arXiv:2605.13381cs.CVcs.MM2026-05

仅知检测模型骨干网络就能伪造高成功率假图。

Backbone is All You Need: Assessing Vulnerabilities of Frozen Foundation Models in Synthetic Image Forensics

  • 利用目标检测器的ViT骨干知识,直接在特征空间生成对抗样本。
  • 攻击成功率接近白盒水平,多场景下均有效。
  • 揭示冻结骨干模型存在严重漏洞,适合安全与检测研究者关注。

随着AI生成图像日益逼真,视觉变换器(ViTs)已成为现代深度伪造检测的核心。然而,当前普遍依赖冻结的预训练骨干网络,引入了微妙却关键的漏洞。本文提出代理迭代对抗攻击(SIAA),一种灰盒攻击方法,仅需了解检测器的ViT骨干结构,即可在目标检测器的特征空间内生成高效对抗样本。实验涵盖多种基于ViT的检测器及多样灰盒场景,包括少样本学习、完整训练不匹配和攻击迁移测试,结果表明该漏洞始终导致高攻击成功率,常接近白盒性能。这说明仅凭骨干网络知识即可严重削弱检测器可靠性,凸显在对抗多媒体取证中亟需更鲁棒的防御机制。

原文摘要 · Abstract (English)

As AI-generated synthetic images become increasingly realistic, Vision Transformers (ViTs) have emerged as a cornerstone of modern deepfake detection. However, the prevailing reliance on frozen, pre-trained backbones introduces a subtle yet critical vulnerability. In this work, we present the Surrogate Iterative Adversarial Attack (SIAA), a gray-box attack that exploits knowledge of the detector's ViT backbone alone and operates entirely within the target detector's feature space to craft highly effective adversarial examples. Through our experiments, involving multiple ViT-based detectors and diverse gray-box scenarios, including few-shot learning, complete training misalignment and attack transferability tests, we demonstrate that this vulnerability consistently yields high attack success rates, often approaching white-box performance. By doing so, we reveal that backbone knowledge alone is sufficient to undermine detector reliability, highlighting the urgent need for more resilient defenses in adversarial multimedia forensics.

图像伪造对抗攻击视觉变换器

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。