Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Silence is Golden: Leveraging Adversarial Examples to Nullify Audio Control in LDM-based Talking-Head Generation

About

Advances in talking-head animation based on Latent Diffusion Models (LDM) enable the creation of highly realistic, synchronized videos. These fabricated videos are indistinguishable from real ones, increasing the risk of potential misuse for scams, political manipulation, and misinformation. Hence, addressing these ethical concerns has become a pressing issue in AI security. Recent proactive defense studies focused on countering LDM-based models by adding perturbations to portraits. However, these methods are ineffective at protecting reference portraits from advanced image-to-video animation. The limitations are twofold: 1) they fail to prevent images from being manipulated by audio signals, and 2) diffusion-based purification techniques can effectively eliminate protective perturbations. To address these challenges, we propose Silencer, a two-stage method designed to proactively protect the privacy of portraits. First, a nullifying loss is proposed to ignore audio control in talking-head generation. Second, we apply anti-purification loss in LDM to optimize the inverted latent feature to generate robust perturbations. Extensive experiments demonstrate the effectiveness of Silencer in proactively protecting portrait privacy. We hope this work will raise awareness among the AI security community regarding critical ethical issues related to talking-head generation techniques. Code: https://github.com/yuangan/Silencer.

Yuan Gan, Jiaxu Miao, Yunze Wang, Yi Yang• 2025

Related benchmarks

TaskDatasetResultRank
Talking Head GenerationHDTF (test)
FID166.9
49
Portrait Privacy ProtectionSyncTalk-generated videos (test)
PSNR30.77
45
Deepfake DefenseSyncTalk generated videos
SSIM89.83
14
Talking Head GenerationCelebA-HQ paired with LibriSpeech (test)
V-PSNR21.86
14
3D Talking Face Generation DefenseInstag
SSIM0.8418
10
Purification ResistanceSyncTalk Freqpure
VGG-Face Score0.3991
9
Purification ResistanceSyncTalk Diffpure
VGG-Face Similarity0.3308
9
Video Protection11 Reference Videos (test)
SSIM0.5311
9
Showing 8 of 8 rows

Other info

Follow for update