Privacy-Preserving Deepfake Detection and Fine-Grained Artifact Localization with Forensic-Aware Image Hiding
Abstract
Remote face-forgery analysis typically requires transmitting identifiable facial content to remote services, creating privacy risks during transmission and storage. Encryption can conceal image content, but an image-like ciphertext may reveal the presence of protected communication and facilitate traffic-level discovery or tracking. Moreover, a conventional decrypt-then-infer pipeline exposes plaintext at the endpoint that performs inference. We propose VeilTrace, a recoverable image-hiding framework that represents a face as a cover-like protected image and reconstructs it only at an authorized forensic endpoint for downstream detection and fine-grained localization. VeilTrace addresses two key challenges. First, high RGB reconstruction fidelity does not guarantee preservation of forensic signals. We therefore introduce a forensic-response consistency objective based on fixed forensic proxy responses. Second, residual misalignment between real/fake pairs can contaminate pixel-level DSSIM supervision. We therefore apply full DSSIM only to geometrically reliable pairs and use a mask-supported fallback for unreliable pairs when a usable manipulation mask is available, yielding our Hybrid-DSSIM strategy. Extensive experiments show that VeilTrace reduces direct exposure of facial plaintext under the evaluated threat model while retaining high forgery-detection accuracy, with a rounded mean frame-level AUC of 88.98% in the FA+SBI setting and 49.76 dB recovery PSNR. Hybrid-DSSIM yields the strongest artifact-map agreement in the controlled ablation.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.