Pith. sign in

REVIEW 2 cited by

Evading Deepfake-Image Detectors with White- and Black-Box Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2004.00622 v1 pith:N3DHAUYV submitted 2020-04-01 cs.CV cs.CR

classification cs.CVcs.CR
keywords classifierreduceattackscontentimageaccessareaattack
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

It is now possible to synthesize highly realistic images of people who don't exist. Such content has, for example, been implicated in the creation of fraudulent social-media profiles responsible for dis-information campaigns. Significant efforts are, therefore, being deployed to detect synthetically-generated content. One popular forensic approach trains a neural network to distinguish real from synthetic content. We show that such forensic classifiers are vulnerable to a range of attacks that reduce the classifier to near-0% accuracy. We develop five attack case studies on a state-of-the-art classifier that achieves an area under the ROC curve (AUC) of 0.95 on almost all existing image generators, when only trained on one generator. With full access to the classifier, we can flip the lowest bit of each pixel in an image to reduce the classifier's AUC to 0.0005; perturb 1% of the image area to reduce the classifier's AUC to 0.08; or add a single noise pattern in the synthesizer's latent space to reduce the classifier's AUC to 0.17. We also develop a black-box attack that, with no access to the target classifier, reduces the AUC to 0.22. These attacks reveal significant vulnerabilities of certain image-forensic classifiers.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors

    cs.CV 2026-07 conditional novelty 6.0 of 10

    TIGA evades black-box AIGC detectors by injecting adversarial directions into the DDIM sampling trajectory, reaching 100% attack success on the paper's face-image benchmarks.

  2. Nearly Solved? Robust Deepfake Detection Requires More than Visual Forensics

    cs.CV 2024-12 reject novelty 5.0 of 10

    Black-box genetic attacks flip 70% of correct fake detections in a retrained patch-based detector, GPT-4o reaches 73% AUC zero-shot on a Celeb-DF subset, and a 6.64% typographic attack degrades it.

Pith tools