paper-with-me

홈 › Papers

FBA$^2$D: Frequency-based Black-box Attack for AI-generated Image Detection

2025-12-10 · Xiaojing Chen, Dan Li, Lijun Peng, Jun YanŁetter, Zhiqing Guo, Junyang Chen, Xiao Lan, Zhongjie Ba, Yunfeng DiaoŁetter arxiv

The prosperous development of Artificial Intelligence-Generated Content (AIGC) has brought people's anxiety about the spread of false information on social media. Designing detectors for filtering is an effective defense method, but most detectors will be compromised by adversarial samples. Currently, most studies exposing AIGC security issues assume information on model structure and data distribution. In real applications, attackers query and interfere with models that provide services in the form of application programming interfaces (APIs), which constitutes the black-box decision-based attack paradigm. However, to the best of our knowledge, decision-based attacks on AIGC detectors remain unexplored. In this study, we propose \textbf{FBA$^2$D}: a frequency-based black-box attack method for AIGC detection to fill the research gap. Motivated by frequency-domain discrepancies between generated and real images, we develop a decision-based attack that leverages the Discrete Cosine Transform (DCT) for fine-grained spectral partitioning and selects frequency bands as query subspaces, improving both query efficiency and image quality. Moreover, attacks on AIGC detectors should mitigate initialization failures, preserve image quality, and operate under strict query budgets. To address these issues, we adopt an ``adversarial example soup'' method, averaging candidates from successive surrogate iterations and using the result as the initialization to accelerate the query-based attack. The empirical study on the Synthetic LSUN dataset and GenImage dataset demonstrate the effectiveness of our prosed method. This study shows the urgency of addressing practical AIGC security problems.

📄 PDF Abstract BibTeX arXiv:2512.09264

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Vulnerabilities in AI-generated Image Detection: The Challenge of Adversarial Attacks

2024-07-30 · Yunfeng Diao, Naixin Zhai, Changtao Miao, Zitong Yu 외

Recent advancements in image synthesis, particularly with the advent of GAN and Diffusion models, have amplified public concerns regarding the dissemination of disinformation. To address such concerns, numerous AI-genera…

Adversarial AttackAdversarial RobustnessImage Generation

D4: Detection of Adversarial Diffusion Deepfakes Using Disjoint Ensembles

2022-02-11 · Ashish Hooda, Neal Mangaokar, Ryan Feng, Kassem Fawaz 외

Detecting diffusion-generated deepfake images remains an open problem. Current detection methods fail against an adversary who adds imperceptible adversarial perturbations to the deepfake to evade detection. In this work…

Adversarial RobustnessDeepFake DetectionFace Swapping

Detecting AutoAttack Perturbations in the Frequency Domain

2021-11-16 · ICML Workshop AML 2021 7 · Peter Lorenz, Paula Harder, Dominik Strassel, Margret Keuper 외

Recently, adversarial attacks on image classification networks by the AutoAttack (Croce and Hein, 2020b) framework have drawn a lot of attention. While AutoAttack has shown a very high attack success rate, most defense a…

image-classificationImage Classification

TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors

2026-07-28 · Xia Du, Zhuosen Bao, Zheng Lin, Jizhe Zhou 외 arxiv

Recent diffusion models have achieved remarkable realism in facial image synthesis, posing growing challenges to artificial intelligence-generated content (AIGC) forensic detectors.Existing evasion methods typically pert…

Evading DeepFake Detectors via Adversarial Statistical Consistency

2023-04-23 · CVPR 2023 1 · Yang Hou, Qing Guo, Yihao Huang, Xiaofei Xie 외

In recent years, as various realistic face forgery techniques known as DeepFake improves by leaps and bounds,more and more DeepFake detection techniques have been proposed. These methods typically rely on detecting stati…

DeepFake DetectionFace Swapping