Transferable Dual-Domain Feature Importance Attack against AI-Generated Image Detector
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866914164457340928 |
|---|---|
| author | Zhu, Weiheng Cao, Gang Liu, Jing Yu, Lifang Weng, Shaowei |
| author_facet | Zhu, Weiheng Cao, Gang Liu, Jing Yu, Lifang Weng, Shaowei |
| contents | Recent AI-generated image (AIGI) detectors achieve impressive accuracy under clean condition. In view of antiforensics, it is significant to develop advanced adversarial attacks for evaluating the security of such detectors, which remains unexplored sufficiently. This letter proposes a Dual-domain Feature Importance Attack (DuFIA) scheme to invalidate AIGI detectors to some extent. Forensically important features are captured by the spatially interpolated gradient and frequency-aware perturbation. The adversarial transferability is enhanced by jointly modeling spatial and frequency-domain feature importances, which are fused to guide the optimization-based adversarial example generation. Extensive experiments across various AIGI detectors verify the cross-model transferability, transparency and robustness of DuFIA. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2511_15571 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Transferable Dual-Domain Feature Importance Attack against AI-Generated Image Detector Zhu, Weiheng Cao, Gang Liu, Jing Yu, Lifang Weng, Shaowei Computer Vision and Pattern Recognition Cryptography and Security Recent AI-generated image (AIGI) detectors achieve impressive accuracy under clean condition. In view of antiforensics, it is significant to develop advanced adversarial attacks for evaluating the security of such detectors, which remains unexplored sufficiently. This letter proposes a Dual-domain Feature Importance Attack (DuFIA) scheme to invalidate AIGI detectors to some extent. Forensically important features are captured by the spatially interpolated gradient and frequency-aware perturbation. The adversarial transferability is enhanced by jointly modeling spatial and frequency-domain feature importances, which are fused to guide the optimization-based adversarial example generation. Extensive experiments across various AIGI detectors verify the cross-model transferability, transparency and robustness of DuFIA. |
| title | Transferable Dual-Domain Feature Importance Attack against AI-Generated Image Detector |
| topic | Computer Vision and Pattern Recognition Cryptography and Security |
| url | https://arxiv.org/abs/2511.15571 |