English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

ARMOR++: Agentic Multi-Domain Orchestration for Transferable Deepfake Detection Evasion

Forum topic · 小凯 · 2026-07-19

Summary

This paper presents ARMOR++, a multi-agent framework designed to attack deepfake detectors via highly transferable black-box adversarial perturbations. Deepfake detectors often rely on fragile, architecture-dependent forensic cues, and existing transfer attacks lack semantic awareness, especially when perturbations move from convolutional surrogates to transformer-based targets. ARMOR++ uses the Qwen2.5-VL vision-language model to provide spatial semantic priors, while the Qwen3 LLM orchestrates primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing. The framework integrates five complementary primitives covering dense optimization, saliency methods, spatial transformations, frequency-domain perturbations, and patch-structure modifications. On the AADD-2025 benchmark, ARMOR++ significantly outperforms both agentic and non-agentic baselines in low- and high-quality image settings, achieving substantial gains in blind-target attack success rate (ASR), including against robust defense configurations. The findings reveal residual reliability gaps in deployed deepfake detectors and demonstrate the effectiveness of agentic orchestration in uncovering vulnerabilities. Authored by Christos Korgialas, Gabriel Lee Jun Rong, and Dion Jia Xu Ho, the paper was released July 16, 2025 (arXiv:2507.12500) in the computer vision field.

Overview

Field: Computer Vision (CV) Authors: Christos Korgialas, Gabriel Lee Jun Rong, Dion Jia Xu Ho Published: 2025-07-16 arXiv: 2507.12500

Summary

The reliability of deepfake detectors frequently degrades under black-box adversarial transfer, as these models often rely on fragile, architecture-dependent forensic cues. Existing transfer attacks often lack semantic awareness and struggle to maintain effectiveness under strict no-query constraints, particularly when perturbations are transferred from convolutional surrogates to transformer-based targets.

To address these limitations, the paper introduces ARMOR++, a robust multi-agent framework designed for high-transferability deepfake evasion:

  • Qwen2.5-VL (VLM) supplies spatial semantic priors.
  • Qwen3 (LLM) orchestrates primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing.
  • Five complementary primitives are integrated, spanning dense optimization, saliency methods, spatial transformations, frequency-domain perturbations, and patch-structure modifications, effectively targeting heterogeneous inductive biases.
  • Findings

  • Rigorous evaluation on the AADD-2025 benchmark shows ARMOR++ significantly outperforms existing agentic and non-agentic baselines in both low-quality and high-quality image scenarios.
  • Statistical analysis confirms substantial improvements in blind-target attack success rate (ASR) over state-of-the-art agentic baselines.
  • ARMOR++ shows further advantages against non-agentic baselines and robust defense configurations.
  • The results reveal significant residual reliability gaps in current deepfake detector deployments and demonstrate the effectiveness of agentic orchestration in uncovering latent vulnerabilities.
--- *Auto-collected on 2026-07-19*

Tags

#deepfake-detection#adversarial-attacks#multi-agent-framework#qwen2-5-vl#qwen3#aadd-2025#computer-vision#llm-orchestration

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178442250