Making Generated Images Hard To Spot: A Transferable Attack On Synthetic Image Detectors

  • 2022-06-22 18:11:40
  • Xinwei Zhao, Matthew C. Stamm
Visually realistic GAN-generated images have recently emerged as an importantmisinformation threat. Research has shown that these synthetic images containforensic traces that are readily identifiable by forensic detectors.Unfortunately, these detectors are built upon neural networks, which arevulnerable to recently developed adversarial attacks. In this paper, we proposea new anti-forensic attack capable of fooling GAN-generated image detectors.Our attack uses an adversarially trained generator to synthesize traces thatthese detectors associate with real images. Furthermore, we propose a techniqueto train our attack so that it can achieve transferability, i.e. it can foolunknown CNNs that it was not explicitly trained against. We evaluate our attackthrough an extensive set of experiments, where we show that our attack can fooleight state-of-the-art detection CNNs with synthetic images created using sevendifferent GANs, and outperform other alternative attacks.


