Can Tainted Pixels Expose Deepfake Videos?

Authors: Juan Hu, Shaojing Fan, Sanjay Saha, Marc Herrera, Terence Sim

Published: 2026-08-26 15:39:43+00:00

AI Summary

TaintedPixels is a proactive video-protection method designed to expose deepfake manipulations by embedding inconspicuous structured periodic perturbations into the blue channel of facial regions. These perturbations remain subtle in the original video but become visibly obvious once the video undergoes manipulation by black-box tools. The method achieves a high forgery fake rate and significantly improves human detection of manipulated videos, while maintaining high perceptual quality of the protected source.

Abstract

Publicly-acceesible face-manipulation tools have made deepfake creation accessible to non-expert users. Against these, existing defenses are mostly post-hoc, detecting only after forgery has occurred, and operating on still images rather than videos. Research is lacking in i) the proactive protection of published facial videos against black-box manipulation tools, and in (ii) understanding its perceptual effect on human viewers. We introduce TaintedPixels, a proactive video-protection method built around an asymmetric visibility trade-off: the embedded watermark should remain inconspicuous in the published video but become obvious once a downstream tool manipulates the video. TaintedPixels injects structured periodic perturbations into the blue channel of facial regions and refines them under stripe-visibility, color-cast, and video-level LPIPS budgets, with lightweight motion-adaptive deployment. We believe TaintedPixels is the first proactive defense designed specifically against black-box manipulation tools rather than image-level pipelines or specific surrogate generators. Across three publicly available off-the-shelf video manipulation tools and two off-the-shelf detectors, TaintedPixels attains the highest forgery fake rate while keeping perturbations small (LPIPS = 0.0042). Our non-expert human study, conducted on a diverse set of 300 video stimuli spanning different lighting conditions, backgrounds, and skin tones, shows that protected source videos draw a 3.26% suspicion rate, while forgeries from protected sources are identified as fake much more often than forgeries from unprotected sources (90.72% vs. 56.71%). This validates the effectiveness of TaintedPixels.


Key findings
TaintedPixels achieves a significantly higher fake detection rate for forged videos (90.72% vs. 56.71% for unprotected sources in human studies) with minimal perceptual impact on the protected source videos (3.26% suspicion rate). The method is robust to common post-processing operations like H.264 compression and re-encoding, demonstrating its effectiveness against off-the-shelf manipulation tools.
Approach
The method injects structured periodic perturbations into the blue channel of facial regions in videos. These perturbations are refined under budgets for stripe-visibility, color-cast, and video-level LPIPS, with a lightweight motion-adaptive deployment. The aim is for the perturbations to be inconspicuous in the original video but amplified by manipulation tools, leading to visible artifacts in the forged output.
Datasets
FaceForensics++, Celeb-DF
Model(s)
NPR (Tan et al. [2024]), Deep-Fake-Detector-v2-Model (Sakthi)
Author countries
Singapore