[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-114921-en":3,"doc-seo-114921-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},114921,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","An adversarial attack approach for eXplainable AI evaluation on deepfake detection models","Rising concern about model interpretability drives growing interest in using eXplainable AI (XAI) tools for deepfake detection models. In image classification, XAI methods highlight pixels that influence predictions, supporting debugging and parameter tuning. However, deepfake detection requires special evaluation because generic insertion/removal approaches for salient regions can yield less meaningful results. This paper experimentally shows that common removal/insertion evaluation is unsuitable for deepfake detectors and introduces a deepfake-specific XAI evaluation approach.","Computers & Security 139 (2024) 103684  \nContents lists available at ScienceDirect Computers & Security  \njournal [homepage: www.elsevier.com/locate/cose](homepage: www.elsevier.com/locate/cose)  \n| An adversarial attack approach for eXplainable AI evaluation on deepfake   detection models\u003Cbr>*\u003Cbr>Balachandar Gowrisankar , Vrizlynn L.L. Thing\u003Cbr>Singapore Technologies Engineering Ltd, Singapore |  |  |\n| --- | --- | --- |\n| A R T I C L E I N F O |  | A B S T R A C T |\n| Keywords: Deepfake Explainable AI Evaluation Adversarial attack Image forensics |  | With the rising concern on model interpretability, the application of eXplainable AI (XAI) tools on deepfake detection models has been a topic of interest recently. In image classification tasks, XAI tools highlight pixels influencing the decision given by a model. This helps in troubleshooting the model and determining areas that may require further tuning of parameters. With a wide range of tools available in the market, choosing the right tool for a model becomes necessary as each one may highlight different sets of pixels for a given image. There is a need to evaluate different tools and decide the best performing ones among them. Generic XAI evaluation methods like insertion or removal of salient pixels/segments are applicable for general image classification tasks but may produce less meaningful results when applied on deepfake detection models due to their functionality. In this paper, we perform experiments to show that generic removal/insertion XAI evaluation methods are not suitable for deepfake detection models. We also propose and implement an XAI evaluation approach specifically suited for deepfake detection models. |\n\n1. Introduction  \nAdvancements in technology and computational resources have proliferated the creation and circulation of deepfakes on the Internet. Deepfake is a term used to denote fake images/videos/audios created using deep learning techniques. Tools used to create deepfakes have evolved over the years and as a result, humans are losing the capability to distinguish between real and fake content using naked eye. Thus, ML researchers are investing a lot of time and effort in this field to understand the process behind the creation of deepfakes and develop models to detect them. Cross Efficient Vision Transformer (Coccomini et al., 2022), XceptionNet (Chollet, 2017) and BA-TFD (Cai et al., 2022) are few benchmark deep learning models proposed in the recent past to combat the spread of fake content on the web. While researchers continue to develop complex detection models, humans are finding it difficult to blindly believe a model’s decision. Model evaluation metrics like accuracy, precision, recall etc. are not proving enough to gain a person’s trust on the model. This lead to the development of XAI. These are tools designed to help a human understand the reasons behind a model’s decision. LRP (Bach et al., 2015), Grad-CAM (Selvaraju et al., 2017), LIME (Ribeiro et al., 2016) and SHAP (Lundberg and Lee, 2017) are some popular XAI tools used in practice.  \nWith a plethora of tools available to the public, it is important to select the right tool for a model. Naturally, we may think that all tools will provide similar results and aspects like complexity, speed etc. should be the ones setting them apart. An example of applying SOBOL, Grad-CAM and LIME on XceptionNet for a real image is shown in Fig. 1. In the case of SOBOL and Grad-CAM, the pixels marked in red are the ones which contribute highly to a the model’s decision while LIME denotes the responsible pixels with a yellow boundary. In SOBOL’s explanation, the red regions are aligned more towards the left eye whereas they are pointed towards the nose in Grad-CAM. LIME highlights a part of the hair region in its explanation (shown here at the bottom right corner). This clearly shows that ambiguities exist among XAI tools and all of them may not highlight the same set of pixels for a given image a","cbCaihmpxydO6TuG","https://ap.wps.com/l/cbCaihmpxydO6TuG","pdf",4526741,1,10,"English","en",105,"# Introduction\n## XAI and deepfake detection challenges\n## Generic XAI evaluation methods and limitations\n## Paper contributions and evaluation approach","[{\"question\":\"Why is XAI important for deepfake detection models?\",\"answer\":\"XAI helps humans understand the reasons behind a model’s decisions, since traditional metrics like accuracy and precision are insufficient for trust. For deepfake detection, interpretability supports debugging and confidence in predictions.\"},{\"question\":\"What problem do generic insertion/removal XAI evaluation methods have for deepfake detectors?\",\"answer\":\"Generic methods assume that removing salient pixels will directly weaken the model’s prediction. For deepfake detectors, salient regions correspond to face visual concepts (eyes, nose, mouth), so judging predictions without the full face can become misleading.\"},{\"question\":\"What does the paper propose instead of generic XAI evaluation?\",\"answer\":\"The paper proposes and implements an XAI evaluation approach specifically suited for deepfake detection models, along with experimental evidence that generic removal/insertion methods are not suitable.\"}]","An adversarial attack approach for eXplainable AI evaluation on deepfake detection models | PDF",1785445278,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"an-adversarial-attack-approach-for-explainable-ai-evaluation-on-deepfake-detection-models","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/an-adversarial-attack-approach-for-explainable-ai-evaluation-on-deepfake-detection-models/114921/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-31","2026-07-30",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is XAI important for deepfake detection models?","Question",{"text":76,"@type":77},"XAI helps humans understand the reasons behind a model’s decisions, since traditional metrics like accuracy and precision are insufficient for trust. For deepfake detection, interpretability supports debugging and confidence in predictions.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What problem do generic insertion/removal XAI evaluation methods have for deepfake detectors?",{"text":81,"@type":77},"Generic methods assume that removing salient pixels will directly weaken the model’s prediction. For deepfake detectors, salient regions correspond to face visual concepts (eyes, nose, mouth), so judging predictions without the full face can become misleading.",{"name":83,"@type":74,"acceptedAnswer":84},"What does the paper propose instead of generic XAI evaluation?",{"text":85,"@type":77},"The paper proposes and implements an XAI evaluation approach specifically suited for deepfake detection models, along with experimental evidence that generic removal/insertion methods are not suitable.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":21,"slug":134},"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]