PhantomSeal: Proactive Deepfakes Defense with Identity/Context Protection and Forensic Tracing

Authors: Liangqin Ren, Zeyan Liu, Ye Wang, Yuxin Chen, Fengjun Li, Bo Luo

Published: 2026-07-20 19:05:20+00:00

Comment: Accepted by ACM CCS 2026

AI Summary

PhantomSeal is a proactive defense mechanism against face-swapping deepfakes that simultaneously protects both the identity and context of user images while enabling forensic tracing. It employs a novel cloaking technique that embeds a stealthy identifier, steering the deepfake generation process towards content resembling the chosen cloak identity, thereby preventing successful face-swapping. Extensive experiments demonstrate its effectiveness, reducing attack success rates and accurately identifying manipulated content.

Abstract

Deepfakes, especially face-swapping attacks, pose significant challenges to authenticity, security, and ethics across science, engineering, and society. While most existing detection/tracing approaches operate post hoc, proactive defenses that aim to intervene before deepfake generation remain limited in terms of real-world effectiveness. In this paper, we present PhantomSeal, the first proactive defense to simultaneously protect both the identity and the context of users' images from being used in face-swapping attacks, while supporting forensic tracing. We present a novel cloaking technique that embeds a selected identity as a stealthy identifier. This mechanism steers the deepfake generation process toward producing content that resembles the chosen cloak identity, thereby preventing successful face-swapping while enabling effective feature-based forensic analysis. The effectiveness and robustness of PhantomSeal is demonstrated in extensive experiments across different face-swapping architectures and models. For example, it reduces the attack success rate of SimSwap, an advanced deepfake model, to 0.30%, and correctly identifies 97.97% of manipulated content. Codes can be found at https://github.com/LiangqinRen/PhantomSeal


Key findings
PhantomSeal significantly reduces the attack success rate of advanced deepfake models like SimSwap to 0.30% while correctly identifying 97.97% of manipulated content. It effectively protects both identity and context, and is robust against various real-world transformations and some adaptive attacks. The 'cloaking' mechanism also enables forensic tracing, with a high success rate in identifying the embedded cloak identity.
Approach
PhantomSeal injects invisible, human-perception-aware perturbations into images prior to dissemination. This cloaking mechanism guides deepfake generation to produce content resembling a pre-selected 'cloak' identity, disrupting successful face-swapping attacks and enabling forensic tracing. It uses a bilevel optimization process to select optimal cloak images and generate perturbed images that balance minimal visual change with maximum protection.
Datasets
VGGFace2, FFHQ, StyleGAN3-generated faces, FaceForensics++
Model(s)
SimSwap, DiffFace, FaceShifter, HifiFace, UniFace, InfoSwap, E4S, DiffSwap, Deep-Live-Cam, FaceNet-512, Megvii Face++, Face Recognition library, Amazon AWS Rekognition, FaceSwap-Deepfake-Pytorch, FaceSwap, DeepFaceLive
Author countries
USA