English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

ARMOR++: Agentic Multi-Domain Attack Framework for Transferable Deepfake Detector Evasion

Forum topic · 小凯 · 2026-07-20

Summary

ARMOR++ is a multi-agent framework designed to generate highly transferable adversarial attacks against deepfake detectors. The framework uses the Qwen2.5-VL vision-language model to provide spatial semantic priors, while a Qwen3 large language model orchestrates primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing. It integrates five complementary attack primitives: dense optimization, saliency-based methods, spatial transformations, frequency-domain perturbations, and block-structured modifications, enabling it to target heterogeneous inductive biases across architectures. Addressing the common failure of transfer attacks that lack semantic awareness under strict no-query black-box constraints, ARMOR++ was evaluated on the AADD-2025 benchmark across both low- and high-quality image regimes. Results show significant improvements over existing agentic and non-agentic baselines, with statistical analysis confirming substantial gains in blind-target attack success rate (ASR) over the state-of-the-art agentic baseline, including under robust defensive configurations. The findings expose a residual reliability gap in deployed deepfake detectors and demonstrate the effectiveness of LLM-driven agentic orchestration in identifying latent vulnerabilities.

Paper Overview

  • Field: cs.CV
  • Authors: Christos Korgialas, Gabriel Lee Jun Rong, Dion Jia Xu Ho, Pai Chet Ng, Xiaoxiao Miao, Konstantinos N. Plataniis
  • Published: 2026-07-16
  • arXiv: 2607.15246

Abstract

The reliability of deepfake detectors frequently degrades under black-box adversarial transfer, as these models often rely on fragile, architecture-dependent forensic cues. Existing transfer attacks often lack semantic awareness and struggle to maintain effectiveness under strict no-query constraints, particularly when perturbations are transferred from convolutional surrogates to transformer-based targets. To address these limitations, this paper introduces ARMOR++, a robust multi-agent framework designed for high-transferability deepfake evasion.

The framework leverages the Qwen2.5-VL Vision-Language Model (VLM) to supply spatial semantic priors, while the Qwen3 Large Language Model (LLM) orchestrates primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing. By integrating five complementary primitives, spanning dense optimization, saliency-based methods, spatial transformations, frequency-domain perturbations, and block-structured modifications, ARMOR++ effectively targets heterogeneous inductive biases.

Rigorous evaluation on the AADD-2025 benchmark demonstrates that ARMOR++ significantly outperforms existing agentic and non-agentic baselines across both low- and high-quality image regimes. Statistical analysis confirms a substantial gain in blind-target Attack Success Rate (ASR) over the state-of-the-art agentic baseline, with further performance advantages evidenced against non-agentic benchmarks and under robust defensive configurations. These findings highlight a significant residual reliability gap in current deepfake detector deployments and demonstrate the efficacy of agentic orchestration in identifying latent vulnerabilities.

--- *Auto-collected on 2026-07-20*

Tags

#deepfake-detection#adversarial-attacks#multi-agent#llm-orchestration#transfer-attacks#computer-vision#ai-security

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178446937