🛡️ Red Team Framework: Image Protection Against AI Manipulation
A comprehensive red team pipeline for evaluating adversarial perturbation-based image protection methods against deepfake generation and AI manipulation.
Overview
This framework implements and benchmarks three state-of-the-art image protection methods:
Face identity similarity between source & deepfake output
FaceShield
LPIPS
Perceptual distance between images
All
PSNR
Peak signal-to-noise ratio
All
SSIM
Structural similarity index
FaceShield
CLIP Dir. Sim.
Alignment between edit direction and text
DiffusionGuard
ImageReward
Human-aligned quality assessment
DiffusionGuard
FID
Fréchet Inception Distance
All
L2 Distance
Pixel-level difference
All
Pre-processing Robustness Tests
The framework tests protection robustness against common pre-processing attacks:
JPEG Compression (Q=75, Q=50, Q=25)
Gaussian Blur (σ=1.0, 2.0, 3.0)
Resize & Restore (50%, 75%)
Center Crop & Resize
AdverseCleaner (algorithmic purification)
Random Noise Addition (σ=0.01, 0.05)
Hardware Requirements
Method
Min VRAM
Recommended GPU
Time per Image
FaceShield
8 GB
RTX A6000 (48GB)
~30s (30 iters)
DiffusionGuard
12 GB
RTX 3090 (24GB)
~90s (800 iters)
VGMShield (Prevention)
16 GB
A100 (80GB)
~5min (1000 iters)
Full Pipeline
24 GB
A100 (80GB)
~10min per method
Comprehensive Analysis Report
See ANALYSIS_REPORT.md for the full comparative analysis with quantitative results from all papers.
Citation
bibtex
1@InProceedings{Jeong_2025_ICCV,
2 title={FaceShield: Defending Facial Image against Deepfake Threats},
3 author={Jeong, Jaehwan and In, Sumin and Kim, Sieun and Shin, Hannie and Jeong, Jongheon and Yoon, Sang Ho and Chung, Jaewook and Kim, Sangpil},
4 booktitle={ICCV},
5 year={2025}
6}
78@InProceedings{Choi_2025_ICLR,
9 title={DiffusionGuard: A Robust Defense Against Malicious Diffusion-based Image Editing},
10 author={Choi, June Suk and Lee, Kyungmin and Jeong, Jongheon and Xie, Saining and Shin, Jinwoo and Lee, Kimin},
11 booktitle={ICLR},
12 year={2025}
13}
1415@article{pang2024vgmshield,
16 title={VGMShield: Mitigating Misuse of Video Generative Models},
17 author={Pang, Yan and Zhang, Yang and Wang, Tianhao},
18 journal={arXiv:2402.13126},
19 year={2024}
20}