Abstract: Highlights•Solved the robustness and generalization issues of adversarial examples in Deepfake active defense.•A new robust DeepFake distortion attack algorithm is proposed.•Introducing self-supervised learning into the adversarial autoaugment module solves the overfitting problem.
Loading