arXiv:2604.25213cs.CV2026-04被引 2

GPT-Image-2能秒级伪造票据,连自己都认不出真伪。

When the Forger Is the Judge: GPT-Image-2 Cannot Recognize Its Own Faked Documents

论文配图:When the Forger Is the Judge: GPT-Image-2 Cannot Recognize Its Own Faked Documents
图 1 · 摘自论文原文
  • 用GPT-Image-2生成3066张伪造票据,配像素级掩码。
  • 人类和四种检测器识别率均仅略超随机(最高0.599)。
  • 自检模型反而最差,说明其伪造能力已超越自身识别力。

OpenAI的GPT-Image-2已能近乎无缝地伪造文档图像:单个数字可在不到一秒内替换,成本仅几美分。我们发布AIForge-Doc v2数据集,包含3,066张由GPT-Image-2生成的伪造票据,采用与DocTamper兼容的像素级掩码格式。同时评估四类防御方案:120名人类检验员(共365对判断,通过公开2AFC平台CanUSpotAI.com)、TruFor(通用取证)、DocTamper(qcf-568,文档特定)及同模型零样本自检——要求判断图像中是否存在由AI图像模型生成或编辑的区域。人类2AFC准确率为0.501,接近随机水平,即使并列对比也无法区分伪造与真实票据。三种计算判别器仅略高于随机(TruFor 0.599,DocTamper 0.585,自检0.532)。自检模型表现持续不佳,非偶然:五种提示策略与四种模糊响应处理策略下,AUC始终未超过0.59。为排除检测器在源域失效可能,我们基于其训练分布构建同域传统篡改数据集进行校准:TruFor在跨相机拼接上达到AUC 0.962,DocTamper在跨文档OCR令牌拼接+双遍JPEG重编码下达0.852。两者在传统篡改任务中仍保持接近发表性能;但切换至GPT-Image-2 inpainting后,AUC下降0.27–0.36(TruFor 0.962→0.599,DocTamper 0.852→0.585),凸显针对GPT-Image-2 inpainting的检测空白。数据集、流程、四类判别协议及校准集均已公开。

原文摘要 · Abstract (English)

OpenAI's GPT-Image-2 has effectively erased the visual boundary between authentic and AI-edited document images: a single number on a receipt can be replaced in under a second for a few cents. We release AIForge-Doc v2, a paired dataset of 3,066 GPT-Image-2 document forgeries with pixel-precise masks in DocTamper-compatible format, and benchmark four lines of defence: human inspectors (N=120, n=365 pair-votes via the public 2AFC site CanUSpotAI.com), TruFor (generic forensic), DocTamper (qcf-568, document-specific), and the same GPT-Image-2 model as a zero-shot self-judge -- asked, to avoid the trivial "image is mostly real" reading, whether any region was generated or edited by an AI image model. Human 2AFC accuracy is 0.501, indistinguishable from chance: even side-by-side, inspectors cannot tell GPT-Image-2 receipt forgeries from authentic counterparts. The three computational judges sit only modestly above (TruFor 0.599, DocTamper 0.585, self-judge 0.532). The self-judge fails consistently, not by chance: across five prompt strategies and four policies for handling ambiguous responses, AUC never rises above 0.59. To rule out the possibility that the two forensic detectors are broken on our source domain rather than blind to AI inpainting, we calibrate each on a same-domain traditional-tampering set built for its training distribution: TruFor reaches AUC 0.962 on cross-camera splicing of our dataset, DocTamper reaches 0.852 on cross-document OCR-token splicing with two-pass JPEG re-encoding. Both retain near-published performance on traditional tampering; switching to GPT-Image-2 inpainting drops AUC by 0.27-0.36 (0.962->0.599 TruFor; 0.852->0.585 DocTamper), isolating a detection gap specific to GPT-Image-2 inpainting. We release the dataset, pipeline, four-judge protocol, and calibration sets.

伪造检测AI幻觉文档安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。