发表机构
School of Computer and Information Engineering, Xiamen University of Technology; Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg; School of Computer Science, Engineering Research Center of Machine Learning and Industry Intelligence, Sichuan University; PCA Laboratory, Key Laboratory of Intelligent Perception and Systems for High-Dimensional Information of Ministry of Education, School of Computer Science and Engineering, Nanjing University of Science and Technology; Department of Computer and Information Science, Faculty of Science and Technology, University of Macau; School of Engineering, Edith Cowan University; College of Computing and Data Science, Nanyang Technological University(厦门理工学院计算机与信息工程学院; 卢森堡大学安全、可靠性和信任跨学科中心; 四川大学计算机学院机器学习与工业智能工程研究中心; 南京理工大学计算机科学与工程学院高维信息智能感知与系统教育部重点实验室PCA实验室; 澳门大学科技学院计算机与信息科学系; 伊迪斯科文大学工程学院; 南洋理工大学计算与数据科学学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对黑盒AIGC检测器,TIGA提出无需源图像和训练的框架,通过操纵DDIM轨迹、聚合梯度及方向搜索估计目标响应,实现强大黑盒攻击性能、可转移性及高鲁棒性,且无需源图像或扩散模型再训练。
AI 中文摘要
近期扩散模型在面部图像合成中实现了高度逼真,给人工智能生成内容(AIGC)取证带来挑战。现有逃避方法存在局限。我们提出轨迹注入生成攻击(TIGA),它无需源图像和训练,在单个扩散采样轨迹内生成逃避检测的图像。TIGA操纵潜在去噪扩散隐式模型(DDIM)轨迹,聚合多个白盒替代检测器的梯度形成先验,通过对称有限差分查询进行各向异性方向搜索估计黑盒目标响应。实验表明TIGA在无源图像或扩散模型再训练的情况下,能实现强大的黑盒攻击性能、可转移性及高鲁棒性。
英文摘要
Recent diffusion models have achieved remarkable realism in facial image synthesis, posing growing challenges to artificial intelligence-generated content (AIGC) forensic detectors.Existing evasion methods typically perturb pre-generated images or require detector-aware training, which may introduce visible or statistical artifacts and limit applicability when the diffusion model must remain frozen and the target detector is accessible only through black-box queries. We propose Trajectory-Injected Generative Attack (TIGA), a source-image-free and training free framework that generates detector-evasive images within a single diffusion sampling trajectory. TIGA steers the latent Denoising Diffusion Implicit Model (DDIM) trajectory so that adversarial properties emerge during generation rather than being added afterward. TIGA first aggregates gradients from multiple white-box surrogate detectors to form a transferable, sign-aware prior, and then performs anisotropic directional search with symmetric finite-difference queries to estimate the black-box target response. The estimated directions are stabilized by decayed momentum and injected according to the DDIM noise schedule, with frequency-domain reshaping to suppress high frequency artifacts. Experiments on surrogate and unseen specialized forensic detectors show that TIGA achieves strong blackbox attack performance, transferability, and high robustness under common post-processing operations without source images or diffusion-model retraining, while preserving high perceptual quality.
Comments14 pages, 5 figures