发表机构
The University of Edinburgh(爱丁堡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对API部署中生成器被悄悄替换的风险,提出FARE方法,利用生成器特定伪影训练接受区域,仅凭单张图像即可有效检测替换,优于现有基线。
AI 中文摘要
现代AI图像生成器越来越多地被部署为不透明的API,客户可以查询已部署的服务,但无法检查模型权重或架构。这带来了一个实际挑战:提供商可能通过一个生成器的治理认证,随后在部署时悄悄换成更便宜、质量更低的生成器,从而在高风险领域损害公众信任甚至安全。我们研究部署时的完整性审计,并提出FARE(取证接受区域估计)。通过从该生成器采样的图像上训练FARE,对已认证的生成器进行注册。部署后,FARE可以仅使用一张图像判断该生成图像是否与已注册的生成器一致。FARE的特征基于已被提出用于取证应用的生成器特定伪影。FARE在训练过程中通过寻找收紧接受区域并提高对认证生成器细微变化敏感性的困难样本来放大这些特征。在生成器替换(包括相似模型版本和模型变体的替换)中,FARE能有效检测替换,在严格操作点上始终优于现有基线,并且在本工作评估的精确模型和仅决策攻击下仍保持有效性。
英文摘要
Modern AI image generators are increasingly deployed as opaque APIs, where customers can query the deployed service, but cannot inspect model weights or architecture. This creates a practical challenge: a provider may pass governance certification with one generator and later silently switch to a cheaper and lower-quality one for deployment, compromising public trust or even safety in high-stakes domains. We study integrity auditing at deployment time and propose FARE (Forensic Acceptance Region Estimation). A certified generator is enrolled by training FARE on images sampled from that generator. After deployment, FARE can determine whether a generated image is consistent with the enrolled generator---using only that image. FARE's features are based on image generator-specific artifacts that have been proposed for forensic applications. FARE amplifies these features during training by finding hard samples that tighten the acceptance region and increase sensitivity to subtle changes in the certified generator. Across generator swaps, including substitutions with similar model versions and model variants, FARE is effective at detecting swaps, consistently outperforming existing baselines at strict operating points, and remains effective under the exact-model and decision-only attacks evaluated in this work.
CommentsThis work has been accepted for publication in the proceedings of The 40th Annual Conference on Neural Information Processing Systems (NeurIPS 2026). 22 pages, including technical appendices. Code: https://github.com/kaikaiyao/FARE