Recent advances in Generative Adversarial Networks (GANs) have shown increasing success in generating photorealistic images. But they also raise challenges to visual forensics and model attribution. We present the first study of learning GAN fingerprints towards image attribution and using them to classify an image as real or GAN-generated. For GAN-generated images, we further identify their sources. Our experiments show that (1) GANs carry distinct model fingerprints and leave stable fingerprints in their generated images, which support image attribution; (2) even minor differences in GAN training can result in different fingerprints, which enables fine-grained model authentication; (3) fingerprints persist across different image frequencies and patches and are not biased by GAN artifacts; (4) fingerprint finetuning is effective in immunizing against five types of adversarial image perturbations; and (5) comparisons also show our learned fingerprints consistently outperform several baselines in a variety of setups.
History
Preferred Citation
Ning Yu, Larry Davis and Mario Fritz. Attributing Fake Images to GANs: Learning and Analyzing GAN Fingerprints. In: IEEE International Conference on Computer Vision (ICCV). 2019.
Primary Research Area
Trustworthy Information Processing
Secondary Research Area
Empirical and Behavioral Security
Name of Conference
IEEE International Conference on Computer Vision (ICCV)
Legacy Posted Date
2019-08-22
Open Access Type
Gold
BibTeX
@inproceedings{cispa_all_2965,
title = "Attributing Fake Images to GANs: Learning and Analyzing GAN Fingerprints",
author = "Yu, Ning and Davis, Larry and Fritz, Mario",
booktitle="{IEEE International Conference on Computer Vision (ICCV)}",
year="2019",
}