Robust, Generalizable Proactive Face-swapping Defense via Semantic Gradient Divergence

Robust, Generalizable Proactive Face-swapping Defense via Semantic Gradient Divergence

Seung-hyeok Back, Do Hyun Ki, Juwan Kim, Seok Bong Yoo

Proceedings of the Thirty-Fifth International Joint Conference on Artificial Intelligence
Main Track. Pages 890-898. https://doi.org/10.24963/ijcai.2026/100

The rapid progress of identity-feature-based face-swapping technology has raised concerns about impersonation and privacy violations. Although proactive defenses aim to block identity extraction at the source, existing methods suffer from perceptible visual artifacts, poor generalization across diverse deepfake models, and vulnerability to post-processing techniques (e.g., diffusion purification, image compression, and transformations). This work proposes a robust, generalizable proactive face-swapping defense via semantic gradient divergence (SGD-Guard) to address these challenges. It introduces an integrated feature gallery that uses CLIP features and a generalized identity feature, obtained by iteratively refining heterogeneous identity features into a homogeneous representation. This framework facilitates our semantic distortion attack by leveraging consensus weighting to target specific facial attributes within a CLIP-identity joint embedding space, disrupting deepfake generation while preserving visual fidelity. Furthermore, to ensure robustness against purification and post-processing, this method incorporates a module that prioritizes critical transformations by exploiting directional discrepancies. Comprehensive experiments demonstrate that the method effectively defends against diverse face-swapping models with high cross-model transferability.
Keywords:
Computer Vision: Adversarial learning, adversarial attack and defense methods
Computer Vision: Image and video synthesis and generation
Computer Vision: Transparency, accountability, fairness and privacy