딥페이크 생성 기술의 급속한 발전에 따라, 실제 환경에서도 신뢰할 수 있는 포렌식 모델의 견고성을 확보하는 것이 중요한 과제로 부상하였다. 기존의 딥페이크 탐지기는 정제된 벤치마크 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17293190
Seoul : Sungkyunkwan University, 2025
Thesis (M.A.) -- Sungkyunkwan University , Department of Artificial Intelligence , 2025. 8
2025
영어
서울
현실 환경 왜곡 및 다단계 변조에 강인한 딥페이크 탐지
89 p. : col. ill., charts ; 30 cm
Advisor: Simon S. Woo
Includes bibliographical reference(p. 66-74)
I804:11040-000000183979
0
상세조회0
다운로드딥페이크 생성 기술의 급속한 발전에 따라, 실제 환경에서도 신뢰할 수 있는 포렌식 모델의 견고성을 확보하는 것이 중요한 과제로 부상하였다. 기존의 딥페이크 탐지기는 정제된 벤치마크 ...
딥페이크 생성 기술의 급속한 발전에 따라, 실제 환경에서도 신뢰할 수 있는 포렌식 모델의 견고성을 확보하는 것이 중요한 과제로 부상하였다. 기존의 딥페이크 탐지기는 정제된 벤치마크 환경에서는 우수한 성능을 보였지만, 실제 환경에서의 왜곡이나 다단계 변조에는 취약할 수 있다는 점은 충분히 조명되지 않았다. 이에 본 연구에서는 두 가지 현실적 시나리오를 중심으로 딥페이크 탐지기의 견고성과 일반화 성능을 종합적으로 평가하였다.
첫 번째로, 화면 촬영 과정에서 발생하는 모아레(Moiré) 패턴 왜곡이 탐지 성능에 미치는 영향을 분석하기 위해 DeepMoiréFake(DMF) 데이터셋을 구축하였다. 해당 데이터셋은 스마트폰으로 다양한 모니터를 촬영하여 수집한 실제 모아레 패턴과, Moiré Attack(MA) 및 Screen Photo Simulator(SPS)를 활용해 생성한 합성 모아레 패턴을 포함하도록 구성하였다. 실험 결과, 실제 모아레는 최대 11.7%의 AUC 성능 저하를 유발하였고, 단순한 디모아레 처리(demoiréing)는 오히려 포렌식 단서를 제거하여 탐지 성능을 더욱 떨어뜨리는 것으로 나타났다. 원본 및 모아레 왜곡을 포함한 데이터로 재학습한 결과, 모아레 패턴이 없는 깨끗한 원본 데이터에 대한 성능 저하 없이 탐지기의 강인성이 크게 향상되었으며, 원본, 실제 모아레, 합성 모아레 조건 모두에서 일관된 성능 향상을 달성할 수 있었다.
두 번째로, 다단계 변조(multi-step manipulation) 시나리오를 분석하기 위해 FaceSwap, GAN, 디퓨전 기반 생성기 5종을 조합하여 1단계, 2단계, 3단계로 구성된 FakeChain 벤치마크를 제안하였다. 정량적·정성적 분석 결과, 마지막 단계에 사용된 생성기가 탐지 성능에 가장 큰 영향을 미치며, 이전 단계의 변조 흔적은 대부분 덮어지는 경향을 보였다. 특히, FaceSwap은 변조 단계 수와 무관하게 안정적인 포렌식 특성을 유지하는 반면, GAN 기반 모델은 마지막 단계의 아티팩트가 이전 정보를 덮어버리는 경향을 나타냈다. 디퓨전 기반 모델은 변조 이력을 효과적으로 보존함으로써 특징 공간에서 뚜렷한 분리를 유도하였다.
이러한 결과를 바탕으로, 본 연구는 기존 딥페이크 탐지 파이프라인의 한계를 지적하고, 현실적인 왜곡에 강인한 탐지기를 개발하기 위해 다음과 같은 전략의 필요성을 제시하였다: (1) 왜곡 인지 기반 학습, (2) 다단계 조합 변조에 대한 평가, (3) 포렌식 신호의 보존. 본 연구는 실사용 환경에서도 신뢰할 수 있는 딥페이크 탐지기를 설계하는 데 있어 실질적인 방향성과 통찰을 제공하였다.
다국어 초록 (Multilingual Abstract)
As deepfake generation technologies rapidly evolve, ensuring the robustness of forensic models under real-world conditions becomes increasingly urgent. While existing detectors perform well on clean, benchmark datasets, their vulnerability to natural ...
As deepfake generation technologies rapidly evolve, ensuring the robustness of forensic models under real-world conditions becomes increasingly urgent. While existing detectors perform well on clean, benchmark datasets, their vulnerability to natural distortions and multi-step manipulations remains underexplored. In this study, we present a comprehensive evaluation of deepfake detection performance under two critical yet insufficiently explored scenarios: (1) Moiré pattern artifacts caused by screen-captured content, and (2) multi-stage manipulation pipelines composed of sequential generative techniques.
To investigate the first scenario, we construct the DeepMoiréFake (DMF) dataset, which integrates authentic Moiré patterns captured using smartphone recordings of monitors, along with synthetic distortions generated through augmentation-based (MA) and simulation-based (SPS) approaches. We observe that authentic Moiré patterns can degrade detector AUC scores by up to 11.7%, and that naïve demoiréing often further reduces performance by inadvertently removing forensic cues. However, retraining with a combination of original and authentic Moiré distortions significantly enhances detector robustness, yielding consistent performance improvements across both clean and distorted test conditions without compromising accuracy on undistorted data.
In the second scenario, we introduce the FakeChain benchmark, which includes 1-, 2-, and 3-step manipulated images composed from five popular generators spanning face-swapping, GAN, and diffusion models. Through quantitative and qualitative analysis, including t-SNE visualization and FFT-based spectral analysis, we demonstrate that the final generator heavily influences detectability and often masks prior manipulations. Face-swapping models yield stable forensic cues across manipulation depths, GANs tend to overwrite earlier signals with final-stage artifacts, and diffusion models more effectively preserve manipulation history, resulting in clearer separation in the feature space. Together, these results reveal critical limitations in current detection pipelines and offer actionable insights for developing more resilient deepfake detectors. Our work highlights the importance of distortion-aware training, compositional evaluation, and forensic feature preservation to ensure robustness in real-world deployment scenarios.
목차 (Table of Contents)