arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.31749cs.CV

组件失效下的融合:集成AI生成图像检测的负面结果与失败模式

Fusion Under Component Failure: Negative Results and Failure Modes in Ensemble AI-Generated Image Detection

Suraj Singh, Tushar Verma, Pragyan Singh, Shaurya Bhav, Shivam Kumar

首次发表
浏览论文内容

中文总结 AI 辅助

本研究评估了AI生成图像检测的堆叠集成在组件失效下的表现,发现仅在目标域重拟合时融合有效,并揭示了弃权处理不当和语料库偏差等失败模式。

中文摘要 AI 辅助

我们构建了一个用于AI生成图像检测的普通堆叠集成——三个开放检测器产生五个分数,由一个梯度提升元学习器融合,该学习器将检测器的失败视为缺失数据——部署了它,然后针对它本应先面对的三个对照进行了评估。本文报告了这些对照的发现,包括它们推翻我们先前结论的地方。只有当融合在目标领域上重新拟合时才值得其成本。已部署的元学习器在单独语料库上拟合,在2000张StyleGAN人脸图像上并未超过其最佳单一成员(AUC 0.9896对比0.9961;McNemar检验p = 1.000)。但在领域内重新拟合的堆叠器超过了该成员加上事后校准器(Delta-AUC = +0.0025,[+0.0014, +0.0038];p = 3.4e-4)。早期草稿声称校准后的单一检测器全面获胜;该比较混合了不同机制,我们在此予以纠正。一个语料库不足以作为评估。在80张截图上,每个模型的AUC区间都包含0.5。我们不能说得更强:集成下降与其最佳成员之间的差异为[-0.185, +0.115]。弃权(不执行)是真实存在的、相关的,且处理不当。当五个检测器中有四个沉默,幸存者报告“真实”时,系统返回P(AI) = 0.9985,因为在一个从未用缺失性拟合的学习器中,全NaN输入得分为0.9995。三个AIDE检查点共同失败,共享一个预处理路径。一个要求两个不同架构的法定人数规则无需重新训练即可防止这两种失败。我们还发现语料库A带有严重的类条件JPEG偏差,仅从文件头就能区分类别,这限制了我们报告的每个领域内数字。代码、测试框架、哈希标识的工件及所有更正均已发布。

英文摘要

We built an ordinary stacking ensemble for AI-generated image detection -- three open detectors producing five scores, fused by a gradient-boosted meta-learner that treats a detector's failure as missing data -- deployed it, and then evaluated it against three controls it should have faced first. This paper reports what the controls found, including where they overturned our own earlier conclusions. Fusion is worth its cost only when refitted on the target domain. The shipped meta-learner, fitted on a separate corpus, does not beat its best single member on 2000 StyleGAN faces (AUC 0.9896 vs 0.9961; McNemar p = 1.000). But a stacker refitted in-domain beats that member plus a post-hoc calibrator (Delta-AUC = +0.0025, [+0.0014, +0.0038]; p = 3.4e-4). An earlier draft claimed the calibrated single detector won outright; that comparison mixed regimes and we correct it here. One corpus is not an evaluation. On 80 screenshots every model's AUC interval contains 0.5. We can say nothing stronger: the difference between the ensemble's drop and its best member's is [-0.185, +0.115]. Abstention is real, correlated, and mishandled. With four of five detectors silent and the survivor reporting "real", the system returns P(AI) = 0.9985, because an all-NaN input scores 0.9995 in a learner never fitted with missingness. The three AIDE checkpoints fail together, sharing one preprocessing path. A quorum rule requiring two distinct architectures prevents both failures with no retraining. We also find Corpus A carries a class-conditional JPEG bias severe enough to separate the classes from the header alone, which limits every in-domain number we report. Code, harness, hash-identified artifacts and all corrections are released.

↑