When Your Photo Stops Being Yours

31222099474?profile=RESIZE_400xMillions of photos go online every day.  Most people still treat a face in a picture as belonging to the person who is depicted.  That assumption may no longer hold true.  Software can now lift a face from one photograph and drop it into a completely different scene, or put a stranger’s face into someone else’s original setting while keeping the pose, expression, clothes, and background.  The results look real enough that ordinary viewers, and sometimes the detection software itself, accept them.  These tools are called face-swapping deepfakes.  They have already been used to create non-consensual intimate images, to invent political statements, and to stage scams in which an attacker appears to stand in a place or role that never belonged to them.[1]

The tools work by pulling apart two things that were previously joined.  One is identity, the features that make a face recognizable as a specific person.  The other is context, the angle of the head, the light on the skin, the expression, the clothing, or the room behind the person.  Modern deepfake systems extract the identity from a source photo and inject it into the context of a target photo.  The whole process takes only a few seconds on ordinary hardware.

Most defenses arrive after the damage is done or cover only part of the problem. Detection methods look for leftover traces in a finished image. Attackers can often scrub those traces. Watermarking and restoration techniques help after a fake appears, but they do nothing to stop the fake from being made and shared in the first place. A smaller group of proactive methods tries to interdict deepfake production efforts by adding noise that confuses face detectors or landmark extractors. These methods usually protect either the face or the scene, but not both. An attacker who fails with one approach can simply switch roles and succeed with the other. Few of them leave a clear trail that investigators can follow later.

A research team led by Liangqin Ren at the University of Kansas, working with colleagues at the University of Louisville and the University of Chicago, set out to close those gaps. Their work, described in a paper titled “PhantomSeal: Proactive Deepfakes Defense with Identity/Context Protection and Forensic Tracing,” protects a photograph before it is ever posted. The idea is that before an image leaves the user’s control, the system selects a second face, called a cloak, and embeds information from that cloak into the original photograph in a way that stays invisible to human eyes. The protected photograph still looks like the original, but any face-swapping tool that subsequently tries to extract identity or context runs into a steered signal.

When the tool tries to steal the identity, the output face tends to look like the cloak rather than the original person. When the tool tries to insert a new face into the original scene, the context features change enough that the swap either fails or produces obvious visual defects. At the same time, the presence of cloak identity gives forensic tools a reference they can match. That creates a link between the protected original and any subsequent deepfake.

The team tested the approach against several widely used systems, including both generative-adversarial-network models such as SimSwap and diffusion-based models such as DiffFace. In one set of tests on SimSwap, the success rate of identity-stealing attacks fell from near-total success on unprotected images to 0.30 percent once protection was applied, according to a commercial face-recognition service. Tracing success, measured as correct identification of the embedded cloak, reached 97.97 percent in the same tests. Context-stealing attacks were also disrupted, with success rates dropping into low single digits. The protected images kept high visual quality. Pixel-level and perceptual similarity scores stayed close to the originals, and face-recognition systems continued to identify the protected photographs as the original person at rates above 99 percent.

Choosing the right cloak matters. The researchers tried real photographs from public face datasets as well as synthetic faces generated by StyleGAN3. Synthetic cloaks avoid the privacy problems that come with using another real person’s image. They also found that the distance between the original identity and the cloak identity affects the balance between protection strength and tracing reliability. A moderate distance works best on both measures. The full protection process can finish in under two seconds on current high-end consumer graphics hardware. Shorter times remain practical with only modest drops in performance.

Because the method works on the photograph itself before distribution, it can sit inside the platforms where people already share images. A social network or messaging service could apply the protection automatically at upload, drawing from a rotating pool of AI-generated cloak faces so that no real third-party identity is ever required. Users would keep posting pictures that look unchanged to friends and followers. Any later attempt to weaponize those pictures would hit the built-in resistance and leave a forensic marker.

The same approach may reach beyond still photographs. Video frames, live streams, and other visual media that rely on identity and context extraction could receive similar treatment. Fields that already struggle with synthetic media, such as journalism verification, online identity systems, and digital evidence handling in legal settings, could gain from a technique that both reduces the supply of usable source material and gives investigators an independent reference signal. In each case, the requirement stays the same: an alteration that ordinary viewers never notice, yet decisive inside the internal representations that face-swapping pipelines depend on.

Investigators today rely on visual inspection, statistical artifact analysis, and, when available, platform metadata or watermark recovery. PhantomSeal adds another option. Because the deepfake output is deliberately pulled toward a known cloak identity, a comparison against a registry of cloaks used by a given platform can confirm both that protection was present and which original image was involved. That confirmation does not replace existing methods. It supplements them with a signal generated now of protection rather than reconstructed afterward.

The authors note that the current design addresses face-swapping systems that work with explicit source and target images. Prompt-driven generative models that synthesize scenes from text descriptions and loose identity references follow a different pipeline and would need separate defenses. Real-world distribution can introduce compression, resizing, and filtering. The team tested common transformations and found the protection largely intact, although stronger adaptive removal attacks remain an open problem. Deployment at platform scale would also require careful management of cloak libraries and clear policies on how tracing information is stored and accessed.

Even with those limits, the work shows that proactive protection does not need to be limited to single-purpose disruption. By steering rather than simply scrambling the signals that face-swapping tools depend on, it becomes possible to protect identity and context together while creating a usable forensic trail. The result is a practical step toward giving people more control over personal images in an environment where visual evidence can no longer be taken at face value. As platforms and users adopt such measures, the cost of producing convincing non-consensual deepfakes rises, and investigators' ability to reconstruct the origin of those fakes improves. That combination does not eliminate the problem. It changes the practical balance in favor of the people whose faces and lives appear in the photographs.

 

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

 Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://six3ro.substack.com/p/when-your-photo-stops-being-yours

You need to be a member of Red Sky Alliance to add comments!