MEGA Hub

TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors

Authors

Do you know Xia Du?You can claim authorship or link another user.Do you know Zhuosen Bao?You can claim authorship or link another user.Do you know Zheng Lin?You can claim authorship or link another user.Do you know Jizhe Zhou?You can claim authorship or link another user.Do you know Jiawei Lian?You can claim authorship or link another user.Do you know Chi-man Pun?You can claim authorship or link another user.Do you know Jun Luo?You can claim authorship or link another user.Do you know Wei Ni?You can claim authorship or link another user.Do you know Symeon Chatzinotas?You can claim authorship or link another user.

Abstract

Recent diffusion models have achieved remarkable realism in facial image synthesis, posing growing challenges to artificial intelligence-generated content (AIGC) forensic detectors.Existing evasion methods typically perturb pre-generated images or require detector-aware training, which may introduce visible or statistical artifacts and limit applicability when the diffusion model must remain frozen and the target detector is accessible only through black-box queries. We propose Trajectory-Injected Generative Attack (TIGA), a source-image-free and training free framework that generates detector-evasive images within a single diffusion sampling trajectory. TIGA steers the latent Denoising Diffusion Implicit Model (DDIM) trajectory so that adversarial properties emerge during generation rather than being added afterward. TIGA first aggregates gradients from multiple white-box surrogate detectors to form a transferable, sign-aware prior, and then performs anisotropic directional search with symmetric finite-difference queries to estimate the black-box target response. The estimated directions are stabilized by decayed momentum and injected according to the DDIM noise schedule, with frequency-domain reshaping to suppress high frequency artifacts. Experiments on surrogate and unseen specialized forensic detectors show that TIGA achieves strong blackbox attack performance, transferability, and high robustness under common post-processing operations without source images or diffusion-model retraining, while preserving high perceptual quality.

Community

00

Publication notes

Author note
14 pages, 5 figures