Training-Free Reconstruction-Based AI-Generated Image Detectors Are Inherently Vulnerable to Adversarial Examples

๐Ÿ“… 2026-08-17
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This study addresses the unknown adversarial robustness of training-free reconstruction-based AI-generated image detectors by proposing the first dedicated adversarial attack method leveraging autoencoder reconstruction error. By amplifying reconstruction errors through minimal perturbations to induce misclassification, and validating effectiveness via multi-model cross-evaluation and real-world degradation tests, this work demonstrates significant performance degradation across three mainstream detectors. Notably, the generated adversarial examples exhibit strong cross-model transferability. These findings reveal inherent security flaws and fundamental vulnerabilities in such detectors, thereby filling a critical gap in adversarial security assessment within this domain.
๐Ÿ“ Abstract
The impressive visual quality and ubiquity of AI-generated images call for reliable and robust detection methods. Reconstruction-based detectors have emerged as a promising direction for transparent and training-free identification of synthetic images. However, due to their fundamentally different mode of operation (compared to standard, classifier-based methods), little is known about their adversarial robustness. In this work, we propose two novel attack methods targeted at detectors that leverage autoencoder reconstruction error. We find that by constructing imperceptible adversarial examples, the distance between original and reconstruction can be artificially increased, causing fake images to be wrongly classified as real. Our evaluation including images from three state-of-the-art generators and three detectors demonstrates that detection performance is significantly decreased, even if attacked images additionally undergo real-world degradations. Critically, our adversarial examples naturally transfer across detectors, as they all share the same principle, pointing towards an inherent vulnerability of reconstruction-based detectors.
Problem

Research questions and friction points this paper is trying to address.

AI-generated image detection
reconstruction-based detectors
adversarial examples
adversarial robustness
training-free detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Adversarial Attack
Reconstruction-Based Detector
Training-Free Detection
Transferability
AI-Generated Image
๐Ÿ’ผ Related Jobs
No related jobs found.
R
Roman Demchenko
Ruhr University Bochum, Bochum, Germany
J
Jonas Ricker
Ruhr University Bochum, Bochum, Germany
Asja Fischer
Asja Fischer
Professor for Machine Learning, Ruhr University Bochum
machine learningdeep learningprobabilistic models