concerns over misinformation and privacy.
Related Technical Papers & Translations
Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption
To address the challenges of high energy consumption and prominent costs in the traditional three-columns distillation process for cellulosic fuel ethanol, a distillation—molecular sieve coupling separation process is proposed. This process integrates a three-column (crude distillation column, first distillation column, second distillation column) system with a 3A molecular sieve adsorption deep dehydration unit. A thermal coupling network is constructed via differential pressure design (steam from medium/high-pressure columns as mutual heat sources, reboiler liquid waste heat for feed preheating), and molecular sieve adsorption conditions are optimized. The study first performs a thermodynamic consistency test on the ethanol—water system, determines optimal non-random two-liquid (NRTL) model binary interaction parameters via experimental data regression for Aspen Plus simulation. Aiming at minimum total annual cost (TAC), Aspen Plus is used to optimize process parameters (theoretical tray number, feed location, reflux ratio, side-draw position, etc.). Economic analysis shows this process reduces CO2 emission costs by 27.56%, TAC by 15.58% (to 5.123 × 106 USD·a-1), and increases ethanol purity to >99.6%, providing an effective solution for green, efficient separation.
A cohesion loss model for determining residual strength of deep bedded sandstone
Rock residual strength, as an important input parameter, plays an indispensable role in proposing the reasonable and scientific scheme about stope design, underground tunnel excavation and stability evaluation of deep chambers. Therefore, previous residual strength models of rocks established were reviewed. And corresponding related problems were stated. Subsequently, starting from the effects of bedding and whole life-cycle evolution process, series of triaxial mechanical tests of deep bedded s
Federated model with contrastive learning and adaptive control variates for human activity recognition
Recent attention to privacy issues demands a communication-safe method for training human activity recognition (HAR) models on client activity data. Federated learning (FL) has become a compelling technique to facilitate model training between the server and clients while preserving data privacy. However, classical FL methods often assume independent and identically distributed (IID) data among clients. This assumption does not hold true in practical scenarios. Human activity in real-world scena