PhantomSeal: Proactive Deepfakes Defense with Identity/Context Protection and Forensic Tracing
Liangqin Ren, Zeyan Liu, Ye Wang, Yuxin Chen, Fengjun Li, Bo Luo
cs.CR
Submitted: 2026-07-20
Comments: 22 pages, 5 figures, and 24 tables. Extended version with additional technical details and appendices. Accepted by ACM CCS 2026
Code: https://github.com/LiangqinRen/PhantomSeal
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: Deepfakes, especially face-swapping attacks, pose significant challenges to authenticity, security, and ethics across science, engineering, and society.
Terminology
Abstract
Deepfakes, especially face-swapping attacks, pose significant challenges to authenticity, security, and ethics across science, engineering, and society. While most existing detection/tracing approaches operate post hoc, proactive defenses that aim to intervene before deepfake generation remain limited in terms of real-world effectiveness. In this paper, we present PhantomSeal, the first proactive defense to simultaneously protect both the identity and the context of users' images from being used in face-swapping attacks, while supporting forensic tracing. We present a novel cloaking technique that embeds a selected identity as a stealthy identifier. This mechanism steers the deepfake generation process toward producing content that resembles the chosen cloak identity, thereby preventing successful face-swapping while enabling effective feature-based forensic analysis. The effectiveness and robustness of PhantomSeal is demonstrated in extensive experiments across different face-swapping architectures and models. For example, it reduces the attack success rate of SimSwap, an advanced deepfake model, to 0.30%, and correctly identifies 97.97% of manipulated content. The source codes is available at https://github.com/LiangqinRen/PhantomSeal.
Sources
- Explaining and Harnessing Adversarial Examples
- FaceShield: Defending Facial Image against Deepfake Threats
- Adversarial Machine Learning at Scale
- Facial Features Matter: a Dynamic Watermark based Proactive Deepfake Detection Approach
- Inject Where It Matters: Training-Free Spatially-Adaptive Identity Preservation for Text-to-Image Personalization
- FaceShifter: Towards High Fidelity And Occlusion Aware Face Swapping
- E4S: Fine-grained Face Swapping via Editing With Regional GAN Inversion
- Hiding Faces in Plain Sight: Disrupting AI Face Synthesis with Adversarial Perturbations
- Towards Deep Learning Models Resistant to Adversarial Attacks
- Conditional Generative Adversarial Nets
- Detecting GAN generated Fake Images using Co-occurrence Matrices
- OGAN: Disrupting Deepfakes with an Adversarial Attack that Survives Training
- LEAT: Towards Robust Deepfake Disruption in Real-World Scenarios via Latent Ensemble Attack
- InstantID: Zero-shot Identity-Preserving Generation in Seconds
- HifiFace: 3D Shape and Semantic Prior Guided High Fidelity Face Swapping
- Are Watermarks Bugs for Deepfake Detectors? Rethinking Proactive Forensics
- FaceGuard: Proactive Deepfake Detection
- Hiding Faces in Plain Sight: Defending DeepFakes by Disrupting Face Detection
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs