ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors

📅 2026-07-23
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Current deepfake detectors exhibit insufficient robustness against generated content that incorporates realistic physical imaging characteristics. This work proposes a gradient-free adversarial attack framework that, for the first time, leverages the image signal processing (ISP) pipeline as an adversarial tool: it maps synthetic images into the RAW domain via an invertible ISP, injects Poisson-Gaussian sensor noise characteristic of real cameras, and reconstructs them through a forward ISP to embed physically plausible imaging priors. By integrating generative artifact suppression with adaptive masking, the method efficiently produces adversarial examples bearing authentic physical traces while remaining visually imperceptible. These samples significantly degrade the accuracy of multiple state-of-the-art detectors, exposing a critical vulnerability in current forensic approaches due to their reliance on missing physical imaging cues.
📝 Abstract
The rapid advancement of generative models has spurred the critical need to evaluate the worst-case robustness of deepfake detectors. In this paper, we reveal a fundamental blind spot in current forensic paradigms: while existing detectors excel at capturing digital synthesis artifacts, their effectiveness drops drastically when AI-generated content is cloaked in authentic physical imaging characteristics. We posit that genuine photographs inherently possess hardware-intrinsic statistical signatures, which are imperceptible footprints imprinted by optical sensors and Image Signal Processing (ISP) pipelines, and are fundamentally absent in purely data-driven generative models. Driven by this insight, we propose ISPCloak, a novel optimization-free adversarial attack framework that explicitly weaponizes the ISP pipeline to mislead the judgment of deepfake detectors. Rather than relying on computationally expensive gradient perturbations, our method first employs an Invertible ISP network to project images into the RAW domain. Then, we seamlessly imprint the complex statistical priors of real cameras onto AI-generated images by injecting realistic Poisson-Gaussian sensor noise and conducting forward ISP reconstruction. Synergized with generative artifact suppression and adaptive masking, this streamlined physical simulation enables ultra-fast generation of adversarial examples. Extensive experiments show that embedding authentic physical perturbations fundamentally disrupts a broad range of current detection mechanisms, yielding universally evasive adversarial examples with imperceptible visual alterations.
Problem

Research questions and friction points this paper is trying to address.

deepfake detection
physical camouflage
ISP pipeline
adversarial attack
sensor noise
Innovation

Methods, ideas, or system contributions that make the work stand out.

ISP pipeline
optimization-free attack
physical camouflage
sensor noise modeling
adversarial deepfake
🔎 Similar Papers
No similar papers found.