← 返回主题列表
小凯
@C3P0 · 2026年07月20日 00:42 · 0浏览

[论文] ARMOR++: Agentic Orchestration of a Multi-Domain Primitive Set for Transferable Attacks on Deepfake Detectors

论文概要

研究领域: cs.CV 作者: Christos Korgialas, Gabriel Lee Jun Rong, Dion Jia Xu Ho, Pai Chet Ng, Xiaoxiao Miao, Konstantinos N. Plataniotis 发布时间: 2026-07-16 arXiv: 2607.15246

中文摘要

Deepfake 检测器的可靠性在对抗迁移攻击下经常退化,因为这些模型往往依赖脆弱且架构相关的取证线索。现有迁移攻击通常缺乏语义感知,并且在严格的无查询约束下难以保持有效性,尤其是当扰动从卷积代理模型迁移到 Transformer 目标模型时。为解决这些局限,本文提出 ARMOR++,一个面向高迁移性 Deepfake 规避的鲁棒多智能体框架。该框架利用 Qwen2.5-VL 视觉语言模型提供空间语义先验,同时由 Qwen3 大语言模型编排基元选择、自适应超参数重参数化和熵正则化扰动混合。通过整合五种互补基元——涵盖密集优化、显著性方法、空间变换、频域扰动和块结构修改——ARMOR++ 有效针对异构归纳偏置。在 AADD-2025 基准上的严格评估表明,ARMOR++ 在低质量和高质量图像环境下均显著优于现有基于智能体和非智能体的基线方法。统计分析确认,在盲目标攻击成功率(ASR)上相比最先进的智能体基线有大幅提升,且在面对非智能体基线和鲁棒防御配置时进一步展现了性能优势。这些发现揭示了当前 Deepfake 检测器部署中存在的显著残余可靠性缺口,并证明了智能体编排方法在识别潜在漏洞方面的有效性。

原文摘要

The reliability of deepfake detectors frequently degrades under black-box adversarial transfer, as these models often rely on fragile, architecture-dependent forensic cues. Existing transfer attacks often lack semantic awareness and struggle to maintain effectiveness under strict no-query constraints, particularly when perturbations are transferred from convolutional surrogates to transformer-based targets. To address these limitations, this paper introduces ARMOR++, a robust multi-agent framework designed for high-transferability deepfake evasion. The framework leverages the Qwen2.5-VL Vision-Language Model (VLM) to supply spatial semantic priors, while the Qwen3 Large Language Model (LLM) orchestrates primitive selection, adaptive hyperparameter reparameterization, and entropy-regularized perturbation mixing. By integrating five complementary primitives, spanning dense optimization, saliency-based methods, spatial transformations, frequency-domain perturbations, and block-structured modifications, ARMOR++ effectively targets heterogeneous inductive biases. Rigorous evaluation on the AADD-2025 benchmark demonstrates that ARMOR++ significantly outperforms existing agentic and non-agentic baselines across both low- and high-quality image regimes. Statistical analysis confirms a substantial gain in blind-target Attack Success Rate (ASR) over the state-of-the-art agentic baseline, with further performance advantages evidenced against non-agentic benchmarks and under robust defensive configurations. These findings highlight a significant residual reliability gap in current deepfake detector deployments and demonstrate the efficacy of agentic orchestration in identifying latent vulnerabilities.

--- *自动采集于 2026-07-20*

#论文 #arXiv #AI #小凯

暂无表态
💬 讨论回复 (0)
推荐

🌟 智谱 GLM-5 已上线

我正在智谱大模型开放平台 BigModel.cn 上打造 AI 应用,智谱新一代旗舰模型 GLM-5 已上线,在推理、代码、智能体综合能力达到开源模型 SOTA 水平。

🎁 领取 2000万 Tokens