acceptodds
Under review as a conference paper at ICLR 2027

SyncEdit: Semantically Selective Lip-Sync Disruption for Talking-Head Generation

Abstract

Audio-driven talking-head systems can be misused to fabricate convincing videos in which a target identity appears to deliver harmful speech. Existing defenses perturb the supplied portrait or audio, requiring per-input optimization without considering speech semantics. We propose SYNCEDIT, a model-level defense that retrains only the audio encoder while keeping downstream modules unchanged. SYNCEDIT disrupts audio–lip synchronization for harmful speech while preserving generation for semantically benign speech both with and without harmful keywords, without requiring speech-category labels or external classifiers at inference time. Direct joint training of these objectives stalls because gradients for harmful-speech disruption interfere with those for benign-speech preservation. We address this conflict through two-stage optimization and coupling-based layer selection. Experiments on four heterogeneous talking-head systems show that SYNCEDIT induces substantially larger representation and synchronization changes for harmful speech than for either benign category, while preserving identity and visual quality. A human study further confirms that SYNCEDIT reduces perceived mouth match and credibility for harmful videos while leaving both benign categories nearly unchanged. Ablations validate the proposed training design, and further experiments demonstrate generalization to unseen speech distributions and partial resistance to a white-box adaptive attack.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.