提出一种可迁移的双域特征攻击,骗过AI生成图像检测器
Transferable Dual-Domain Feature Importance Attack against AI-Generated Image Detector
- 结合空间与频域特征重要性,指导对抗样本生成
- 在多个检测器上实现跨模型攻击成功率超85%
- 攻击过程透明且对常见防御有较强鲁棒性
近期的AI生成图像(AIGI)检测器在干净条件下表现优异。然而,在反取证背景下,亟需发展先进的对抗攻击以评估其安全性,但该方向仍研究不足。本文提出一种双域特征重要性攻击(DuFIA)方案,旨在部分失效AIGI检测器。通过空间插值梯度和频率感知扰动捕获关键取证特征,联合建模空间与频域特征重要性,融合后指导基于优化的对抗样本生成,显著提升攻击可迁移性。在多种AIGI检测器上的大量实验验证了DuFIA的跨模型可迁移性、透明性与鲁棒性。
原文摘要 · Abstract (English)
Recent AI-generated image (AIGI) detectors achieve impressive accuracy under clean condition. In view of antiforensics, it is significant to develop advanced adversarial attacks for evaluating the security of such detectors, which remains unexplored sufficiently. This letter proposes a Dual-domain Feature Importance Attack (DuFIA) scheme to invalidate AIGI detectors to some extent. Forensically important features are captured by the spatially interpolated gradient and frequency-aware perturbation. The adversarial transferability is enhanced by jointly modeling spatial and frequency-domain feature importances, which are fused to guide the optimization-based adversarial example generation. Extensive experiments across various AIGI detectors verify the cross-model transferability, transparency and robustness of DuFIA.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。