Pith. sign in

REVIEW 2 cited by

Exploring the Adversarial Robustness of CLIP for AI-generated Image Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.19553 v2 pith:5ZDUT652 submitted 2024-07-28 cs.CV

classification cs.CV
keywords detectorsadversarialbeencnn-basedai-generatedattacksmethodsrobustness
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In recent years, many forensic detectors have been proposed to detect AI-generated images and prevent their use for malicious purposes. Convolutional neural networks (CNNs) have long been the dominant architecture in this field and have been the subject of intense study. However, recently proposed Transformer-based detectors have been shown to match or even outperform CNN-based detectors, especially in terms of generalization. In this paper, we study the adversarial robustness of AI-generated image detectors, focusing on Contrastive Language-Image Pretraining (CLIP)-based methods that rely on Visual Transformer (ViT) backbones and comparing their performance with CNN-based methods. We study the robustness to different adversarial attacks under a variety of conditions and analyze both numerical results and frequency-domain patterns. CLIP-based detectors are found to be vulnerable to white-box attacks just like CNN-based detectors. However, attacks do not easily transfer between CNN-based and CLIP-based methods. This is also confirmed by the different distribution of the adversarial noise patterns in the frequency domain. Overall, this analysis provides new insights into the properties of forensic detectors that can help to develop more effective strategies.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Nearly Solved? Robust Deepfake Detection Requires More than Visual Forensics

    cs.CV 2024-12 reject novelty 5.0 of 10

    Black-box genetic attacks flip 70% of correct fake detections in a retrained patch-based detector, GPT-4o reaches 73% AUC zero-shot on a Celeb-DF subset, and a 6.64% typographic attack degrades it.

  2. Human Action CLIPs: Detecting AI-generated Human Motion

    cs.CV 2024-11 conditional novelty 5.0 of 10

    CLIP-based semantic embeddings, with a fine-tuned variant, detect AI-generated human-motion video with high accuracy (up to 99.2% video-level) and generalize to unseen generators.

Pith tools