arXiv:2606.26384cs.CV2026-06

用通用模型检测深度伪造,发现多数基准测试其实测的是通用理解而非真伪识别能力。

What Do Deepfake Benchmarks Measure? An Audit Using Frozen Self-Supervised Representations

  • 用冻结的自监督表示做线性探测,评估基准测试是否依赖通用特征
  • 三种模态下探测器性能接近专用检测器,说明基准可能反映通用理解而非伪造特征
  • 生成难度与表示空间中的弗雷歇几何相关,提示基准可被通用模型解释

随着深度伪造生成技术趋于人眼难以分辨,可靠检测变得至关重要。然而,高分通过基准测试的检测器在真实场景中常失效。一个令人担忧的循环已出现:基准推动复杂、定制化检测器的发展,但如果这些基准不反映真实世界的深度伪造,这种复杂性可能解决的是错误问题。这引出一个根本问题:这些基准究竟在测量什么?我们使用一种刻意简单的诊断方法,对视频、图像和音频深度伪造基准进行了审计。如果在线性探测器上使用冻结的通用自监督表示就能逼近专用检测器的性能,则说明该基准主要奖励的是通用模态理解,而非法证理解。这一结果有两个含义:基准可能不反映现实威胁模型,且专用检测器所表现的“法证理解”可能只是通用表示的副产品。我们在三个模态中均观察到,线性探测器在通用自监督表示上的表现接近专用检测器。此外,我们还发现生成难度部分由同一表示空间中的弗雷歇几何解释。这些结果共同支持一种基准审计视角:在将高分解读为法证理解证据之前,应先审视多少基准内容已被通用表示预先解决。

原文摘要 · Abstract (English)

As deepfake generators approach perceptual indistinguishability, reliable detection becomes critical. Yet, detectors that score well on benchmarks routinely fail in the wild. A concerning feedback loop has emerged: benchmarks drive increasingly complex, engineered detectors, yet if those benchmarks do not reflect real-world deepfakes, this complexity may be solving the wrong problem entirely. This raises a prior question: what are these benchmarks actually measuring? We conduct an audit of video, image, and audio deepfake benchmarks using a deliberately simple diagnostic. If a linear probe on frozen, general-purpose self-supervised representations can approximate the performance of a bespoke detector, the benchmark is largely rewarding general modality understanding rather than forensic understanding. This has two implications: the benchmark may not reflect realistic threat models, and it raises the question of whether the bespoke detectors the probe approaches are truly learning forensic understanding. We observe, across three modalities, linear probes on general-purpose self-supervised representations closely approach the performance of bespoke detectors. We further show that generator-level difficulty is partly explained by Frechet geometry in the same representation space. Together, these results support a benchmark-audit view of deepfake detection: before high scores are read as evidence of forensic understanding, it is worth asking how much of the benchmark is already solved by general-purpose representations.

深度伪造基准审计自监督学习检测评测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。