論文の概要: TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors
- arxiv url: http://arxiv.org/abs/2607.25894v1
- Date: Tue, 28 Jul 2026 15:51:39 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-07-29 20:50:42.908321
- Title: TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors
- Title(参考訳): TIGA:ブラックボックスAIGC検出器に対する軌道注入ジェネレーター攻撃
- Authors: Xia Du, Zhuosen Bao, Zheng Lin, Jizhe Zhou, Jiawei Lian, Chi-man Pun, Jun Luo, Wei Ni, Symeon Chatzinotas,
- Abstract要約: Trajectory-Injected Generative Attack (TIGA) は、検出器回避画像を生成する、ソースフリーでトレーニング可能なフリーフレームワークである。
TIGAはDDIM(Laint Denoising Diffusion Implicit Model)の軌道を制御し、生成中に対向特性が出現するようにしている。
TIGAは、共通の後処理操作下で、強力なブラックボックス攻撃性能、転送性、高ロバスト性を実現する。
- 参考スコア(独自算出の注目度): 76.4118981404995
- License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
- Abstract: Recent diffusion models have achieved remarkable realism in facial image synthesis, posing growing challenges to artificial intelligence-generated content (AIGC) forensic detectors.Existing evasion methods typically perturb pre-generated images or require detector-aware training, which may introduce visible or statistical artifacts and limit applicability when the diffusion model must remain frozen and the target detector is accessible only through black-box queries. We propose Trajectory-Injected Generative Attack (TIGA), a source-image-free and training free framework that generates detector-evasive images within a single diffusion sampling trajectory. TIGA steers the latent Denoising Diffusion Implicit Model (DDIM) trajectory so that adversarial properties emerge during generation rather than being added afterward. TIGA first aggregates gradients from multiple white-box surrogate detectors to form a transferable, sign-aware prior, and then performs anisotropic directional search with symmetric finite-difference queries to estimate the black-box target response. The estimated directions are stabilized by decayed momentum and injected according to the DDIM noise schedule, with frequency-domain reshaping to suppress high frequency artifacts. Experiments on surrogate and unseen specialized forensic detectors show that TIGA achieves strong blackbox attack performance, transferability, and high robustness under common post-processing operations without source images or diffusion-model retraining, while preserving high perceptual quality.
- Abstract(参考訳): 近年の拡散モデルは、顔画像合成において顕著なリアリズムを達成し、人工知能生成コンテンツ(AIGC)法定検出器に挑戦する傾向にある。
本研究では,単一拡散サンプリング軌道内で検出回避画像を生成する,ソースフリーかつトレーニングフリーなフレームワークであるTrajectory-Injected Generative Attack (TIGA)を提案する。
TIGAは、遅延拡散拡散インプリシットモデル (DDIM) の軌道を制御し、その後追加されるのではなく、世代中に対向特性が出現するようにしている。
TIGAはまず、複数のホワイトボックスサロゲート検出器からの勾配を集約し、転送可能でサインアウェアな先行処理を行い、次に対称有限差分クエリで異方性方向探索を行い、ブラックボックスターゲット応答を推定する。
推定方向は減衰運動量によって安定化され、DDIMノイズスケジュールに従って注入され、高周波アーティファクトの抑制のために周波数領域の整形が行われる。
シュロゲートおよび目に見えない特殊法定検出器の実験は、TIGAが高知覚品質を維持しながら、ソース画像や拡散モデル再トレーニングを伴わない一般的な後処理操作において、強力なブラックボックス攻撃性能、転送性、高ロバスト性を達成していることを示している。
関連論文リスト
- ForensicsSAM: Toward Robust and Unified Image Forgery Detection and Localization Resisting to Adversarial Attack [56.0056378072843]
高い転送性を持つ逆画像は上流モデルでのみ作成可能であることを示す。
本稿では,IFDLフレームワークを組み込んだForensicsSAMを提案する。
論文 参考訳(メタデータ) (2025-08-10T16:03:44Z) - LATTE: Latent Trajectory Embedding for Diffusion-Generated Image Detection [13.576997219135992]
LATent Trajectory Embeddingは、複数の認知ステップにまたがる遅延埋め込みの進化をモデル化する新しいアプローチである。
GenImage、Chameleon、Diffusion Forensicsといったいくつかのベンチマークの実験は、LATTEが優れたパフォーマンスを達成することを示している。
論文 参考訳(メタデータ) (2025-07-03T12:53:47Z) - Take Fake as Real: Realistic-like Robust Black-box Adversarial Attack to Evade AIGC Detection [4.269334070603315]
本稿では,後処理の融合最適化を用いた現実的なロバストブラックボックス攻撃(R$2$BA)を提案する。
R$2$BAは優れた抗検出性能,可視性,GANおよび拡散型症例の強い堅牢性を示す。
論文 参考訳(メタデータ) (2024-12-09T18:16:50Z) - StealthDiffusion: Towards Evading Diffusion Forensic Detection through Diffusion Model [62.25424831998405]
StealthDiffusionは、AI生成した画像を高品質で受け入れがたい敵の例に修正するフレームワークである。
ホワイトボックスとブラックボックスの設定の両方で有効であり、AI生成した画像を高品質な敵の偽造に変換する。
論文 参考訳(メタデータ) (2024-08-11T01:22:29Z) - Vulnerabilities in AI-generated Image Detection: The Challenge of Adversarial Attacks [39.524974831780874]
FPBAはブラックボックス攻撃を成功させることができるので、敵攻撃はAIGI検出器にとって真の脅威であることを示す。
我々はこの手法を周波数ベースのポストトレインベイズアタック (FPBA) と呼ぶ。
論文 参考訳(メタデータ) (2024-07-30T14:07:17Z) - Adv-Diffusion: Imperceptible Adversarial Face Identity Attack via Latent
Diffusion Model [61.53213964333474]
本稿では,生の画素空間ではなく,潜在空間における非知覚的対角的アイデンティティ摂動を生成できる統一的なフレームワークAdv-Diffusionを提案する。
具体的には,周囲のセマンティックな摂動を生成するために,個人性に敏感な条件付き拡散生成モデルを提案する。
設計された適応強度に基づく対向摂動アルゴリズムは、攻撃の伝達性とステルス性の両方を確保することができる。
論文 参考訳(メタデータ) (2023-12-18T15:25:23Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。